{"cves":[{"id":"CVE-2026-41849","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nAn integer overflow vulnerability exists in the evaluation logic of the\nSpring Expression Language (SpEL). An attacker can exploit this by\nsupplying a specially crafted SpEL expression that triggers excessive\nresource consumption, resulting in a Denial of Service (DoS).\nAffected versions:\nSpring Framework 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41849","https://spring.io/security/cve-2026-41849"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41848","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nApplications may be vulnerable to a Regular Expression Denial of Service\n(ReDoS) attack if an attacker is able to provide a pattern which is then\ndirectly or indirectly supplied to one of the following methods in\nAntPathMatcher: match(String pattern, String path), matchStart(String\npattern, String path), extractUriTemplateVariables(String pattern, String\npath).\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41848","https://spring.io/security/cve-2026-41848"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41847","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nSpring WebFlux applications may be vulnerable to a security bypass when\nusing the Kotlin Router DSL.\nAffected versions:\nSpring Framework 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41847","https://spring.io/security/cve-2026-41847"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41846","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:30.702912+00:00","description":"\nSpring MVC applications which accept user-supplied values in the cssClass,\ncssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary\nHTML/JavaScript code injection, potentially resulting in a cross-site\nscripting (XSS) vulnerability.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41846","https://spring.io/security/cve-2026-41846"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41845","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nDue to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape()\nmay lead to JavaScript code injection in the browser, potentially resulting\nin a cross-site scripting (XSS) vulnerability.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41845","https://spring.io/security/cve-2026-41845"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41844","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nA Spring MVC or Spring WebFlux application which configures a mapping for\n\"/**\" where the view name is not explicitly specified allows an attacker to\ncraft a link resulting in a 302 redirect to an arbitrary external host via\nthe redirect: prefix.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41844","https://spring.io/security/cve-2026-41844"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41843","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nSpring MVC and WebFlux applications are vulnerable to Path Traversal\nattacks when resolving static resources.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41843","https://spring.io/security/cve-2026-41843"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41842","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nSpring MVC and WebFlux applications are vulnerable to Denial of Service\n(DoS) attacks when resolving static resources.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41842","https://spring.io/security/cve-2026-41842"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41841","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nSpring MVC and WebFlux applications are vulnerable to Information\nDisclosure attacks when resolving static resources.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41841","https://spring.io/security/cve-2026-41841"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41840","published":"2026-06-09T00:00:00","updated_at":"2026-06-26T07:32:48.007984+00:00","description":"\nSpring WebFlux applications are vulnerable to Denial of Service (DoS)\nattacks when processing multipart requests.\nAffected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through\n6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41840","https://spring.io/security/cve-2026-41840"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41839","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nA WebFlux application with a compromised subdomain (for example,\ncompromised via cross-site scripting (XSS)) is vulnerable to an escalation\nattack exchanging a known session ID for that of an authenticated user.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41839","https://spring.io/security/cve-2026-41839"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41838","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:16.428935+00:00","description":"\nIDs for WebSocket sessions in the spring-websocket module are not\ncryptographically unpredictable, which may be possible to exploit in\ncombination with inadequate authorization rules.\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through\n6.1.27; 5.3.0 through 5.3.48.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41838","https://spring.io/security/cve-2026-41838"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-35188","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:43:58.127575+00:00","description":"\nIssue summary: A malicious server can exploit TLS OCSP stapling by\ndelivering\na crafted response through the status_request extension, triggering a\ndouble-free in the client's certificate verification path.\nImpact summary: Successful exploitation allows an attacker to corrupt heap\nmemory via a double-free, potentially leading to a Denial of Service or\npossibly an attacker controlled code execution or other undefined behavior.\nIf OCSP stapling is enabled and the TLS client connects to a malicious\nserver,\na crafted OCSP stapled response can trigger a double free in the TLS client\nwhen the stapled response is checked.\nThe OCSP stapling is not enabled by default. Reliable code execution\nthrough a double-free is technically complex and highly\nenvironment-dependent\nbut the Denial of Service impact is straightforward to achieve, warranting\nModerate severity.\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0 and 3.6 are vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-35188"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.6+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.6+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.6+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-34183","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:24:03.825399+00:00","description":"\nIssue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 3.4, 3.5, 3.6 and 4.0 are vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34183","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-34182","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:25:21.282429+00:00","description":"\nIssue Summary: Cryptographic Message Services (CMS) processing fails to\nperform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass\nintegrity\nvalidation for a given message.\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher. OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine\nCEK\n(the content-encryption key), but with the inner OID rewritten to\nAES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under\nthe\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality\nfor the\nCEK used for the chosen recipient of the message.\nIn another use case, an attacker can reduce the tag length of the chosen\nAEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified\ncontent.\nThe FIPS modules are not affected by this issue.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4, and 3.0 are vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34182","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-2","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-2","USN-8414-1"],"notices":[{"id":"USN-8414-2","title":"OpenSSL vulnerabilities","summary":"USN-8414-1 fixed several vulnerabilities in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T18:29:37.094691","description":"USN-8414-1 fixed several vulnerabilities in OpenSSL. This update provides\nthe corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu\n18.04 LTS, and Ubuntu 20.04 LTS.