{"grype_matches":[{"artifact":{"id":"c32a684c6a26f3d3","cpes":["cpe:2.3:a:sqlitepclraw_lib_e_sqlite3:sqlitepclraw_lib_e_sqlite3_.net:2.1.6:*:*:*:*:*:*:*","cpe:2.3:a:sqlitepclraw_lib_e_sqlite3:sqlitepclraw_lib_e_sqlite3:2.1.6:*:*:*:*:*:*:*"],"name":"SQLitePCLRaw.lib.e_sqlite3","purl":"pkg:nuget/SQLitePCLRaw.lib.e_sqlite3@2.1.6","type":"dotnet","version":"2.1.6","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2m69-gcr7-jv3q","versionConstraint":"<=2.1.11 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SQLitePCLRaw.lib.e_sqlite3","version":"2.1.6"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-2m69-gcr7-jv3q","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"risk":57.1152,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-6965","https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8","http://seclists.org/fulldisclosure/2025/Sep/49","http://seclists.org/fulldisclosure/2025/Sep/53","http://seclists.org/fulldisclosure/2025/Sep/56","http://seclists.org/fulldisclosure/2025/Sep/57","http://seclists.org/fulldisclosure/2025/Sep/58","http://www.openwall.com/lists/oss-security/2025/09/06/1","https://cert-portal.siemens.com/productcert/html/ssa-225816.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://github.com/google/security-research/security/advisories/GHSA-qj7j-3jp8-8ccv","https://github.com/github/advisory-database/pull/7675"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2m69-gcr7-jv3q","description":"SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite"},"relatedVulnerabilities":[{"id":"CVE-2025-6965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.3,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"urls":["https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8","http://seclists.org/fulldisclosure/2025/Sep/49","http://seclists.org/fulldisclosure/2025/Sep/53","http://seclists.org/fulldisclosure/2025/Sep/56","http://seclists.org/fulldisclosure/2025/Sep/57","http://seclists.org/fulldisclosure/2025/Sep/58","http://www.openwall.com/lists/oss-security/2025/09/06/1","https://cert-portal.siemens.com/productcert/html/ssa-225816.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6965","description":"There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above."}]},{"artifact":{"id":"3ae9ab90782bede2","cpes":["cpe:2.3:a:npgsql:npgsql_.net:8.0.0:*:*:*:*:*:*:*","cpe:2.3:a:npgsql:npgsql:8.0.0:*:*:*:*:*:*:*"],"name":"Npgsql","purl":"pkg:nuget/Npgsql@8.0.0","type":"dotnet","version":"8.0.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"8.0.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x9vc-6hfv-hg8c","versionConstraint":">=8.0.0,<8.0.3 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"Npgsql","version":"8.0.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x9vc-6hfv-hg8c","fix":{"state":"fixed","versions":["8.0.3"],"available":[{"date":"2024-05-10","kind":"first-observed","version":"8.0.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-32655","cwe":"CWE-89","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-32655","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-32655","date":"2026-10-08","epss":0.01716,"percentile":0.7672}],"risk":1.3384800000000001,"urls":["https://github.com/npgsql/npgsql/security/advisories/GHSA-x9vc-6hfv-hg8c","https://github.com/npgsql/npgsql/commit/f7e7ead0702d776a8f551f5786c4cac2d65c4bc6","https://github.com/npgsql/npgsql/files/14309386/Npgsql.Security.Advisory.pdf","https://github.com/npgsql/npgsql/files/14309397/npgsql-protocol-overflow-poc.zip","https://github.com/npgsql/npgsql/releases/tag/v8.0.3","https://github.com/npgsql/npgsql/releases/tag/v4.0.14","https://github.com/npgsql/npgsql/releases/tag/v4.1.13","https://github.com/npgsql/npgsql/releases/tag/v5.0.18","https://github.com/npgsql/npgsql/releases/tag/v6.0.11","https://github.com/npgsql/npgsql/releases/tag/v7.0.7","https://nvd.nist.gov/vuln/detail/CVE-2024-32655","https://github.com/npgsql/npgsql/commit/091655eed0c84e502ab424950c930339d17c1928","https://github.com/npgsql/npgsql/commit/3183efb2bdcca159c8c2e22af57e18ea8f853cf0","https://github.com/npgsql/npgsql/commit/67acbe027e28477ac2199e15cfb554bb2ffaf169","https://github.com/npgsql/npgsql/commit/703d9af8fa48dfe8c0180e36edb8278f34342d7b","https://github.com/npgsql/npgsql/commit/a22a42d8141d7a3528f43c02c095a409507cf1af","https://github.com/npgsql/npgsql/commit/e34e2ba8042e666d9af54a1b255fba4d5b11df56","https://www.youtube.com/watch?v=Tfg1B8u1yvE"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x9vc-6hfv-hg8c","description":"Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow"},"relatedVulnerabilities":[{"id":"CVE-2024-32655","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-32655","cwe":"CWE-89","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-32655","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-32655","date":"2026-10-08","epss":0.01716,"percentile":0.7672}],"urls":["https://github.com/npgsql/npgsql/commit/091655eed0c84e502ab424950c930339d17c1928","https://github.com/npgsql/npgsql/commit/3183efb2bdcca159c8c2e22af57e18ea8f853cf0","https://github.com/npgsql/npgsql/commit/67acbe027e28477ac2199e15cfb554bb2ffaf169","https://github.com/npgsql/npgsql/commit/703d9af8fa48dfe8c0180e36edb8278f34342d7b