{"grype_matches":[{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77692","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77692","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77692","cwe":"CWE-476","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77692","date":"2026-10-08","epss":0.06558,"percentile":0.93644}],"risk":3.279,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77692"},"relatedVulnerabilities":[{"id":"CVE-2026-77692","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77692","cwe":"CWE-476","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77692","date":"2026-10-08","epss":0.06558,"percentile":0.93644}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-77692"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77692","description":"An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77692","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77692","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77692","cwe":"CWE-476","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77692","date":"2026-10-08","epss":0.06558,"percentile":0.93644}],"risk":3.279,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77692"},"relatedVulnerabilities":[{"id":"CVE-2026-77692","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77692","cwe":"CWE-476","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77692","date":"2026-10-08","epss":0.06558,"percentile":0.93644}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-77692"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77692","description":"An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":">=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48959"},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.2925,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84782"},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.2925,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84782"},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.2925,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84782"},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19666","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19666","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19666","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19666","date":"2026-10-08","epss":0.00569,"percentile":0.4536}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19666"},"relatedVulnerabilities":[{"id":"CVE-2026-19666","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19666","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19666","date":"2026-10-08","epss":0.00569,"percentile":0.4536}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19666"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19666","description":"On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19666","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19666","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19666","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19666","date":"2026-10-08","epss":0.00569,"percentile":0.4536}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19666"},"relatedVulnerabilities":[{"id":"CVE-2026-19666","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19666","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19666","date":"2026-10-08","epss":0.00569,"percentile":0.4536}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19666"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19666","description":"On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19667","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19667","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19667","cwe":"CWE-197","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19667","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19667"},"relatedVulnerabilities":[{"id":"CVE-2026-19667","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19667","cwe":"CWE-197","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19667","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19667"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19667","description":"If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76163","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76163","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76163","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-76163","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76163"},"relatedVulnerabilities":[{"id":"CVE-2026-76163","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76163","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-76163","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-76163"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76163","description":"If BIND is loaded with a \"`named.conf`\" file that contains no global \"`options`\" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80274","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-80274","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-80274","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-80274","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80274"},"relatedVulnerabilities":[{"id":"CVE-2026-80274","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80274","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-80274","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-80274"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80274","description":"If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-81563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-81563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-81563","cwe":"CWE-401","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81563","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-81563"},"relatedVulnerabilities":[{"id":"CVE-2026-81563","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81563","cwe":"CWE-401","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81563","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-81563"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81563","description":"A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.\nThis issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19667","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19667","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19667","cwe":"CWE-197","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19667","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19667"},"relatedVulnerabilities":[{"id":"CVE-2026-19667","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19667","cwe":"CWE-197","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19667","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19667"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19667","description":"If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76163","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76163","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76163","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-76163","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76163"},"relatedVulnerabilities":[{"id":"CVE-2026-76163","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76163","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-76163","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-76163"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76163","description":"If BIND is loaded with a \"`named.conf`\" file that contains no global \"`options`\" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80274","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-80274","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-80274","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-80274","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80274"},"relatedVulnerabilities":[{"id":"CVE-2026-80274","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80274","cwe":"CWE-617","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-80274","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-80274"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80274","description":"If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-81563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-81563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-81563","cwe":"CWE-401","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81563","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-81563"},"relatedVulnerabilities":[{"id":"CVE-2026-81563","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81563","cwe":"CWE-401","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81563","date":"2026-10-08","epss":0.00569,"percentile":0.45359}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-81563"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81563","description":"A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.\nThis issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-81736","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-81736","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-81736","cwe":"CWE-1050","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81736","date":"2026-10-08","epss":0.00569,"percentile":0.45358}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-81736"},"relatedVulnerabilities":[{"id":"CVE-2026-81736","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81736","cwe":"CWE-1050","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81736","date":"2026-10-08","epss":0.00569,"percentile":0.45358}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-81736"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81736","description":"If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.