\n\n Original advisory details:\n\nFrank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-34180","CVE-2026-42766","CVE-2026-7383","CVE-2026-9076"]},{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-34181","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:23:46.974625+00:00","description":"\nIssue Summary: The PKCS#12 file processing fails to perform sufficient\ninput\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key\nforgery.\nImpact Summary: An attacker impersonating a user can cause a service\nreading\nPKCS#12 files to accept forged certificates and private keys with a 1 in\n256\nprobability.\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte,\nallowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, and 3.4 are vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34181","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8414-1"],"notices":[{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-34180","published":"2026-06-09T00:00:00","updated_at":"2026-08-27T21:25:51.506701+00:00","description":"\nIssue summary: Parsing a crafted DER-encoded ASN.1 structure with a\nprimitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\nImpact summary: The heap buffer over-read may crash the application (Denial\nof\nService) or to load into the decoded ASN.1 object contents of memory beyond\nthe\nend of the input buffer. More typically such ASN.1 elements would instead\nbe\ntruncated.\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length\nof\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In\nthe\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read\neither\nless than or beyond the end of the allocated buffer.\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(),\nor\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked\nbefore\nit reaches the affected code. The issue only affects 64-bit Unix and\nUnix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this\nissue,\nas the affected code is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this as being low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nnodejs in jammy embeds OpenSSL 1.1.1m\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable\nto this issue."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34180","https://openssl-library.org/news/secadv/20260609.txt","https://ubuntu.com/security/notices/USN-8414-2","https://ubuntu.com/security/notices/USN-8414-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.12+Fips1","component":null,"pocket":"fips-updates"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.1.1-1ubuntu2.1~18.04.23+esm9","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.1.1f-1ubuntu2.24+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.5.3-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.27+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.20+esm16","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2n-1ubuntu5.13+esm5","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8414-2","USN-8414-1"],"notices":[{"id":"USN-8414-2","title":"OpenSSL vulnerabilities","summary":"USN-8414-1 fixed several vulnerabilities in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T18:29:37.094691","description":"USN-8414-1 fixed several vulnerabilities in OpenSSL. This update provides\nthe corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu\n18.04 LTS, and Ubuntu 20.04 LTS.\n\n Original advisory details:\n\nFrank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-34180","CVE-2026-42766","CVE-2026-7383","CVE-2026-9076"]},{"id":"USN-8414-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-06-09T17:14:22.220064","description":"Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nPavol Zacik and Alex Gaynor discovered that OpenSSL incorrectly accepted\nPKCS#12 files with short HMAC keys when using PBMAC1. An attacker could\npossibly use this issue to bypass integrity checks. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-34181)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nAbhinav Agarwal discovered that OpenSSL had unbounded memory growth in the\nQUIC PATH_CHALLENGE handler. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive resources, leading to a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-34183)\n\nSunwoo Lee, Hyuk Lim, and Seunghyun Yoon discovered that OpenSSL had a NULL\npointer dereference in QUIC server initial packet handling. A remote\nattacker could possibly use this issue to cause OpenSSL to crash, resulting\nin a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu\n26.04 LTS. (CVE-2026-42764)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nAlex Gaynor discovered that OpenSSL had a Bleichenbacher oracle in\nCMS_decrypt() and PKCS7_decrypt() with multiple RecipientInfo values. An\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-42768)\n\nAlex Gaynor discovered that OpenSSL had a trust-anchor substitution issue\nin CMP rootCaKeyUpdate processing. An attacker could possibly use this\nissue to bypass certificate trust validation. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42769)\n\nAlex Gaynor discovered that OpenSSL used attacker-supplied parameters when\nvalidating FFC-DH peers. An attacker could possibly use this issue to\nweaken key validation and compromise security guarantees. (CVE-2026-42770)\n\nAlex Gaynor discovered that OpenSSL could ignore the IV in AES-OCB mode on\nthe EVP_Cipher() path. An attacker could possibly use this issue to bypass\ncryptographic protections and obtain sensitive information.\n(CVE-2026-45445)\n\nAlex Gaynor discovered that OpenSSL had incorrect tag processing for empty\nmessages in AES-GCM-SIV and AES-SIV modes. An attacker could possibly use\nthis issue to bypass cryptographic integrity checks. (CVE-2026-45446)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.25","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.11","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.11","pocket":"security"}],"questing":[{"name":"openssl","version":"3.5.3-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.3-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.3-1ubuntu3.4","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45447","CVE-2026-34182","CVE-2026-42764","CVE-2026-45446","CVE-2026-42766","CVE-2026-34180","CVE-2026-7383","CVE-2026-34183","CVE-2026-9076","CVE-2026-42770","CVE-2026-34181","CVE-2026-42769","CVE-2026-42768","CVE-2026-45445","CVE-2026-42767"]}]},{"id":"CVE-2026-11701","published":"2026-06-09T00:00:00","updated_at":"2026-06-18T18:13:05.132346+00:00","description":"\nInappropriate implementation in Guest View in Google Chrome prior to\n149.0.7827.103 allowed a remote attacker to perform UI spoofing via a\ncrafted HTML page. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11701","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html","https://issues.chromium.org/issues/516413817"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11700","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:02.179740+00:00","description":"\nUse after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed\na remote attacker who had compromised the renderer process to potentially\nperform a sandbox escape via a crafted HTML page. (Chromium security\nseverity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11700","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html","https://issues.chromium.org/issues/511732085"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11699","published":"2026-06-09T00:00:00","updated_at":"2026-06-09T18:26:02.179740+00:00","description":"\nUse after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103\nallowed a remote attacker to potentially exploit heap corruption via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11699","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html","https://issues.chromium.org/issues/518237527"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":9920,"limit":20,"total_results":79316}