","https://github.com/npgsql/npgsql/commit/a22a42d8141d7a3528f43c02c095a409507cf1af","https://github.com/npgsql/npgsql/commit/e34e2ba8042e666d9af54a1b255fba4d5b11df56","https://github.com/npgsql/npgsql/commit/f7e7ead0702d776a8f551f5786c4cac2d65c4bc6","https://github.com/npgsql/npgsql/releases/tag/v4.0.14","https://github.com/npgsql/npgsql/releases/tag/v4.1.13","https://github.com/npgsql/npgsql/releases/tag/v5.0.18","https://github.com/npgsql/npgsql/releases/tag/v6.0.11","https://github.com/npgsql/npgsql/releases/tag/v7.0.7","https://github.com/npgsql/npgsql/releases/tag/v8.0.3","https://github.com/npgsql/npgsql/security/advisories/GHSA-x9vc-6hfv-hg8c","https://www.youtube.com/watch?v=Tfg1B8u1yvE"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-32655","description":"Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This causes Npgsql to write a message size that is too small when constructing a Postgres protocol message to send it over the network to the database. When parsing the message, the database will only read a small number of bytes and treat any following bytes as new messages while they belong to the old message. Attackers can abuse this to inject arbitrary Postgres protocol messages into the connection, leading to the execution of arbitrary SQL statements on the application's behalf. This vulnerability is fixed in 4.0.14, 4.1.13, 5.0.18, 6.0.11, 7.0.7, and 8.0.3."}]},{"artifact":{"id":"53f81f534257f280","cpes":["cpe:2.3:a:mimekit:mimekit_.net:4.6.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.6.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.6.0","type":"dotnet","version":"4.6.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.6.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"35c1e224c7bb71c2","cpes":["cpe:2.3:a:automapper:automapper_.net:12.0.0:*:*:*:*:*:*:*","cpe:2.3:a:automapper:automapper:12.0.0:*:*:*:*:*:*:*"],"name":"AutoMapper","purl":"pkg:nuget/AutoMapper@12.0.0","type":"dotnet","version":"12.0.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"15.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rvv3-g6hj-g44x","versionConstraint":"<15.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"AutoMapper","version":"12.0.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-rvv3-g6hj-g44x","fix":{"state":"fixed","versions":["15.1.1"],"available":[{"date":"2026-03-16","kind":"first-observed","version":"15.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32933","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32933","date":"2026-10-08","epss":0.00665,"percentile":0.5026}],"risk":0.49874999999999997,"urls":["https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x","https://github.com/LuckyPennySoftware/AutoMapper/commit/0afaf1e91648fca1a57512e94dd00a76ee016816","https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v16.1.1","https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v15.1.1","https://nvd.nist.gov/vuln/detail/CVE-2026-32933","https://github.com/LuckyPennySoftware/AutoMapper/discussions/4624"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rvv3-g6hj-g44x","description":"AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion"},"relatedVulnerabilities":[{"id":"CVE-2026-32933","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32933","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32933","date":"2026-10-08","epss":0.00665,"percentile":0.5026}],"urls":["https://github.com/LuckyPennySoftware/AutoMapper/commit/0afaf1e91648fca1a57512e94dd00a76ee016816","https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v15.1.1","https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v16.1.1","https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32933","description":"AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a `StackOverflowException` and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue."}]},{"artifact":{"id":"99713dce86011978","cpes":["cpe:2.3:a:ssh_net:ssh_net_.net:2020.0.2:*:*:*:*:*:*:*","cpe:2.3:a:ssh_net:ssh_net:2020.0.2:*:*:*:*:*:*:*"],"name":"SSH.NET","purl":"pkg:nuget/SSH.NET@2020.0.2","type":"dotnet","version":"2020.0.2","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2026.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mggc-4xg6-vcxf","versionConstraint":"<2026.0.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SSH.NET","version":"2020.0.2"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-mggc-4xg6-vcxf","fix":{"state":"fixed","versions":["2026.0.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"2026.