{"cves":[{"id":"CVE-2026-33592","published":"2026-07-02T08:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nAn unauthenticated remote attacker can exhaust\nserver memory via the FindServers Discovery Service in open62541. The\nserverUris field of FindServersRequest is not validated for length or array\nsize. An attacker can declare an arbitrarily large string (up to ~3.9 GB)\ndelivered across intermediate chunks without ever sending the final chunk.\nThe\nserver buffers all chunks in RAM indefinitely until the SecureChannel times\nout. The attack is pre-session and bypasses all encryption configuration.\nThe issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through\n1.5.4, master.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33592","https://github.com/open62541/open62541","https://github.com/open62541/open62541/pull/8142","https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae"],"bugs":[""],"patches":{"open62541":[]},"tags":{},"packages":[{"name":"open62541","source":"https://ubuntu.com/security/cve?package=open62541","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open62541","debian":"https://tracker.debian.org/pkg/open62541","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50142","published":"2026-07-02T00:00:00","updated_at":"2026-09-02T21:16:45.111104+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0\nuntil 1.23.0, a crafted HEIF sequence accepted by\nheif_context_read_from_memory() with the msf1 sequence brand can cause\nunbounded heap allocation. In libheif/sequences/seq_boxes.cc,\nBox_stsz::parse() applies max_sequence_frames only to variable-size\nsamples, so fixed-size mode accepts an attacker-controlled sample_count\nwithout a bound. In libheif/sequences/track.cc, Track::load() also adds\ncurrent_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the\nconsistency check to be bypassed by wraparound. The resulting values reach\nthe Chunk::Chunk() allocation path, which can consume gigabytes of memory\nand crash or stall the process through memory exhaustion. This issue is\nfixed in version 1.23.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50142","https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh","https://ubuntu.com/security/notices/USN-8526-1"],"bugs":[""],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/commit/a6caa38f7a70d66dc9caec2a7bfe20935b32c622"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"upstream","status":"released","description":"1.23.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.20.2-1ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8526-1"],"notices":[{"id":"USN-8526-1","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-09T19:25:53.159767","description":"Xianrui Dong discovered that libheif had an out-of-bounds read in its\nHEIF sequence track parser. An attacker could possibly use this issue\nto cause a denial of service or obtain sensitive information. This issue\nonly affected Ubuntu 26.04 LTS. (CVE-2026-47254)\n\nJunyi Liu discovered that libheif had a null pointer dereference in its\nimage tiling interface. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2026-47709)\n\nCalvin Young and Enoch Chow discovered that libheif had an integer\noverflow in its inline mask size calculation. An attacker could\npossibly use this issue to cause a denial of service or obtain sensitive\ninformation. (CVE-2026-47714)\n\nAriel Koren discovered that libheif had an integer underflow in its\ngrid image tile coordinate transform. An attacker could possibly use\nthis issue to cause a denial of service or obtain sensitive information.\n(CVE-2026-48029)\n\nIt was discovered that libheif had a missing bound check in its HEIF\nsequence parser, allowing unbounded heap allocation. An attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-50142)","is_hidden":false,"release_packages":{"questing":[{"name":"libheif","version":"1.20.2-1ubuntu0.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-view","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-dev","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-examples","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugins-all","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif1","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"}],"resolute":[{"name":"libheif","version":"1.21.2-3ubuntu0.3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-thumbnailer","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-view","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-dev","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-examples","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugins-all","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif1","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47709","CVE-2026-50142","CVE-2026-48029","CVE-2026-47254","CVE-2026-47714"]}]},{"id":"CVE-2026-48029","published":"2026-07-02T00:00:00","updated_at":"2026-08-07T05:37:15.905271+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0\nthrough 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via\nirot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48029","https://github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqv","https://ubuntu.com/security/notices/USN-8526-1"],"bugs":[""],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/commit/e523ec0bf379110b7c33d4c159f8b1202d332157"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"upstream","status":"released","description":"1.23.