{"cves":[{"id":"CVE-2026-45591","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:13:31.955541+00:00","description":"\nUncontrolled resource consumption in ASP.NET Core allows an unauthorized\nattacker to deny service over a network.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45591","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-june-2026-servicing-updates","https://github.com/dotnet/announcements/issues/405","https://ubuntu.com/security/notices/USN-8420-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"jammy","status":"released","description":"8.0.128-8.0.28-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.128-8.0.28-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.0.128-8.0.28-0ubuntu1~25.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"questing","status":"released","description":"9.0.118-9.0.17-0ubuntu1~25.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"noble","status":"released","description":"10.0.109-10.0.9-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"10.0.109-10.0.9-0ubuntu1~25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.109-10.0.9-0ubuntu1~26.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8420-1"],"notices":[{"id":"USN-8420-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-11T06:57:20.480950","description":"It was discovered that .NET did not properly handle link resolution before\nfile access. A local attacker could use this issue to perform unauthorized\nfile tampering and write arbitrary files outside of the intended extraction\ndirectory. (CVE-2026-45491)\n\nIt was discovered that .NET did not properly handle deeply-nested\nMessagePack arrays. An attacker could use this to cause .NET to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-45591)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"}],"questing":[{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~25.10.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~25.10.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet9","version":"9.0.118-9.0.17-0ubuntu1~25.10.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-apphost-pack-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-host-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-hostfxr-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-dbg-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-9.0-source-built-artifacts","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-aot-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-dbg-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-targeting-pack-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-templates-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet9","version":"9.0.118-9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45491","CVE-2026-45591"]}]},{"id":"CVE-2026-45491","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:13:31.955541+00:00","description":"\nImproper link resolution before file access ('link following') in .NET\nallows an unauthorized attacker to perform tampering locally.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45491","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-june-2026-servicing-updates","https://github.com/dotnet/announcements/issues/404","https://ubuntu.com/security/notices/USN-8420-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"jammy","status":"released","description":"8.0.128-8.0.28-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.128-8.0.28-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.0.128-8.0.28-0ubuntu1~25.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"questing","status":"released","description":"9.0.118-9.0.17-0ubuntu1~25.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"noble","status":"released","description":"10.0.109-10.0.9-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"10.0.109-10.0.9-0ubuntu1~25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.109-10.0.9-0ubuntu1~26.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8420-1"],"notices":[{"id":"USN-8420-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-11T06:57:20.480950","description":"It was discovered that .NET did not properly handle link resolution before\nfile access. A local attacker could use this issue to perform unauthorized\nfile tampering and write arbitrary files outside of the intended extraction\ndirectory. (CVE-2026-45491)\n\nIt was discovered that .NET did not properly handle deeply-nested\nMessagePack arrays. An attacker could use this to cause .NET to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-45591)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.128-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.109-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.128-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~24.04.1","pocket":"security"}],"questing":[{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~25.10.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~25.10.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet9","version":"9.0.118-9.0.17-0ubuntu1~25.10.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-apphost-pack-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-host-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-hostfxr-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-runtime-dbg-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-9.0-source-built-artifacts","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-aot-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-sdk-dbg-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-targeting-pack-9.0","version":"9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.109-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet-templates-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet8","version":"8.0.128-8.0.28-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"dotnet9","version":"9.0.118-9.0.17-0ubuntu1~25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.128-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.128-8.0.28-0ubuntu1~25.10.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-9.0","version":"9.0.118-0ubuntu1~25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet9","version_link":"https://launchpad.net/ubuntu/+source/dotnet9/9.0.118-9.0.17-0ubuntu1~25.10.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.109-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.109-10.0.9-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.109-10.0.9-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45491","CVE-2026-45591"]}]},{"id":"CVE-2026-45490","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:13:31.955541+00:00","description":"\nImproper authorization in .NET allows an authorized attacker to elevate\nprivileges locally.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45490","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-june-2026-servicing-updates","https://github.com/dotnet/announcements/issues/403"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45447","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:31:39.771355+00:00","description":"\nIssue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being high severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 are vulnerable\nto this issue."}],"codename":null,"priority":"high","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45447","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-2","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.1.1-1ubuntu2.1~18.04.23+esm9","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.1.1f-1ubuntu2.24+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.27+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.20+esm16","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2n-1ubuntu5.13+esm5","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8414-2","USN-8414-1"],"notices":[{"id":"USN-8414-2","title":"OpenSSL vulnerabilities","summary":"USN-8414-1 fixed several vulnerabilities in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T18:29:37.094691","description":"USN-8414-1 fixed several vulnerabilities in OpenSSL. This update provides\nthe corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu\n18.04 LTS, and Ubuntu 20.04 LTS.\n\n Original advisory details:\n\nFrank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-34180","CVE-2026-42766","CVE-2026-7383","CVE-2026-9076"]},{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-45446","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:30:33.830715+00:00","description":"\nIssue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant\nAEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success\nonly\nif the tag is verified succesfully.\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds\nits\nall-zeros value.\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do\nnot\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC)\nsupport\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip\nthe\nciphertext update when a message with an empty ciphertext arrives.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4 and 3.0 (AES-SIV mode only) are\nvulnerable to this issue."}],"codename":null,"priority":"low","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45446","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-45445","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:30:10.547932+00:00","description":"\nIssue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4 and 3.0 are vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45445","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-42771","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:13:31.955541+00:00","description":"\nIssue summary: When the X509_VERIFY_PARAM_set1_email is called by an\napplication to validate a crafted e-mail address, such as during S/MIME\nmessage validation, an out of bounds read can happen.