\nThis issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-81736","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-81736","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-81736","cwe":"CWE-1050","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81736","date":"2026-10-08","epss":0.00569,"percentile":0.45358}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-81736"},"relatedVulnerabilities":[{"id":"CVE-2026-81736","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81736","cwe":"CWE-1050","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-81736","date":"2026-10-08","epss":0.00569,"percentile":0.45358}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-81736"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81736","description":"If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.\nThis issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.24750000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48962"},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19668","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19668","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19668","cwe":"CWE-407","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19668","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"risk":0.24,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19668"},"relatedVulnerabilities":[{"id":"CVE-2026-19668","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19668","cwe":"CWE-407","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19668","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19668"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19668","description":"A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record.  Default limits on \"max-records-per-type\" and \"max-types-per-name\" help mitigate the exposure.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75029","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75029","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-75029","cwe":"CWE-405","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-75029","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"risk":0.24,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75029"},"relatedVulnerabilities":[{"id":"CVE-2026-75029","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75029","cwe":"CWE-405","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-75029","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-75029"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75029","description":"In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19668","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19668","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19668","cwe":"CWE-407","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19668","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"risk":0.24,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19668"},"relatedVulnerabilities":[{"id":"CVE-2026-19668","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19668","cwe":"CWE-407","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19668","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19668"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19668","description":"A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record.  Default limits on \"max-records-per-type\" and \"max-types-per-name\" help mitigate the exposure.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75029","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75029","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-75029","cwe":"CWE-405","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-75029","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"risk":0.24,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75029"},"relatedVulnerabilities":[{"id":"CVE-2026-75029","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75029","cwe":"CWE-405","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-75029","date":"2026-10-08","epss":0.0048,"percentile":0.39416}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-75029"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75029","description":"In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42497"},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19662","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19662","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19662","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19662","date":"2026-10-08","epss":0.00464,"percentile":0.38222}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19662"},"relatedVulnerabilities":[{"id":"CVE-2026-19662","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19662","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19662","date":"2026-10-08","epss":0.00464,"percentile":0.38222}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://kb.isc.org/docs/cve-2026-19662"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19662","description":"An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19662","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19662","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19662","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19662","date":"2026-10-08","epss":0.00464,"percentile":0.38222}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19662"},"relatedVulnerabilities":[{"id":"CVE-2026-19662","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19662","cwe":"CWE-416","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19662","date":"2026-10-08","epss":0.00464,"percentile":0.38222}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://kb.isc.org/docs/cve-2026-19662"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19662","description":"An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.22399999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-9538"},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.15.2+dfsg-0.1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"< 2.15.2+dfsg-0.1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"fixed","versions":["2.15.2+dfsg-0.1ubuntu0.2"],"available":[{"date":"2026-09-21","kind":"advisory","version":"2.15.2+dfsg-0.1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.218,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-74860"},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-7ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.40.1-7ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.40.1-7ubuntu0.3"],"available":[{"date":"2026-09-09","kind":"advisory","version":"5.40.1-7ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.216,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13221"},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-48961","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"risk":0.2035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48961"},"relatedVulnerabilities":[{"id":"CVE-2026-48961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-7ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.40.1-7ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.40.1-7ubuntu0.3"],"available":[{"date":"2026-09-09","kind":"advisory","version":"5.40.1-7ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.187,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12087"},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-7ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.40.1-7ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.40.1-7ubuntu0.3"],"available":[{"date":"2026-09-09","kind":"advisory","version":"5.40.1-7ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.1785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57433"},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"86f95184cf4bd2b5","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1ubuntu3.1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1ubuntu3.1?arch=amd64&distro=ubuntu-26.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg+really1.3.1-1ubuntu3.1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1ubuntu3.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"1ce77119307aa4a5","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"c8481e5ece0d4908","cpes":["cpe:2.3:a:libc-gconv-modules-extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules-extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-gconv-modules-extra","purl":"pkg:deb/ubuntu/libc-gconv-modules-extra@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-gconv-modules-extra/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-gconv-modules-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"c513001c6e67b66e","cpes":["cpe:2.3:a:libc6:libc6:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"1ce77119307aa4a5","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"c8481e5ece0d4908","cpes":["cpe:2.3:a:libc-gconv-modules-extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules-extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-gconv-modules-extra","purl":"pkg:deb/ubuntu/libc-gconv-modules-extra@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-gconv-modules-extra/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-gconv-modules-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"c513001c6e67b66e","cpes":["cpe:2.3:a:libc6:libc6:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.5-1ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.7"],"available":[{"date":"2026-10-01","kind":"advisory","version":"3.5.5-1ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.13859999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54873"},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.5-1ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.7"],"available":[{"date":"2026-10-01","kind":"advisory","version":"3.5.5-1ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.13859999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54873"},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.5-1ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.7"],"available":[{"date":"2026-10-01","kind":"advisory","version":"3.5.5-1ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.13859999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54873"},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