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.20.2-1ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8526-1"],"notices":[{"id":"USN-8526-1","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-09T19:25:53.159767","description":"Xianrui Dong discovered that libheif had an out-of-bounds read in its\nHEIF sequence track parser. An attacker could possibly use this issue\nto cause a denial of service or obtain sensitive information. This issue\nonly affected Ubuntu 26.04 LTS. (CVE-2026-47254)\n\nJunyi Liu discovered that libheif had a null pointer dereference in its\nimage tiling interface. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2026-47709)\n\nCalvin Young and Enoch Chow discovered that libheif had an integer\noverflow in its inline mask size calculation. An attacker could\npossibly use this issue to cause a denial of service or obtain sensitive\ninformation. (CVE-2026-47714)\n\nAriel Koren discovered that libheif had an integer underflow in its\ngrid image tile coordinate transform. An attacker could possibly use\nthis issue to cause a denial of service or obtain sensitive information.\n(CVE-2026-48029)\n\nIt was discovered that libheif had a missing bound check in its HEIF\nsequence parser, allowing unbounded heap allocation. An attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-50142)","is_hidden":false,"release_packages":{"questing":[{"name":"libheif","version":"1.20.2-1ubuntu0.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-view","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-dev","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-examples","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugins-all","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif1","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"}],"resolute":[{"name":"libheif","version":"1.21.2-3ubuntu0.3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-thumbnailer","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-view","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-dev","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-examples","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugins-all","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif1","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47709","CVE-2026-50142","CVE-2026-48029","CVE-2026-47254","CVE-2026-47714"]}]},{"id":"CVE-2026-47714","published":"2026-07-02T00:00:00","updated_at":"2026-08-07T05:37:15.905271+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. In versions\n1.21.2 and prior, the inline mask parsing code in `libheif/region.cc`\ncontains an integer overflow. Both `width` and `height` are `unsigned int`\n(32-bit) values parsed from the HEIF file. Their product can exceed\n`UINT32_MAX`, wrapping to a small value before the division by 8. This\ncauses an undersized buffer allocation, leading to out-of-bounds memory\naccess when the mask data is later interpreted as a `width x height`\nbitmap. Version 1.22.0 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47714","https://github.com/strukturag/libheif/security/advisories/GHSA-h4wm-6wwf-qvhx","https://ubuntu.com/security/notices/USN-8526-1","https://ubuntu.com/security/notices/USN-8526-2"],"bugs":[""],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/commit/b1bd1c000e596f09ecd7bae87f95b88c21a6dc4a"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"upstream","status":"released","description":"1.23.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.20.2-1ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.17.6-1ubuntu4.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-8526-1","USN-8526-2"],"notices":[{"id":"USN-8526-1","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-09T19:25:53.159767","description":"Xianrui Dong discovered that libheif had an out-of-bounds read in its\nHEIF sequence track parser. An attacker could possibly use this issue\nto cause a denial of service or obtain sensitive information. This issue\nonly affected Ubuntu 26.04 LTS. (CVE-2026-47254)\n\nJunyi Liu discovered that libheif had a null pointer dereference in its\nimage tiling interface. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2026-47709)\n\nCalvin Young and Enoch Chow discovered that libheif had an integer\noverflow in its inline mask size calculation. An attacker could\npossibly use this issue to cause a denial of service or obtain sensitive\ninformation. (CVE-2026-47714)\n\nAriel Koren discovered that libheif had an integer underflow in its\ngrid image tile coordinate transform. An attacker could possibly use\nthis issue to cause a denial of service or obtain sensitive information.\n(CVE-2026-48029)\n\nIt was discovered that libheif had a missing bound check in its HEIF\nsequence parser, allowing unbounded heap allocation. An attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-50142)","is_hidden":false,"release_packages":{"questing":[{"name":"libheif","version":"1.20.2-1ubuntu0.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-view","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-dev","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-examples","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugins-all","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif1","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"}],"resolute":[{"name":"libheif","version":"1.21.2-3ubuntu0.3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-thumbnailer","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-view","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-dev","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-examples","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugins-all","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif1","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47709","CVE-2026-50142","CVE-2026-48029","CVE-2026-47254","CVE-2026-47714"]},{"id":"USN-8526-2","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-14T16:29:55.104545","description":"USN-8526-1 fixed vulnerabilities in libheif. This update provides the\ncorresponding updates for CVE-2026-47709 and CVE-2026-47714 in\nUbuntu 24.04 LTS.