\nImpact summary: This out of bounds read will not directly exfiltrate\nthe data read to the attacker so the most likely result is a crash and\na Denial of Service.\nAn internal helper function called from X509_VERIFY_PARAM_[set|add]_email()\nused a wrong length when validating the local part of an email address.\nThis could cause the 64 octet limit on the local part of an email address\nto be not enforced, or cause an out of bound read and potentially a crash.\nThe bug is reachable via S-MIME validation with a crafted From: address\nsupplied in an email message that can potentially cause a crash.\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0 is vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42771"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"4.0+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"4.0+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42770","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:31:58.109139+00:00","description":"\nIssue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the\nvalue\nof q is not compared.\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4, and 3.0 are vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42770","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-42769","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:29:53.210480+00:00","description":"\nIssue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority\n(RA)\nlevel to the root Certification Authority (root CA) level.\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the\n'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process\nineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\nSignificant preconditions for the attack (having valid RA-level\ncredentials)\nare the reason the issue was assigned Low severity.\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, and 3.4 are vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42769","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-42768","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:30:01.267567+00:00","description":"\nIssue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable\nto\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\nImpact summary: The Bleichenbacher-style attack allows an attacker to use\nthe\nvictim's vulnerable application as a way to decrypt or sign messages with\nthe\nvictim's private RSA key.\nThe attack is possible in 2 variants.\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over\nevery\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts\nany\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature\nunder\nit.\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided\nwith\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\nAn attacker who authors a message and is able to compare both error code\nand\nthe result of the decryption, can mount a Bleichenbacher oracle.\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism\ndescribed\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue,\nas\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4 are vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42768","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-42767","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:29:46.135310+00:00","description":"\nIssue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client\napplication.\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\nAn attacker controlling a CMP server (or acting as a man-in-the-middle)\ncould\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\nApplications that process untrusted CMP/CRMF messages may be affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4, and 3.0 are vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42767","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-42766","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:31:21.628182+00:00","description":"\nIssue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in\nspecially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether\nit\nwas present.\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\nApplications that process password-encrypted CMS messages may be affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 are vulnerable\nto this issue."}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42766","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-2","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.1.1-1ubuntu2.1~18.04.23+esm9","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.1.1f-1ubuntu2.24+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.27+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.20+esm16","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2n-1ubuntu5.13+esm5","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8414-2","USN-8414-1"],"notices":[{"id":"USN-8414-2","title":"OpenSSL vulnerabilities","summary":"USN-8414-1 fixed several vulnerabilities in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T18:29:37.094691","description":"USN-8414-1 fixed several vulnerabilities in OpenSSL. This update provides\nthe corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu\n18.04 LTS, and Ubuntu 20.04 LTS.\n\n Original advisory details:\n\nFrank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-34180","CVE-2026-42766","CVE-2026-7383","CVE-2026-9076"]},{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-42765","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:13:17.805812+00:00","description":"\nIssue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL\ndereference\nwill happen if the verified chain does not have a self-signed trusted\nanchor,\ncrashing the process.\nImpact summary: A NULL pointer dereference can trigger a crash which leads\nto a\nDenial of Service for an application.\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed\ntrusted\nanchor, the issuer will be NULL for the last certificate in the chain. A\nNULL\npointer dereference then happens.\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0 and 3.6 are vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42765"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.6+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.6+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42764","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:30:41.463209+00:00","description":"\nIssue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\nImpact summary: NULL pointer dereference typically causes abnormal\ntermination\nof the affected QUIC server process and a Denial of Service.\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\nBy default, the client address validation is enabled in the OpenSSL QUIC\nserver\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, and 3.5 are vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42764","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.5+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-41855","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nIn an untrusted JMS environment,\norg.springframework.jms.support.converter.MappingJackson2MessageConverter\nand org.springframework.jms.support.converter.JacksonJsonMessageConverter\nallow arbitrary class instantiation, which can lead to unauthorized actions\nvia gadget class deserialization.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41855","https://spring.io/security/cve-2026-41855"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41854","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nDue to incorrect host parsing, applications that rely on\nUriComponentsBuilder to parse and validate an externally provided URL\nstring may be exposed to a server-side request forgery (SSRF) attack.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41854","https://spring.io/security/cve-2026-41854"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Spring 6 and later","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41853","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nSpring MVC and WebFlux applications are vulnerable to Multipart request\nsmuggling attacks.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41853","https://spring.io/security/cve-2026-41853"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41852","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nA vulnerability in Spring Expression Language (SpEL) evaluation logic\nallows for arbitrary zero-argument method invocation, even within\nrestricted or read-only contexts, which may allow an attacker to invoke\nunintended application logic.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41852","https://spring.io/security/cve-2026-41852"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41851","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nApplications which accept user-supplied Spring Expression Language (SpEL)\nexpressions may be vulnerable to a Denial of Service (DoS) attack if the\nevaluation of a SpEL expression triggers unbounded cache growth.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41851","https://spring.io/security/cve-2026-41851"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41850","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nApplications that evaluate user-supplied Spring Expression Language (SpEL)\nexpressions are vulnerable to an Algorithmic Denial of Service (DoS). By\nproviding a specially crafted expression, an attacker can trigger excessive\nresource consumption during evaluation, leading to application degradation\nor unavailability.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41850","https://spring.io/security/cve-2026-41850"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":9900,"limit":20,"total_results":79316}