"1ce77119307aa4a5","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"c8481e5ece0d4908","cpes":["cpe:2.3:a:libc-gconv-modules-extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules-extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-gconv-modules-extra","purl":"pkg:deb/ubuntu/libc-gconv-modules-extra@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-gconv-modules-extra/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-gconv-modules-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"c513001c6e67b66e","cpes":["cpe:2.3:a:libc6:libc6:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"192c175d5c1b17cf","cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2ubuntu3:*:*:*:*:*:*:*"],"name":"login.defs","purl":"pkg:deb/ubuntu/login.defs@1%3A4.17.4-2ubuntu3?arch=all&distro=ubuntu-26.04&upstream=shadow","type":"deb","version":"1:4.17.4-2ubuntu3","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login.defs/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/login.defs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"shadow","version":"1:4.17.4-2ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"50cd5c7e27977f62","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2ubuntu3:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.17.4-2ubuntu3?arch=amd64&distro=ubuntu-26.04&upstream=shadow","type":"deb","version":"1:4.17.4-2ubuntu3","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"shadow","version":"1:4.17.4-2ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7017"},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.12089999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84784"},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.12089999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84784"},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.12089999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84784"},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19033","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19033","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19033","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19033","date":"2026-10-08","epss":0.0024,"percentile":0.13929}],"risk":0.12,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19033"},"relatedVulnerabilities":[{"id":"CVE-2026-19033","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19033","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19033","date":"2026-10-08","epss":0.0024,"percentile":0.13929}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19033"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19033","description":"For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19033","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19033","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19033","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19033","date":"2026-10-08","epss":0.0024,"percentile":0.13929}],"risk":0.12,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19033"},"relatedVulnerabilities":[{"id":"CVE-2026-19033","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19033","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19033","date":"2026-10-08","epss":0.0024,"percentile":0.13929}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19033"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19033","description":"For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.1161,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75806"},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.1161,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75806"},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.1161,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75806"},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19941","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19941","cwe":"CWE-345","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19941","date":"2026-10-08","epss":0.00226,"percentile":0.12254}],"risk":0.11299999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19941"},"relatedVulnerabilities":[{"id":"CVE-2026-19941","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19941","cwe":"CWE-345","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19941","date":"2026-10-08","epss":0.00226,"percentile":0.12254}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19941"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19941","description":"An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-19941","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19941","cwe":"CWE-345","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19941","date":"2026-10-08","epss":0.00226,"percentile":0.12254}],"risk":0.11299999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19941"},"relatedVulnerabilities":[{"id":"CVE-2026-19941","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19941","cwe":"CWE-345","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-19941","date":"2026-10-08","epss":0.00226,"percentile":0.12254}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-19941"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19941","description":"An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77119","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77119","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77119","cwe":"CWE-346","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77119","date":"2026-10-08","epss":0.00226,"percentile":0.12253}],"risk":0.11299999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77119"},"relatedVulnerabilities":[{"id":"CVE-2026-77119","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77119","cwe":"CWE-346","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77119","date":"2026-10-08","epss":0.00226,"percentile":0.12253}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-77119"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77119","description":"A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77119","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77119","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77119","cwe":"CWE-346","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77119","date":"2026-10-08","epss":0.00226,"percentile":0.12253}],"risk":0.11299999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77119"},"relatedVulnerabilities":[{"id":"CVE-2026-77119","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77119","cwe":"CWE-346","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-77119","date":"2026-10-08","epss":0.00226,"percentile":0.12253}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-77119"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77119","description":"A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"f03c62f9632aa8e3","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"a4959fa62617363e","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"b2cccac623466946","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"344371014bd8f630","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"7de018288807be5c","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"981aa9cfed164db1","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.16.0-2%2Breally2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:4.16.0-2+really2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"2e2d3e5090b27047","cpes":["cpe:2.3:a:mount:mount:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"09f0d5a732e9e0b3","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.10709999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35191"},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.10709999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35191"},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.10709999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35191"},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.10560000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75804"},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.10560000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75804"},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.10560000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75804"},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-7ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.40.1-7ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.40.1-7ubuntu0.3"],"available":[{"date":"2026-09-09","kind":"advisory","version":"5.40.1-7ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57432"},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"18d6d9052050fbfe","cpes":["cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_libs:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_libs:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-libs","purl":"pkg:deb/ubuntu/bind9-libs@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-libs/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-libs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-libs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78301","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78301","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78301","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-78301","date":"2026-10-08","epss":0.00207,"percentile":0.09884}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78301"},"relatedVulnerabilities":[{"id":"CVE-2026-78301","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.8,"impactScore":4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78301","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-78301","date":"2026-10-08","epss":0.00207,"percentile":0.09884}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-78301"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78301","description":"A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On a server that also provides recursion BIND can follow this locally sourced cut and cache attacker-supplied data, affecting names outside the configured zone. This situation persists as long as the malformed zone remains in the zone database.