\n\nOriginal advisory details:\n\n Junyi Liu discovered that libheif had a null pointer dereference in its\n image tiling interface. An attacker could possibly use this issue to\n cause a denial of service. (CVE-2026-47709)\n\n Calvin Young and Enoch Chow discovered that libheif had an integer\n overflow in its inline mask size calculation. An attacker could\n possibly use this issue to cause a denial of service or obtain sensitive\n information. (CVE-2026-47714)","is_hidden":false,"release_packages":{"noble":[{"name":"libheif","version":"1.17.6-1ubuntu4.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-dev","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-examples","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif1","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47714","CVE-2026-47709"]}]},{"id":"CVE-2026-47709","published":"2026-07-02T00:00:00","updated_at":"2026-08-07T05:37:09.592117+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. Versions prior\nto 1.22.0 crashes in the public C API\n`heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF\nimage item has an associated `uncC` property but no associated `ispe`\nproperty. In debug builds this trips the `ispe && uncC` assertion in\n`ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan\nbuild, the same file causes a null pointer read at address `0xa8`. Version\n1.22.0 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47709","https://github.com/strukturag/libheif/security/advisories/GHSA-4h72-vqgp-9376","https://ubuntu.com/security/notices/USN-8526-1","https://ubuntu.com/security/notices/USN-8526-2"],"bugs":[""],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/commit/294d9c09d","upstream: https://github.com/strukturag/libheif/commit/f36bd8cdd"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"upstream","status":"released","description":"1.23.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.20.2-1ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.17.6-1ubuntu4.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-8526-1","USN-8526-2"],"notices":[{"id":"USN-8526-1","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-09T19:25:53.159767","description":"Xianrui Dong discovered that libheif had an out-of-bounds read in its\nHEIF sequence track parser. An attacker could possibly use this issue\nto cause a denial of service or obtain sensitive information. This issue\nonly affected Ubuntu 26.04 LTS. (CVE-2026-47254)\n\nJunyi Liu discovered that libheif had a null pointer dereference in its\nimage tiling interface. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2026-47709)\n\nCalvin Young and Enoch Chow discovered that libheif had an integer\noverflow in its inline mask size calculation. An attacker could\npossibly use this issue to cause a denial of service or obtain sensitive\ninformation. (CVE-2026-47714)\n\nAriel Koren discovered that libheif had an integer underflow in its\ngrid image tile coordinate transform. An attacker could possibly use\nthis issue to cause a denial of service or obtain sensitive information.\n(CVE-2026-48029)\n\nIt was discovered that libheif had a missing bound check in its HEIF\nsequence parser, allowing unbounded heap allocation. An attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-50142)","is_hidden":false,"release_packages":{"questing":[{"name":"libheif","version":"1.20.2-1ubuntu0.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-view","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-dev","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-examples","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugins-all","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif1","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"}],"resolute":[{"name":"libheif","version":"1.21.2-3ubuntu0.3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-thumbnailer","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-view","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-dev","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-examples","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugins-all","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif1","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47709","CVE-2026-50142","CVE-2026-48029","CVE-2026-47254","CVE-2026-47714"]},{"id":"USN-8526-2","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-14T16:29:55.104545","description":"USN-8526-1 fixed vulnerabilities in libheif. This update provides the\ncorresponding updates for CVE-2026-47709 and CVE-2026-47714 in\nUbuntu 24.04 LTS.\n\nOriginal advisory details:\n\n Junyi Liu discovered that libheif had a null pointer dereference in its\n image tiling interface. An attacker could possibly use this issue to\n cause a denial of service. (CVE-2026-47709)\n\n Calvin Young and Enoch Chow discovered that libheif had an integer\n overflow in its inline mask size calculation. An attacker could\n possibly use this issue to cause a denial of service or obtain sensitive\n information. (CVE-2026-47714)","is_hidden":false,"release_packages":{"noble":[{"name":"libheif","version":"1.17.6-1ubuntu4.