{"grype_matches":[{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2021-31879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"risk":0.5519999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31879"},"relatedVulnerabilities":[{"id":"CVE-2021-31879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"8da8a7d75fe5f6ac","cpes":["cpe:2.3:a:git:git:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/ubuntu/git@1%3A2.43.0-1ubuntu7.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1:2.43.0-1ubuntu7.3","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000021","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"git","version":"1:2.43.0-1ubuntu7.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2018-1000021","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"risk":0.3222,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000021"},"relatedVulnerabilities":[{"id":"CVE-2018-1000021","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"urls":["http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000021","description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack)."}]},{"artifact":{"id":"9bd8426ce776b55a","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/ubuntu/git-man@1%3A2.43.0-1ubuntu7.3?arch=all&distro=ubuntu-24.04&upstream=git","type":"deb","version":"1:2.43.0-1ubuntu7.3","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1000021","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"git","version":"1:2.43.0-1ubuntu7.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2018-1000021","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"risk":0.3222,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000021"},"relatedVulnerabilities":[{"id":"CVE-2018-1000021","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"urls":["http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000021","description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack)."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10524","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"risk":0.32130000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10524"},"relatedVulnerabilities":[{"id":"CVE-2024-10524","cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."}]},{"artifact":{"id":"5d668b4eb9cdb47a","cpes":["cpe:2.3:a:libperl5.38t64:libperl5.38t64:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libperl5.38t64","purl":"pkg:deb/ubuntu/libperl5.38t64@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.38t64/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/libperl5.38t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.38t64:amd64.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/libperl5.38t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"bc00ecb2bdfc2b6f","cpes":["cpe:2.3:a:perl:perl:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/ubuntu/perl@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"c9080c1b63d1cc8f","cpes":["cpe:2.3:a:perl-modules-5.38:perl-modules-5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.38:perl_modules_5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.38:perl-modules-5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.38:perl_modules_5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.38:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-modules-5.38","purl":"pkg:deb/ubuntu/perl-modules-5.38@5.38.2-3.2ubuntu0.6?arch=all&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.38/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/perl-modules-5.38/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.38.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl-modules-5.38.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.38.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/perl-modules-5.38.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.2745,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77214"},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"8da8a7d75fe5f6ac","cpes":["cpe:2.3:a:git:git:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/ubuntu/git@1%3A2.43.0-1ubuntu7.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1:2.43.0-1ubuntu7.3","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-52005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"git","version":"1:2.43.0-1ubuntu7.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52005","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52005"},"relatedVulnerabilities":[{"id":"CVE-2024-52005","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"urls":["https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329","https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52005","description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources."}]},{"artifact":{"id":"9bd8426ce776b55a","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.43.0-1ubuntu7.3:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/ubuntu/git-man@1%3A2.43.0-1ubuntu7.3?arch=all&distro=ubuntu-24.04&upstream=git","type":"deb","version":"1:2.43.0-1ubuntu7.3","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"git","version":"1:2.43.0-1ubuntu7.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52005","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52005"},"relatedVulnerabilities":[{"id":"CVE-2024-52005","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"urls":["https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329","https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52005","description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.174,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102633"},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106552","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106552","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-08","epss":0.00291,"percentile":0.19813}],"risk":0.1455,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106552"},"relatedVulnerabilities":[{"id":"CVE-2026-106552","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-08","epss":0.00291,"percentile":0.19813}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-16599","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-16599","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"risk":0.11249999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-16599"},"relatedVulnerabilities":[{"id":"CVE-2026-16599","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"urls":["https://cert.pl/en/posts/2026/08/CVE-2026-16599","https://gitlab.com/gnuwget/wget","https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16599","description":"GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.1015,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66382"},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106585","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-08","epss":0.00189,"percentile":0.07871}],"risk":0.0945,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106585"},"relatedVulnerabilities":[{"id":"CVE-2026-106585","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-08","epss":0.00189,"percentile":0.07871}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106582","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106582","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106582","cwe":"CWE-514","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106582","date":"2026-10-08","epss":0.00182,"percentile":0.07148}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106582"},"relatedVulnerabilities":[{"id":"CVE-2026-106582","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106582","cwe":"CWE-514","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106582","date":"2026-10-08","epss":0.00182,"percentile":0.07148}],"urls":["https://arxiv.org/abs/2609.07709","https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106582","description":"In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 \"Crossing the Streams\" findings."