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"41a221af47920772","cpes":["cpe:2.3:a:bind9-utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9-utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9_utils:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9-utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:bind9:bind9_utils:1\\:9.20.24-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"bind9-utils","purl":"pkg:deb/ubuntu/bind9-utils@1%3A9.20.24-1ubuntu0.3?arch=amd64&distro=ubuntu-26.04&upstream=bind9","type":"deb","version":"1:9.20.24-1ubuntu0.3","language":"","licenses":["BSD-2-clause","BSD-3-clause","CC0-1.0","FSFAP","ISC","MPL-2.0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bind9-utils/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/bind9-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bind9-utils.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/bind9-utils.list"}],"upstreams":[{"name":"bind9"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78301","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"bind9","version":"1:9.20.24-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78301","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78301","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-78301","date":"2026-10-08","epss":0.00207,"percentile":0.09884}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78301"},"relatedVulnerabilities":[{"id":"CVE-2026-78301","cvss":[{"type":"Secondary","source":"security-officer@isc.org","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.8,"impactScore":4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78301","cwe":"CWE-349","type":"Secondary","source":"security-officer@isc.org"}],"epss":[{"cve":"CVE-2026-78301","date":"2026-10-08","epss":0.00207,"percentile":0.09884}],"urls":["https://downloads.isc.org/isc/bind9/9.20.29","https://downloads.isc.org/isc/bind9/9.21.26","https://kb.isc.org/docs/cve-2026-78301"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78301","description":"A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On a server that also provides recursion BIND can follow this locally sourced cut and cache attacker-supplied data, affecting names outside the configured zone. This situation persists as long as the malformed zone remains in the zone database.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.5-1ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.7"],"available":[{"date":"2026-10-01","kind":"advisory","version":"3.5.5-1ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.099,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42772"},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.5-1ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.7"],"available":[{"date":"2026-10-01","kind":"advisory","version":"3.5.5-1ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.099,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42772"},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.5-1ubuntu3.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.7"],"available":[{"date":"2026-10-01","kind":"advisory","version":"3.5.5-1ubuntu3.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.099,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42772"},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86137","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86137","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"risk":0.09749999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86137"},"relatedVulnerabilities":[{"id":"CVE-2026-86137","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"urls":["https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86137","description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86143","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"risk":0.097,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86143"},"relatedVulnerabilities":[{"id":"CVE-2026-86143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86144","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86144","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86144"},"relatedVulnerabilities":[{"id":"CVE-2026-86144","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}]},{"artifact":{"id":"f03c62f9632aa8e3","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"a4959fa62617363e","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"b2cccac623466946","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"344371014bd8f630","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"7de018288807be5c","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"981aa9cfed164db1","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.16.0-2%2Breally2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:4.16.0-2+really2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"2e2d3e5090b27047","cpes":["cpe:2.3:a:mount:mount:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"09f0d5a732e9e0b3","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.0882,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54875"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.0882,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54875"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.0882,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54875"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"3241626449a80bf7","cpes":["cpe:2.3:a:coreutils:coreutils:9.5-1ubuntu2\\+0.0.0\\~ubuntu25:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.5-1ubuntu2%2B0.0.0~ubuntu25?arch=all&distro=ubuntu-26.04&upstream=coreutils-from%400.0.0~ubuntu25","type":"deb","version":"9.5-1ubuntu2+0.0.0~ubuntu25","language":"","licenses":["GPL-3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[{"name":"coreutils-from","version":"0.0.0~ubuntu25"}]},"matchDetails":[{"fix":{"suggestedVersion":"9.7-3ubuntu2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5278","versionConstraint":"< 9.7-3ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"coreutils","version":"9.5-1ubuntu2+0.0.0~ubuntu25"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2025-5278","fix":{"state":"fixed","versions":["9.7-3ubuntu2.1"],"available":[{"date":"2026-08-31","kind":"advisory","version":"9.7-3ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5278","date":"2026-10-08","epss":0.00288,"percentile":0.19615}],"risk":0.0864,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-5278"},"relatedVulnerabilities":[{"id":"CVE-2025-5278","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5278","date":"2026-10-08","epss":0.00288,"percentile":0.19615}],"urls":["https://access.redhat.com/errata/RHSA-2026:28911","https://access.redhat.com/errata/RHSA-2026:33124","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33612","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:69964","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2025-5278","https://bugzilla.redhat.com/show_bug.cgi?id=2368764","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","http://www.openwall.com/lists/oss-security/2025/05/27/2","http://www.openwall.com/lists/oss-security/2025/05/29/1","http://www.openwall.com/lists/oss-security/2025/05/29/2","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","https://security-tracker.debian.org/tracker/CVE-2025-5278"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278","description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35363","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35363","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35363","cwe":"CWE-22","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35363","date":"2026-10-08","epss":0.00171,"percentile":0.05908}],"risk":0.08549999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35363"},"relatedVulnerabilities":[{"id":"CVE-2026-35363","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35363","cwe":"CWE-22","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35363","date":"2026-10-08","epss":0.00171,"percentile":0.05908}],"urls":["https://github.com/uutils/coreutils/issues/9749"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35363","description":"A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly refuses to delete . or .., it fails to recognize equivalent paths with trailing slashes, such as ./ or .///. An accidental or malicious execution of rm -rf ./ results in the silent recursive deletion of all contents within the current directory. The command further obscures the data loss by reporting a misleading 'Invalid input' error, which may cause users to miss the critical window for data recovery."}]},{"artifact":{"id":"3241626449a80bf7","cpes":["cpe:2.3:a:coreutils:coreutils:9.5-1ubuntu2\\+0.0.0\\~ubuntu25:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.5-1ubuntu2%2B0.0.0~ubuntu25?arch=all&distro=ubuntu-26.04&upstream=coreutils-from%400.0.0~ubuntu25","type":"deb","version":"9.5-1ubuntu2+0.0.0~ubuntu25","language":"","licenses":["GPL-3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[{"name":"coreutils-from","version":"0.0.0~ubuntu25"}]},"matchDetails":[{"fix":{"suggestedVersion":"9.7-3ubuntu2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56391","versionConstraint":"< 9.7-3ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"coreutils","version":"9.5-1ubuntu2+0.0.0~ubuntu25"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"fixed","versions":["9.7-3ubuntu2.1"],"available":[{"date":"2026-08-31","kind":"advisory","version":"9.7-3ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.08549999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56391"},"relatedVulnerabilities":[{"id":"CVE-2026-56391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-76781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"risk":0.0835,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76781"},"relatedVulnerabilities":[{"id":"CVE-2026-76781","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"urls":["https://access.redhat.com/errata/RHSA-2026:57604","https://access.redhat.com/security/cve/CVE-2026-76781","https://bugzilla.redhat.com/show_bug.cgi?id=2519776","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c6324894","https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/442"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76781","description":"A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS)."