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-dev","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-examples","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"},{"name":"libheif1","version":"1.17.6-1ubuntu4.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47714","CVE-2026-47709"]}]},{"id":"CVE-2026-47254","published":"2026-07-02T00:00:00","updated_at":"2026-08-07T05:37:15.905271+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. Prior to\nversion 1.22.0, `Track::init_sample_timing_table()` in\n`libheif/sequences/track.cc` stores an out-of-bounds chunk index\n(`m_chunks.size()`) into `m_presentation_timeline` when the number of\nchunks defined in the `stco` box is less than the number of samples in\n`stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()`\nreads `m_chunks[chunk_idx]` with that OOB index, causing a\nheap-buffer-overflow. Version 1.22.0 fixes the issue.","ubuntu_description":"","notes":[{"author":"kkernick","note":"The vulnerable code was introduced by b24f643, first released under\n1.21.0."}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47254","https://github.com/strukturag/libheif/security/advisories/GHSA-wqjg-4x9g-6cvg","https://ubuntu.com/security/notices/USN-8526-1"],"bugs":[""],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/commit/edc1250260ffcbaa9cf16a4158a982382d5f1348","upstream: https://github.com/strukturag/libheif/commit/4f9440778f9b92815a5850f8ae656bc642445fda"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"upstream","status":"released","description":"1.23.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8526-1"],"notices":[{"id":"USN-8526-1","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-09T19:25:53.159767","description":"Xianrui Dong discovered that libheif had an out-of-bounds read in its\nHEIF sequence track parser. An attacker could possibly use this issue\nto cause a denial of service or obtain sensitive information. This issue\nonly affected Ubuntu 26.04 LTS. (CVE-2026-47254)\n\nJunyi Liu discovered that libheif had a null pointer dereference in its\nimage tiling interface. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2026-47709)\n\nCalvin Young and Enoch Chow discovered that libheif had an integer\noverflow in its inline mask size calculation. An attacker could\npossibly use this issue to cause a denial of service or obtain sensitive\ninformation. (CVE-2026-47714)\n\nAriel Koren discovered that libheif had an integer underflow in its\ngrid image tile coordinate transform. An attacker could possibly use\nthis issue to cause a denial of service or obtain sensitive information.\n(CVE-2026-48029)\n\nIt was discovered that libheif had a missing bound check in its HEIF\nsequence parser, allowing unbounded heap allocation. An attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-50142)","is_hidden":false,"release_packages":{"questing":[{"name":"libheif","version":"1.20.2-1ubuntu0.6","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-thumbnailer","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"heif-view","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-dev","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-examples","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif-plugins-all","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"},{"name":"libheif1","version":"1.20.2-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.6","pocket":"security"}],"resolute":[{"name":"libheif","version":"1.21.2-3ubuntu0.3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-thumbnailer","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"heif-view","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-dev","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-examples","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif-plugins-all","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"},{"name":"libheif1","version":"1.21.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47709","CVE-2026-50142","CVE-2026-48029","CVE-2026-47254","CVE-2026-47714"]}]},{"id":"CVE-2026-20244","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nA vulnerability in the DMG file format parser of ClamAV could allow an\nunauthenticated, remote attacker to cause a DoS condition, or possibly\nother expanded impacts, resulting from memory corruption on an affected\ndevice.\nThis vulnerability is due to improper boundary checks for content in DMG\nfiles during scanning, which may result in an integer overflow on 32-bit\nplatforms only. An attacker could exploit this vulnerability by submitting\na crafted file that contains DMG content to be scanned by ClamAV on an\naffected device. A successful exploit could allow the attacker to cause the\nClamAV scanning process to terminate, resulting in a DoS condition on the\naffected software.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20244","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-20243","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nA vulnerability in the ALZ file format parser of ClamAV could allow an\nunauthenticated, remote attacker to cause a DoS condition, or possibly\nother expanded impacts, resulting from memory corruption on an affected\ndevice.\nThis vulnerability is due to improper boundary checks for content in ALZ\nfiles during scanning, which may result in an out-of-bounds buffer write.