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"66f54d89b7a27eab","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.13.2\\+dfsg-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.13.2%2Bdfsg-1ubuntu0.1?arch=amd64&distro=ubuntu-24.04&upstream=freetype","type":"deb","version":"2.13.2+dfsg-1ubuntu0.1","language":"","licenses":["BSD-3-Clause","BSL-1.0","Expat","FSFAP","FTL","GPL-2","GPL-2+","GPL-3","GPL-3+","MIT-Modern-Variant","MIT-SMC","OpenGroup-MIT","Public-Domain","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.13.2+dfsg-1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95512","versionConstraint":"< 2.13.2+dfsg-1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"freetype","version":"2.13.2+dfsg-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95512","fix":{"state":"fixed","versions":["2.13.2+dfsg-1ubuntu0.2"],"available":[{"date":"2026-10-06","kind":"advisory","version":"2.13.2+dfsg-1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"risk":0.087,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95512"},"relatedVulnerabilities":[{"id":"CVE-2026-95512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"urls":["https://access.redhat.com/errata/RHSA-2026:74952","https://access.redhat.com/security/cve/CVE-2026-95512","https://bugzilla.redhat.com/show_bug.cgi?id=2462295","https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106588","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106588","cwe":"CWE-653","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106588","date":"2026-10-08","epss":0.0013,"percentile":0.02254}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106588"},"relatedVulnerabilities":[{"id":"CVE-2026-106588","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106588","cwe":"CWE-653","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106588","date":"2026-10-08","epss":0.0013,"percentile":0.02254}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106588","description":"In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69644","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69644"},"relatedVulnerabilities":[{"id":"CVE-2025-69644","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69644","date":"2026-10-08","epss":0.00128,"percentile":0.02137}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106583","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106583","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106583","cwe":"CWE-99","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106583","date":"2026-10-08","epss":0.00128,"percentile":0.02119}],"risk":0.064,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106583"},"relatedVulnerabilities":[{"id":"CVE-2026-106583","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106583","cwe":"CWE-99","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106583","date":"2026-10-08","epss":0.00128,"percentile":0.02119}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106583","description":"In ssh in OpenSSH before 10.6, a $ or \\ character can occur in a command-line username, leading to injection."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66861","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"risk":0.0438,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66861"},"relatedVulnerabilities":[{"id":"CVE-2025-66861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66861","date":"2026-10-08","epss":0.00146,"percentile":0.03358}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106553","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106553","date":"2026-10-08","epss":0.00084,"percentile":0.00262}],"risk":0.042,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106553"},"relatedVulnerabilities":[{"id":"CVE-2026-106553","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.2,"impactScore":1.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106553","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106553","date":"2026-10-08","epss":0.00084,"percentile":0.00262}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106553","description":"In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106555","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106555","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106555","cwe":"CWE-669","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106555","date":"2026-10-08","epss":0.00084,"percentile":0.00261}],"risk":0.042,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106555"},"relatedVulnerabilities":[{"id":"CVE-2026-106555","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.2,"impactScore":1.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106555","cwe":"CWE-669","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106555","date":"2026-10-08","epss":0.00084,"percentile":0.00261}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106555","description":"In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts."}]},{"artifact":{"id":"17317631a09f6a3f","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"c37cad8d5a3a6548","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106589","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106589","cwe":"CWE-272","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106589","date":"2026-10-08","epss":0.00082,"percentile":0.00187}],"risk":0.041,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106589"},"relatedVulnerabilities":[{"id":"CVE-2026-106589","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106589","cwe":"CWE-272","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106589","date":"2026-10-08","epss":0.00082,"percentile":0.00187}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106589","description":"In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106586","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106586","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106586","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106586","date":"2026-10-08","epss":0.00077,"percentile":0.001}],"risk":0.0385,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106586"},"relatedVulnerabilities":[{"id":"CVE-2026-106586","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106586","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106586","date":"2026-10-08","epss":0.00077,"percentile":0.001}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106586","description":"In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106587","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106587","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106587","cwe":"CWE-843","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106587","date":"2026-10-08","epss":0.00077,"percentile":0.00097}],"risk":0.0385,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106587"},"relatedVulnerabilities":[{"id":"CVE-2026-106587","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106587","cwe":"CWE-843","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106587","date":"2026-10-08","epss":0.00077,"percentile":0.00097}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106587","description":"In sshd in OpenSSH before 10.6, the value \"none\" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"e0afa47c77e9c3b3","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.6p1-3ubuntu13.19:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/ubuntu/openssh-client@1%3A9.6p1-3ubuntu13.19?arch=amd64&distro=ubuntu-24.04&upstream=openssh","type":"deb","version":"1:9.6p1-3ubuntu13.19","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106584","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssh","version":"1:9.6p1-3ubuntu13.19"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-106584","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-106584","cwe":"CWE-193","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106584","date":"2026-10-08","epss":0.00056,"percentile":0.00003}],"risk":0.027999999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-106584"},"relatedVulnerabilities":[{"id":"CVE-2026-106584","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106584","cwe":"CWE-193","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106584","date":"2026-10-08","epss":0.00056,"percentile":0.00003}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106584","description":"In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations."}]},{"artifact":{"id":"01814745da17448f","cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*"],"name":"libpng16-16t64","purl":"pkg:deb/ubuntu/libpng16-16t64@1.6.43-5ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=libpng1.6","type":"deb","version":"1.6.43-5ubuntu0.6","language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:eba51029009b00dc768235b0ede109801136194e9bce717d17df371a97d52787","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16t64/copyright","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/usr/share/doc/libpng16-16t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:ce5c06a9d6742f47d9e24f84fc0400b3a7cbb00bc8b94103d5b0dcfeec86cd2a","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libpng1.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46675","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libpng1.6","version":"1.6.43-5ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46675","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46675"},"relatedVulnerabilities":[{"id":"CVE-2026-46675","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]}],"grade":"A","score":"100.00","as_of":"2026-10-09T19:07:16.438Z","grype_db_version":"2026-10-09T06:32:32.000Z"}