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86139","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86139","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86139","date":"2026-10-08","epss":0.00166,"percentile":0.05341}],"risk":0.083,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86139"},"relatedVulnerabilities":[{"id":"CVE-2026-86139","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86139","date":"2026-10-08","epss":0.00166,"percentile":0.05341}],"urls":["https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86139","description":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86141","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86141","cwe":"CWE-252","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86141","date":"2026-10-08","epss":0.00165,"percentile":0.05259}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86141"},"relatedVulnerabilities":[{"id":"CVE-2026-86141","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86141","cwe":"CWE-252","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86141","date":"2026-10-08","epss":0.00165,"percentile":0.05259}],"urls":["https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86141","description":"xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.08009999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35189"},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.08009999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35189"},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.08009999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35189"},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.0798,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-72897"},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.0798,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-72897"},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.0798,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-72897"},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.0789,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54872"},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.0789,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54872"},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.0789,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54872"},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.15.2+dfsg-0.1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86140","versionConstraint":"< 2.15.2+dfsg-0.1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86140","fix":{"state":"fixed","versions":["2.15.2+dfsg-0.1ubuntu0.2"],"available":[{"date":"2026-09-21","kind":"advisory","version":"2.15.2+dfsg-0.1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86140"},"relatedVulnerabilities":[{"id":"CVE-2026-86140","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86142","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86142"},"relatedVulnerabilities":[{"id":"CVE-2026-86142","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"f03c62f9632aa8e3","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"a4959fa62617363e","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"b2cccac623466946","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"344371014bd8f630","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"7de018288807be5c","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"981aa9cfed164db1","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.16.0-2%2Breally2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:4.16.0-2+really2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"2e2d3e5090b27047","cpes":["cpe:2.3:a:mount:mount:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"09f0d5a732e9e0b3","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f03c62f9632aa8e3","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"a4959fa62617363e","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"b2cccac623466946","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"344371014bd8f630","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"7de018288807be5c","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"981aa9cfed164db1","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.16.0-2%2Breally2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux%402.41.3-3ubuntu2.2","type":"deb","version":"1:4.16.0-2+really2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.3-3ubuntu2.2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"2e2d3e5090b27047","cpes":["cpe:2.3:a:mount:mount:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04&upstream=util-linux","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"09f0d5a732e9e0b3","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.3-3ubuntu2.2:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.41.3-3ubuntu2.2?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"2.41.3-3ubuntu2.2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"util-linux","version":"2.41.3-3ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"5aa7ffd2288489ce","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-2?arch=amd64&distro=ubuntu-26.04&upstream=acl","type":"deb","version":"2.3.2-2","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"3161eb548068f7a9","cpes":["cpe:2.3:a:liblmdb0:liblmdb0:0.9.31-1build2:*:*:*:*:*:*:*"],"name":"liblmdb0","purl":"pkg:deb/ubuntu/liblmdb0@0.9.31-1build2?arch=amd64&distro=ubuntu-26.04&upstream=lmdb","type":"deb","version":"0.9.31-1build2","language":"","licenses":["OpenLDAP-2.8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblmdb0/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/liblmdb0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblmdb0:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/liblmdb0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"lmdb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-22185","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"lmdb","version":"0.9.31-1build2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-22185","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-22185","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-22185","date":"2026-10-08","epss":0.00152,"percentile":0.03787}],"risk":0.076,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-22185"},"relatedVulnerabilities":[{"id":"CVE-2026-22185","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-22185","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-22185","date":"2026-10-08","epss":0.00152,"percentile":0.03787}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=10421","https://seclists.org/fulldisclosure/2026/Jan/5","https://seclists.org/fulldisclosure/2026/Jan/8","https://www.openldap.org/","https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22185","description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35368","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35368","cwe":"CWE-426","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35368","date":"2026-10-08","epss":0.00147,"percentile":0.03427}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35368"},"relatedVulnerabilities":[{"id":"CVE-2026-35368","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":6.1,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35368","cwe":"CWE-426","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35368","date":"2026-10-08","epss":0.00147,"percentile":0.03427}],"urls":["https://github.com/uutils/coreutils/issues/10327"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35368","description":"A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load shared libraries (e.g., libnss_*.so.2) from the new root directory. If the NEWROOT is writable by an attacker, they can inject a malicious NSS module to execute arbitrary code as root, facilitating a full container escape or privilege escalation."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.07289999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77696"},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.07289999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77696"},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.07289999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77696"},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"277f395452b739ec","cpes":["cpe:2.3:a:dash:dash:0.5.12-12ubuntu3:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-12ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.5.12-12ubuntu3","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.preinst"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.prerm"},{"path":"/var/lib/dpkg/info/dash.templates","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.templates"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"dash","version":"0.5.12-12ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"1ce77119307aa4a5","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"c8481e5ece0d4908","cpes":["cpe:2.3:a:libc-gconv-modules-extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules-extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-gconv-modules-extra","purl":"pkg:deb/ubuntu/libc-gconv-modules-extra@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-gconv-modules-extra/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-gconv-modules-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"c513001c6e67b66e","cpes":["cpe:2.3:a:libc6:libc6:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35341","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35341","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35341","cwe":"CWE-732","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35341","date":"2026-10-08","epss":0.00141,"percentile":0.0295}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35341"},"relatedVulnerabilities":[{"id":"CVE-2026-35341","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35341","cwe":"CWE-732","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35341","date":"2026-10-08","epss":0.00141,"percentile":0.0295}],"urls":["https://github.com/uutils/coreutils/issues/10020"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35341","description":"A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a follow-up set_permissions call. This results in the existing file's permissions being changed to the default mode (often 644 after umask), potentially exposing sensitive files such as SSH private keys to other users on the system."