\nAn attacker could exploit this vulnerability by submitting a crafted file\nthat contains ALZ content to be scanned by ClamAV on an affected device. A\nsuccessful exploit could allow the attacker to cause the ClamAV scanning\nprocess to terminate, resulting in a DoS condition on the affected\nsoftware.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20243","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-20217","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nA vulnerability in the PESpin file format parser of ClamAV could allow an\nunauthenticated, remote attacker to cause a DoS condition, or possibly\nother expanded impacts, resulting from memory corruption on an affected\ndevice.\nThis vulnerability is due to improper boundary checks for content in PESpin\nfiles during scanning, which may result in an out-of-bounds buffer write.\nAn attacker could exploit this vulnerability by submitting a crafted file\nthat contains PESpin content to be scanned by ClamAV on an affected device.\nA successful exploit could allow the attacker to cause the ClamAV scanning\nprocess to terminate, resulting in a DoS condition on the affected\nsoftware.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20217","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-20216","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nA vulnerability in the InstallShield file format parser of ClamAV could\nallow an unauthenticated, remote attacker to cause a DoS condition on an\naffected device.\nThis vulnerability is due to improper handling of temporary resources\nduring file scanning. An attacker could exploit this vulnerability by\nsubmitting a crafted InstallShield file to be scanned by ClamAV on an\naffected device. A successful exploit could allow the attacker to terminate\nthe ClamAV scanning process and temporarily consume available system\nresources, resulting in a DoS condition on the affected software.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20216","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-20215","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nA vulnerability in the 7z file format parser of ClamAV could allow an\nunauthenticated, remote attacker to cause a DoS condition, or possibly\nother expanded impacts, resulting from memory corruption on an affected\ndevice.\nThis vulnerability is due to improper boundary checks for content in 7z\nfiles during scanning, which may result in an out-of-bounds buffer write.\nAn attacker could exploit this vulnerability by submitting a crafted file\nthat contains 7z content to be scanned by ClamAV on an affected\ndevice. A successful exploit could allow the attacker to cause the ClamAV\nscanning process to terminate, resulting in a DoS condition on the affected\nsoftware.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20215","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-20214","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nA vulnerability in the FSG file format parser of ClamAV could allow an\nunauthenticated, remote attacker to cause a DoS condition, or possibly\nother expanded impacts, resulting from memory corruption on an affected\ndevice.\nThis vulnerability is due to improper boundary checks for content in FSG\nfiles during scanning, which may result in an out-of-bounds buffer write.\nAn attacker could exploit this vulnerability by submitting a crafted file\nthat contains portable executable content compressed with FSG to be scanned\nby ClamAV on an affected device. A successful exploit could allow the\nattacker to cause the ClamAV scanning process to terminate, resulting in a\nDoS condition on the affected software.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20214","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-20213","published":"2026-07-02T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nA vulnerability in the PE file format parser of ClamAV could allow an\nunauthenticated, remote attacker to cause a DoS condition, or possibly\nother expanded impacts, resulting from memory corruption on an affected\ndevice.\nThis vulnerability is due to improper boundary checks for content in PE\nfiles during scanning, which may result in an out-of-bounds buffer write.\nAn attacker could exploit this vulnerability by submitting a crafted file\nthat contains PE content to be scanned by ClamAV on an affected device. A\nsuccessful exploit could allow the attacker to cause the ClamAV scanning\nprocess to terminate, resulting in a DoS condition on the affected\nsoftware.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Building ClamAV requires rust compiler >= 1.61\nreleases as bionic, xenial and trusty are not\ncovered by that version of rustc. ClamAV\nnew versions can't build in these releases\nanymore."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-20213","https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html","https://ubuntu.com/security/notices/USN-8517-1"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.3,1.4.