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85756","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-85756","date":"2026-10-08","epss":0.00617,"percentile":0.47953}],"risk":0.46275,"urls":["https://github.com/sshnet/SSH.NET/security/advisories/GHSA-mggc-4xg6-vcxf","https://nvd.nist.gov/vuln/detail/CVE-2026-85756","https://github.com/sshnet/SSH.NET/commit/c66b9f8fb06c12e71761e58a577b1e796026310f","https://github.com/sshnet/SSH.NET/releases/tag/2026.0.0"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mggc-4xg6-vcxf","description":"SSH.NET: ScpClient allows server-side RCE via default SCP path handling"},"relatedVulnerabilities":[{"id":"CVE-2026-85756","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85756","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-85756","date":"2026-10-08","epss":0.00617,"percentile":0.47953}],"urls":["https://github.com/sshnet/SSH.NET/commit/c66b9f8fb06c12e71761e58a577b1e796026310f","https://github.com/sshnet/SSH.NET/releases/tag/2026.0.0","https://github.com/sshnet/SSH.NET/security/advisories/GHSA-mggc-4xg6-vcxf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85756","description":"SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell's parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"99713dce86011978","cpes":["cpe:2.3:a:ssh_net:ssh_net_.net:2020.0.2:*:*:*:*:*:*:*","cpe:2.3:a:ssh_net:ssh_net:2020.0.2:*:*:*:*:*:*:*"],"name":"SSH.NET","purl":"pkg:nuget/SSH.NET@2020.0.2","type":"dotnet","version":"2020.0.2","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2026.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q939-rpr3-3284","versionConstraint":"<=2025.1.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SSH.NET","version":"2020.0.2"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-q939-rpr3-3284","fix":{"state":"fixed","versions":["2026.0.0"],"available":[{"date":"2026-08-12","kind":"first-observed","version":"2026.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48798","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48798","cwe":"CWE-73","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48798","date":"2026-10-08","epss":0.00421,"percentile":0.34411}],"risk":0.30733,"urls":["https://github.com/sshnet/SSH.NET/security/advisories/GHSA-q939-rpr3-3284","https://github.com/sshnet/SSH.NET/commit/600be0de543765995a189b5d7cd4efac5007f3ce","https://nvd.nist.gov/vuln/detail/CVE-2026-48798","https://github.com/sshnet/SSH.NET/releases/tag/2026.0.0"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q939-rpr3-3284","description":"SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames"},"relatedVulnerabilities":[{"id":"CVE-2026-48798","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48798","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48798","cwe":"CWE-73","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48798","date":"2026-10-08","epss":0.00421,"percentile":0.34411}],"urls":["https://github.com/sshnet/SSH.NET/commit/600be0de543765995a189b5d7cd4efac5007f3ce","https://github.com/sshnet/SSH.NET/releases/tag/2026.0.0","https://github.com/sshnet/SSH.NET/security/advisories/GHSA-q939-rpr3-3284"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48798","description":"SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"e635c0fa6e0a9072","cpes":["cpe:2.3:a:sharpcompress:sharpcompress_.net:0.32.2:*:*:*:*:*:*:*","cpe:2.3:a:sharpcompress:sharpcompress:0.32.2:*:*:*:*:*:*:*"],"name":"SharpCompress","purl":"pkg:nuget/SharpCompress@0.32.2","type":"dotnet","version":"0.32.2","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.48.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6c8g-7p36-r338","versionConstraint":"<0.48.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SharpCompress","version":"0.32.2"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-6c8g-7p36-r338","fix":{"state":"fixed","versions":["0.48.0"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0.48.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44788","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44788","date":"2026-10-08","epss":0.00352,"percentile":0.26758}],"risk":0.19184,"urls":["https://github.com/adamhathcock/sharpcompress/security/advisories/GHSA-6c8g-7p36-r338","https://nvd.nist.gov/vuln/detail/CVE-2026-44788","https://github.com/adamhathcock/sharpcompress/commit/2021a06626d0555a4d69471386e763ca5f5d5dfb"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6c8g-7p36-r338","description":"SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant)"},"relatedVulnerabilities":[{"id":"CVE-2026-44788","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44788","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44788","date":"2026-10-08","epss":0.00352,"percentile":0.26758}],"urls":["https://github.com/adamhathcock/sharpcompress/security/advisories/GHSA-6c8g-7p36-r338"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44788","description":"SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file writes by chaining with a symlink entry, giving a full write primitive on the target filesystem subject to the permissions of the running process."}]},{"artifact":{"id":"896c5f84aa135727","cpes":["cpe:2.3:a:mailkit:mailkit_.net:4.6.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.6.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.6.0","type":"dotnet","version":"4.6.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.6.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"9399a526f720c3e2","cpes":["cpe:2.3:a:libicu74:libicu74:74.2-1ubuntu3.1:*:*:*:*:*:*:*"],"name":"libicu74","purl":"pkg:deb/ubuntu/libicu74@74.2-1ubuntu3.1?arch=amd64&distro=ubuntu-24.04&upstream=icu","type":"deb","version":"74.2-1ubuntu3.1","language":"","licenses":["GPL-3","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libicu74/copyright","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/usr/share/doc/libicu74/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libicu74:amd64.md5sums","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/info/libicu74:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"icu"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-5222","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"icu","version":"74.2-1ubuntu3.