}]},{"artifact":{"id":"b4411343a9990784","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-4ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-4ubuntu0.4?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"1.35+dfsg-4ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"tar","version":"1.35+dfsg-4ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35351","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35351","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35351","cwe":"CWE-281","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35351","date":"2026-10-08","epss":0.0014,"percentile":0.0287}],"risk":0.06999999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35351"},"relatedVulnerabilities":[{"id":"CVE-2026-35351","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35351","cwe":"CWE-281","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35351","date":"2026-10-08","epss":0.0014,"percentile":0.0287}],"urls":["https://github.com/uutils/coreutils/issues/9714"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35351","description":"The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destination file using the caller's UID/GID rather than the source's metadata. This flaw breaks backups and migrations, causing files moved by a privileged user (e.g., root) to become root-owned unexpectedly, which can lead to information disclosure or restricted access for the intended owners."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93658","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-93658","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93658","cwe":"CWE-281","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93658","date":"2026-10-08","epss":0.00139,"percentile":0.02797}],"risk":0.06949999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93658"},"relatedVulnerabilities":[{"id":"CVE-2026-93658","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93658","cwe":"CWE-281","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93658","date":"2026-10-08","epss":0.00139,"percentile":0.02797}],"urls":["https://github.com/uutils/coreutils","https://github.com/uutils/coreutils/blob/0.9.0/src/uu/install/src/install.rs","https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1f55","https://github.com/uutils/coreutils/pull/13629","https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m","https://www.vulncheck.com/advisories/uutils-coreutils-0.0.18-before-0.10.0-privilege-escalation-via-setuid"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93658","description":"uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35371","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35371","cwe":"CWE-451","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35371","date":"2026-10-08","epss":0.00137,"percentile":0.02672}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35371"},"relatedVulnerabilities":[{"id":"CVE-2026-35371","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35371","cwe":"CWE-451","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35371","date":"2026-10-08","epss":0.00137,"percentile":0.02672}],"urls":["https://github.com/uutils/coreutils/issues/10006"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35371","description":"The id utility in uutils coreutils exhibits incorrect behavior in its \"pretty print\" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35373","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35373","cwe":"CWE-176","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35373","date":"2026-10-08","epss":0.00135,"percentile":0.02553}],"risk":0.0675,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35373"},"relatedVulnerabilities":[{"id":"CVE-2026-35373","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35373","cwe":"CWE-176","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35373","date":"2026-10-08","epss":0.00135,"percentile":0.02553}],"urls":["https://github.com/uutils/coreutils/pull/11403"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35373","description":"A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms (e.g., ln SOURCE... DIRECTORY). While GNU ln treats filenames as raw bytes and creates the links correctly, the uutils implementation enforces UTF-8 encoding, resulting in a failure to stat the file and a non-zero exit code. In environments where automated scripts or system tasks process valid but non-UTF-8 filenames common on Unix filesystems, this divergence causes the utility to fail, leading to a local denial of service for those specific operations."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35348","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35348","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35348","cwe":"CWE-248","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35348","date":"2026-10-08","epss":0.00135,"percentile":0.0254}],"risk":0.0675,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35348"},"relatedVulnerabilities":[{"id":"CVE-2026-35348","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35348","cwe":"CWE-248","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35348","date":"2026-10-08","epss":0.00135,"percentile":0.0254}],"urls":["https://github.com/uutils/coreutils/issues/9696"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35348","description":"The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines."}]},{"artifact":{"id":"4a28e7c26f4102e0","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.0666,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75805"},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a42651cc33a72451","cpes":["cpe:2.3:a:openssl:openssl:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.0666,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75805"},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"20f5c6ed3a4b0365","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.5-1ubuntu3.5:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/ubuntu/openssl-provider-legacy@3.5.5-1ubuntu3.5?arch=amd64&distro=ubuntu-26.04&upstream=openssl","type":"deb","version":"3.5.5-1ubuntu3.5","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.5-1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"openssl","version":"3.5.5-1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.5-1ubuntu3.6"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.5.5-1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.0666,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75805"},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35350","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35350","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35350","cwe":"CWE-281","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35350","date":"2026-10-08","epss":0.00133,"percentile":0.02428}],"risk":0.0665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35350"},"relatedVulnerabilities":[{"id":"CVE-2026-35350","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35350","cwe":"CWE-281","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35350","date":"2026-10-08","epss":0.00133,"percentile":0.02428}],"urls":["https://github.com/uutils/coreutils/issues/9750"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35350","description":"The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35344","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35344","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35344","cwe":"CWE-252","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35344","date":"2026-10-08","epss":0.00133,"percentile":0.02421}],"risk":0.0665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35344"},"relatedVulnerabilities":[{"id":"CVE-2026-35344","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35344","cwe":"CWE-252","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35344","date":"2026-10-08","epss":0.00133,"percentile":0.02421}],"urls":["https://github.com/uutils/coreutils/issues/9745"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35344","description":"The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result::ok() on truncation attempts. While intended to mimic GNU behavior for special files like /dev/null, the uutils implementation also hides failures on regular files and directories caused by full disks or read-only file systems. This can lead to silent data corruption in backup or migration scripts, as the utility may report a successful operation even when the destination file contains old or garbage data."