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.5.3+dfsg-0ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.5.3+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.5.3+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8517-1"],"notices":[{"id":"USN-8517-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-08T14:07:06.965257","description":"It was discovered that ClamAV incorrectly handled certain PE files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,\nCVE-2026-20217)\n\nIt was discovered that ClamAV incorrectly handled certain 7z archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20215)\n\nIt was discovered that ClamAV incorrectly handled extraction limits for\ncertain InstallShield archives. A remote attacker could possibly use this\nissue to cause ClamAV to use excessive resources, leading to a denial of\nservice. (CVE-2026-20216)\n\nIt was discovered that ClamAV incorrectly handled certain ALZ archive\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2026-20243)\n\nIt was discovered that ClamAV incorrectly handled certain DMG files. A\nremote attacker could possibly use this issue to cause ClamAV to crash,\nresulting in a denial of service. (CVE-2026-20244)","is_hidden":false,"release_packages":{"jammy":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.22.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2","pocket":"security"}],"noble":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-base","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-daemon","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-doc","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-docs","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-freshclam","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-milter","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamav-testfiles","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"clamdscan","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav-dev","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libclamav12","version":"1.5.3+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-20215","CVE-2026-20243","CVE-2026-20244","CVE-2026-20216","CVE-2026-20214","CVE-2026-20213","CVE-2026-20217"]}]},{"id":"CVE-2026-14432","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:48:02.721280+00:00","description":"\nUse after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a\nremote attacker to execute arbitrary code inside a sandbox via a crafted\nHTML page. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14432","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/524290062"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14431","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:48:02.721280+00:00","description":"\nType Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a\nremote attacker to execute arbitrary code inside a sandbox via a crafted\nHTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14431","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/523884658"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14430","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:48:02.721280+00:00","description":"\nInteger overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a\nremote attacker to execute arbitrary code inside a sandbox via a crafted\nHTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14430","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/522126182"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14429","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nInsufficient validation of untrusted input in Skia in Google Chrome prior\nto 150.0.7871.46 allowed a remote attacker who had compromised the renderer\nprocess to potentially perform a sandbox escape via a crafted HTML page.\n(Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14429","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/520571816"],"bugs":[""],"patches":{"chromium-browser":[],"libskia":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]},{"name":"libskia","source":"https://ubuntu.com/security/cve?package=libskia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libskia","debian":"https://tracker.debian.org/pkg/libskia","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14428","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:48:02.721280+00:00","description":"\nInsufficient validation of untrusted input in Dawn in Google Chrome on\nAndroid prior to 150.0.7871.46 allowed a remote attacker who had\ncompromised the renderer process to potentially perform a sandbox escape\nvia a crafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14428","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/520180257"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14427","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nHeap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46\nallowed a remote attacker who had compromised the renderer process to\npotentially perform a sandbox escape via a crafted HTML page. (Chromium\nsecurity severity: Critical)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14427","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/520113415"],"bugs":[""],"patches":{"chromium-browser":[],"libskia":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]},{"name":"libskia","source":"https://ubuntu.com/security/cve?package=libskia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libskia","debian":"https://tracker.debian.org/pkg/libskia","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14426","published":"2026-07-01T23:16:00","updated_at":"2026-07-09T14:48:02.721280+00:00","description":"\nUse after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a\nremote attacker who convinced a user to engage in specific UI gestures to\nexecute arbitrary code inside a sandbox via a crafted HTML page. (Chromium\nsecurity severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14426","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/517981277"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":8080,"limit":20,"total_results":79316}