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-5222","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-5222","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5222","date":"2026-10-08","epss":0.00425,"percentile":0.34769}],"risk":0.1275,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-5222"},"relatedVulnerabilities":[{"id":"CVE-2025-5222","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5222","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5222","date":"2026-10-08","epss":0.00425,"percentile":0.34769}],"urls":["https://access.redhat.com/errata/RHSA-2025:11888","https://access.redhat.com/errata/RHSA-2025:12083","https://access.redhat.com/errata/RHSA-2025:12331","https://access.redhat.com/errata/RHSA-2025:12332","https://access.redhat.com/errata/RHSA-2025:12333","https://access.redhat.com/errata/RHSA-2026:54544","https://access.redhat.com/errata/RHSA-2026:54553","https://access.redhat.com/errata/RHSA-2026:54581","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/security/cve/CVE-2025-5222","https://bugzilla.redhat.com/show_bug.cgi?id=2368600","https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957","https://lists.debian.org/debian-lts-announce/2025/06/msg00015.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5222","description":"A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"b99f35328df2c1c9","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/ubuntu/gnupg-l10n@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5995b623e873af09","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/ubuntu/gpg-wks-client@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"17317631a09f6a3f","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"c37cad8d5a3a6548","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"817535dcd7b4fdf9","cpes":["cpe:2.3:a:systemd-standalone-sysusers:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone-sysusers:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone_sysusers:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone_sysusers:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"systemd-standalone-sysusers","purl":"pkg:deb/ubuntu/systemd-standalone-sysusers@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-standalone-sysusers/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/systemd-standalone-sysusers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-standalone-sysusers.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/systemd-standalone-sysusers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-standalone-sysusers.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/systemd-standalone-sysusers.list"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"b99f35328df2c1c9","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/ubuntu/gnupg-l10n@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5995b623e873af09","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/ubuntu/gpg-wks-client@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-9403","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"risk":0.0108,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-9403"},"relatedVulnerabilities":[{"id":"CVE-2025-9403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:582e598c69bb5b971bd8817603429862a48ed17bbc9f657b1fe180ebd12d92c8","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-9403","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"risk":0.0108,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-9403"},"relatedVulnerabilities":[{"id":"CVE-2025-9403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well."}]},{"artifact":{"id":"53f81f534257f280","cpes":["cpe:2.3:a:mimekit:mimekit_.net:4.6.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.6.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.6.0","type":"dotnet","version":"4.6.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/ombi/Ombi","layerID":"sha256:6da863c36357554e6e79644875fc8b73ab89f2d76470bddbed14e8db96d33989","accessPath":"/app/ombi/Ombi","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gmc6-fwg3-75m5","versionConstraint":">=3.0.0,<4.7.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.6.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gmc6-fwg3-75m5","fix":{"state":"fixed","versions":["4.7.1"],"available":[{"date":"2024-07-12","kind":"first-observed","version":"4.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-gmc6-fwg3-75m5","https://github.com/dotnet/announcements/issues/312","https://github.com/jstedfast/MimeKit/commit/aef4eda75525848b992ce5e1f9b87399000fffb6","https://github.com/advisories/GHSA-447r-wph3-92pm"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gmc6-fwg3-75m5","description":"Mimekit has vulnerable dependency that can lead to denial of service"},"relatedVulnerabilities":[]}],"grade":"C","score":"55.00","as_of":"2026-10-09T19:19:40.553Z","grype_db_version":"2026-10-09T06:32:32.000Z"}