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86138","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86138","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"risk":0.066,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86138"},"relatedVulnerabilities":[{"id":"CVE-2026-86138","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"277f395452b739ec","cpes":["cpe:2.3:a:dash:dash:0.5.12-12ubuntu3:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-12ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.5.12-12ubuntu3","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.preinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.preinst"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.prerm"},{"path":"/var/lib/dpkg/info/dash.templates","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/dash.templates"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"dash","version":"0.5.12-12ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35367","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35367","cwe":"CWE-732","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35367","date":"2026-10-08","epss":0.0013,"percentile":0.02261}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35367"},"relatedVulnerabilities":[{"id":"CVE-2026-35367","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35367","cwe":"CWE-732","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35367","date":"2026-10-08","epss":0.0013,"percentile":0.02261}],"urls":["https://github.com/uutils/coreutils/issues/10021"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35367","description":"The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, typically resulting in a world-readable file (0644). In multi-user environments, this allows any user on the system to read the captured stdout/stderr output of a command, potentially exposing sensitive information. This behavior diverges from GNU coreutils, which creates nohup.out with owner-only (0600) permissions."}]},{"artifact":{"id":"1ce77119307aa4a5","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"c8481e5ece0d4908","cpes":["cpe:2.3:a:libc-gconv-modules-extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules-extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-gconv-modules-extra","purl":"pkg:deb/ubuntu/libc-gconv-modules-extra@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-gconv-modules-extra/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-gconv-modules-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"c513001c6e67b66e","cpes":["cpe:2.3:a:libc6:libc6:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"ec46134774a36e55","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-7ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.40.1-7ubuntu0.2?arch=amd64&distro=ubuntu-26.04&upstream=perl","type":"deb","version":"5.40.1-7ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"perl","version":"5.40.1-7ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.0635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15649"},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35370","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35370","cwe":"CWE-863","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35370","date":"2026-10-08","epss":0.00127,"percentile":0.02073}],"risk":0.0635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35370"},"relatedVulnerabilities":[{"id":"CVE-2026-35370","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35370","cwe":"CWE-863","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35370","date":"2026-10-08","epss":0.00127,"percentile":0.02073}],"urls":["https://github.com/uutils/coreutils/issues/10006"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35370","description":"The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations."}]},{"artifact":{"id":"2ab9a02662b35ad1","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1build1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.46-1build1?arch=amd64&distro=ubuntu-26.04&upstream=pcre2","type":"deb","version":"10.46-1build1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"pcre2","version":"10.46-1build1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35377","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35377","cwe":"CWE-20","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35377","date":"2026-10-08","epss":0.00126,"percentile":0.0198}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35377"},"relatedVulnerabilities":[{"id":"CVE-2026-35377","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35377","cwe":"CWE-20","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35377","date":"2026-10-08","epss":0.00126,"percentile":0.0198}],"urls":["https://github.com/uutils/coreutils/pull/11512"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35377","description":"A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In GNU env, backslashes within single quotes are treated literally (with the exceptions of \\\\ and \\'). However, the uutils implementation incorrectly attempts to validate these sequences, resulting in an \"invalid sequence\" error and an immediate process termination with an exit status of 125 when encountering valid but unrecognized sequences like \\a or \\x. This divergence from GNU behavior breaks compatibility for automated scripts and administrative workflows that rely on standard split-string semantics, leading to a local denial of service for those operations."}]},{"artifact":{"id":"1ce77119307aa4a5","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"c8481e5ece0d4908","cpes":["cpe:2.3:a:libc-gconv-modules-extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules-extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules_extra:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv-modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv_modules:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc-gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc_gconv:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-gconv-modules-extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_gconv_modules_extra:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc-gconv-modules-extra","purl":"pkg:deb/ubuntu/libc-gconv-modules-extra@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-gconv-modules-extra/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc-gconv-modules-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc-gconv-modules-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"c513001c6e67b66e","cpes":["cpe:2.3:a:libc6:libc6:2.43-2ubuntu2.4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.43-2ubuntu2.4?arch=amd64&distro=ubuntu-26.04&upstream=glibc","type":"deb","version":"2.43-2ubuntu2.4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GFDL-1.3","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"glibc","version":"2.43-2ubuntu2.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35352","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35352","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35352","date":"2026-10-08","epss":0.0012,"percentile":0.01642}],"risk":0.06,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35352"},"relatedVulnerabilities":[{"id":"CVE-2026-35352","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35352","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35352","date":"2026-10-08","epss":0.0012,"percentile":0.01642}],"urls":["https://github.com/uutils/coreutils/issues/10020","http://www.openwall.com/lists/oss-security/2026/05/04/4","http://www.openwall.com/lists/oss-security/2026/05/04/5","http://www.openwall.com/lists/oss-security/2026/05/04/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35352","description":"A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges."}]},{"artifact":{"id":"5aa7ffd2288489ce","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-2?arch=amd64&distro=ubuntu-26.04&upstream=acl","type":"deb","version":"2.3.2-2","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35359","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35359","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35359","cwe":"CWE-59","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-35359","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35359","date":"2026-10-08","epss":0.00106,"percentile":0.01038}],"risk":0.053,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35359"},"relatedVulnerabilities":[{"id":"CVE-2026-35359","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35359","cwe":"CWE-59","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-35359","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35359","date":"2026-10-08","epss":0.00106,"percentile":0.01038}],"urls":["https://github.com/uutils/coreutils/issues/10017"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35359","description":"A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass no-dereference intent. The utility checks if a source path is a symbolic link using path-based metadata but subsequently opens it without the O_NOFOLLOW flag. An attacker with concurrent write access can swap a regular file for a symbolic link during this window, causing a privileged cp process to copy the contents of arbitrary sensitive files into a destination controlled by the attacker."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35360","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35360","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35360","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35360","date":"2026-10-08","epss":0.001,"percentile":0.00805}],"risk":0.05,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35360"},"relatedVulnerabilities":[{"id":"CVE-2026-35360","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35360","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35360","date":"2026-10-08","epss":0.001,"percentile":0.00805}],"urls":["https://github.com/uutils/coreutils/issues/10019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35360","description":"The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35345","cwe":"CWE-59","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-35345","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35345","date":"2026-10-08","epss":0.001,"percentile":0.0079}],"risk":0.05,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35345"},"relatedVulnerabilities":[{"id":"CVE-2026-35345","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35345","cwe":"CWE-59","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-35345","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35345","date":"2026-10-08","epss":0.001,"percentile":0.0079}],"urls":["https://github.com/uutils/coreutils/issues/10328"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35345","description":"A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, the uutils implementation continues to monitor a path after it has been replaced by a symbolic link, subsequently outputting the contents of the link's target. In environments where a privileged user (e.g., root) monitors a log directory, a local attacker with write access to that directory can replace a log file with a symlink to a sensitive system file (such as /etc/shadow), causing tail to disclose the contents of the sensitive file."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35364","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35364","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35364","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35364","date":"2026-10-08","epss":0.00096,"percentile":0.00641}],"risk":0.048,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35364"},"relatedVulnerabilities":[{"id":"CVE-2026-35364","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35364","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35364","date":"2026-10-08","epss":0.00096,"percentile":0.00641}],"urls":["https://github.com/uutils/coreutils/issues/10015"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35364","description":"A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device operations. The utility removes the destination path before recreating it through a copy operation. A local attacker with write access to the destination directory can exploit this window to replace the destination with a symbolic link. The subsequent privileged move operation will follow the symlink, allowing the attacker to redirect the write and overwrite an arbitrary target file with contents from the source."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35357","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35357","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35357","date":"2026-10-08","epss":0.00094,"percentile":0.00566}],"risk":0.047,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35357"},"relatedVulnerabilities":[{"id":"CVE-2026-35357","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35357","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35357","date":"2026-10-08","epss":0.00094,"percentile":0.00566}],"urls":["https://github.com/uutils/coreutils/issues/10011"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35357","description":"The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restricted to their final mode (e.g., 0600) later in the process. A local attacker can race to open the file during this window; once obtained, the file descriptor remains valid and readable even after the permissions are tightened, exposing sensitive or private file contents."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35354","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35354","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35354","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35354","date":"2026-10-08","epss":0.00092,"percentile":0.00488}],"risk":0.046,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35354"},"relatedVulnerabilities":[{"id":"CVE-2026-35354","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35354","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35354","date":"2026-10-08","epss":0.00092,"percentile":0.00488}],"urls":["https://github.com/uutils/coreutils/issues/10014"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35354","description":"A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device moves. The extended attribute (xattr) preservation logic uses multiple path-based system calls that perform fresh path-to-inode lookups for each operation. A local attacker with write access to the directory can exploit this race to swap files between calls, causing the destination file to receive an inconsistent mix of security xattrs, such as SELinux labels or file capabilities."}]},{"artifact":{"id":"8f69e8ade469d8d0","cpes":["cpe:2.3:a:rust-coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust-coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust_coreutils:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust-coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:rust:rust_coreutils:0.8.0-0ubuntu3:*:*:*:*:*:*:*"],"name":"rust-coreutils","purl":"pkg:deb/ubuntu/rust-coreutils@0.8.0-0ubuntu3?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"0.8.0-0ubuntu3","language":"","licenses":["Apache-2.0","MIT","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rust-coreutils/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/rust-coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rust-coreutils.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/rust-coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"rust-coreutils","version":"0.8.0-0ubuntu3"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-35374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-35374","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35374","date":"2026-10-08","epss":0.00091,"percentile":0.00443}],"risk":0.0455,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35374"},"relatedVulnerabilities":[{"id":"CVE-2026-35374","cvss":[{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35374","cwe":"CWE-367","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-35374","date":"2026-10-08","epss":0.00091,"percentile":0.00443}],"urls":["https://github.com/uutils/coreutils/pull/11401"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35374","description":"A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the split utility of uutils coreutils. The program attempts to prevent data loss by checking for identity between input and output files using their file paths before initiating the split operation. However, the utility subsequently opens the output file with truncation after this path-based validation is complete. A local attacker with write access to the directory can exploit this race window by manipulating mutable path components (e.g., swapping a path with a symbolic link). This can cause split to truncate and write to an unintended target file, potentially including the input file itself or other sensitive files accessible to the process, leading to permanent data loss."}]},{"artifact":{"id":"970ee406fec31a62","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:259.5-0ubuntu3.4:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@259.5-0ubuntu3.4?arch=amd64&distro=ubuntu-26.04&upstream=systemd","type":"deb","version":"259.5-0ubuntu3.4","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"systemd","version":"259.5-0ubuntu3.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"788b0461cc06c994","cpes":["cpe:2.3:a:libudev1:libudev1:259.5-0ubuntu3.4:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@259.5-0ubuntu3.4?arch=amd64&distro=ubuntu-26.04&upstream=systemd","type":"deb","version":"259.5-0ubuntu3.4","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"systemd","version":"259.5-0ubuntu3.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"b4411343a9990784","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-4ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-4ubuntu0.4?arch=amd64&distro=ubuntu-26.04","type":"deb","version":"1.35+dfsg-4ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"tar","version":"1.35+dfsg-4ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"4fa7527a29b6d3cf","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.8-4ubuntu3.1:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.8-4ubuntu3.1?arch=amd64&distro=ubuntu-26.04&upstream=gnupg2","type":"deb","version":"2.4.8-4ubuntu3.1","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"gnupg2","version":"2.4.8-4ubuntu3.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5a4285d3959c2c07","cpes":["cpe:2.3:a:libxml2-16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_16:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_16:2.15.2\\+dfsg-0.1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libxml2-16","purl":"pkg:deb/ubuntu/libxml2-16@2.15.2%2Bdfsg-0.1ubuntu0.1?arch=amd64&distro=ubuntu-26.04&upstream=libxml2","type":"deb","version":"2.15.2+dfsg-0.1ubuntu0.1","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-16/copyright","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/usr/share/doc/libxml2-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","layerID":"sha256:ce003ca946e762a76b4dd639fd0b9ec55c58f6d0de60da57d169d15e0c4165a3","accessPath":"/var/lib/dpkg/info/libxml2-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11979","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"26.04"},"package":{"name":"libxml2","version":"2.15.2+dfsg-0.1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:26.04"}}],"vulnerability":{"id":"CVE-2026-11979","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-11979","date":"2026-10-08","epss":0.00148,"percentile":0.03516}],"risk":0.007400000000000001,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:26.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11979"},"relatedVulnerabilities":[{"id":"CVE-2026-11979","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-11979","date":"2026-10-08","epss":0.00148,"percentile":0.03516}],"urls":["https://cert.pl/en/posts/2026/06/CVE-2026-11979","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11979","description":"libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"cd8922511604195c","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/bin/pebble","layerID":"sha256:4a6e4a6c5956212bf74c556250eb0028096f13d74501e43af51a1dbed8d69749","accessPath":"/usr/bin/pebble","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"10.00","as_of":"2026-10-09T19:24:31.292Z","grype_db_version":"2026-10-09T06:32:32.000Z"}