<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ubuntu</title>
  <link>https://cvedaily.com/pages/tags/ubuntu.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ubuntu.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ubuntu</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-47337 – Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47337</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47337</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-47336 – Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47336</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47336</strong></p>
  <p>Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47335 – Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47335</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47335</strong></p>
  <p>Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47334 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47334</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47334</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-833</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47333 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47333</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47333</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47332 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47332</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47332</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47331 – Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47331</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47331</strong></p>
  <p>Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-47330 – Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47330</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47330</strong></p>
  <p>Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-47329 – Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate inva...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47329</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47329</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47328 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47328</guid>
    <pubDate>Thu, 28 May 2026 19:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47328</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-590</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-47327 – Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47327</guid>
    <pubDate>Thu, 28 May 2026 19:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47327</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47326 – Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47326</guid>
    <pubDate>Thu, 28 May 2026 19:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47326</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47269 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47269</guid>
    <pubDate>Wed, 27 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47269</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0,  pam_usb's deny_remote feature checks utmpx ut_addr_v6 to detect whether an authentication request originates from a remote session. The outer guard was if (utent->ut_addr_v6[0] != 0), which only tests the first 32-bit word of the 128-bit address field. IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) st…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46055 – In the Linux kernel, the following vulnerability has been resolved:

apparmor: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46055</guid>
    <pubDate>Wed, 27 May 2026 14:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46055</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  apparmor: Fix string overrun due to missing termination  When booting Ubuntu 26.04 with Linux 7.0-rc4 on an ARM64 Qualcomm Snapdragon X1 we see a string buffer overrun:  BUG: KASAN: slab-out-of-bounds in aa_dfa_match (security/apparmor/match.c:535) Read of size 1 at addr ffff0008901cc000 by task snap-update-ns/2120  CPU: 5 UID:…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-45965 – In the Linux kernel, the following vulnerability has been resolved:

apparmor: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45965</guid>
    <pubDate>Wed, 27 May 2026 14:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-45965</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  apparmor: fix invalid deref of rawdata when export_binary is unset  If the export_binary parameter is disabled on runtime, profiles that were loaded before that will still have their rawdata stored in apparmorfs, with a symbolic link to the rawdata on the policy directory. When one of those profiles are replaced, the rawdata is…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45898 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/iwcm: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45898</guid>
    <pubDate>Wed, 27 May 2026 14:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45898</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/iwcm: Fix workqueue list corruption by removing work_list  The commit e1168f0 ("RDMA/iwcm: Simplify cm_event_handler()") changed the work submission logic to unconditionally call queue_work() with the expectation that queue_work() would have no effect if work was already pending. The problem is that a free list of struct iw…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-45840 – In the Linux kernel, the following vulnerability has been resolved:

openvswitch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45840</guid>
    <pubDate>Wed, 27 May 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-45840</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  openvswitch: cap upcall PID array size and pre-size vport replies  The vport netlink reply helpers allocate a fixed-size skb with nlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID array via ovs_vport_get_upcall_portids().  Since ovs_vport_set_upcall_portids() accepts any non-zero multiple of sizeof(u32) with n…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43298 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43298</guid>
    <pubDate>Fri, 08 May 2026 14:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43298</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Skip vcn poison irq release on VF  VF doesn't enable VCN poison irq in VCNv2.5. Skip releasing it and avoid call trace during deinitialization.  [   71.913601] [drm] clean up the vf2pf work item [   71.915088] ------------[ cut here ]------------ [   71.915092] WARNING: CPU: 3 PID: 1079 at /tmp/amd.aFkFvSQl/amd/amdgp…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43252 – In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43252</guid>
    <pubDate>Wed, 06 May 2026 12:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43252</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: in-kernel: always set ID as avail when rm endp  Syzkaller managed to find a combination of actions that was generating this warning:    WARNING: net/mptcp/pm_kernel.c:1074 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline], CPU#1: syz.7.48/2535   WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_ful…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-71293 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-71293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-71293</guid>
    <pubDate>Wed, 06 May 2026 12:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-71293</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/ras: Move ras data alloc before bad page check  In the rare event if eeprom has only invalid address entries, allocation is skipped, this causes following NULL pointer issue [  547.103445] BUG: kernel NULL pointer dereference, address: 0000000000000010 [  547.118897] #PF: supervisor read access in kernel mode [  547.1…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-71293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43046 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: reje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43046</guid>
    <pubDate>Fri, 01 May 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43046</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: reject root items with drop_progress and zero drop_level  [BUG] When recovering relocation at mount time, merge_reloc_root() and btrfs_drop_snapshot() both use BUG_ON(level == 0) to guard against an impossible state: a non-zero drop_progress combined with a zero drop_level in a root_item, which can be triggered:  --------…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31654 – In the Linux kernel, the following vulnerability has been resolved:

mm/vma: fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31654</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31654</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mm/vma: fix memory leak in __mmap_region()  commit 605f6586ecf7 ("mm/vma: do not leak memory when .mmap_prepare swaps the file") handled the success path by skipping get_file() via file_doesnt_need_get, but missed the error path.  When /dev/zero is mmap'd with MAP_SHARED, mmap_zero_prepare() calls shmem_zero_setup_desc() which a…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6369 – An improper access control vulnerability in the canonical-livepatch snap client ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6369</guid>
    <pubDate>Mon, 20 Apr 2026 14:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6369</strong></p>
  <p>An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubu…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40489 – editorconfig-core-c  is an EditorConfig core library for use by plugins supporti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40489</guid>
    <pubDate>Sat, 18 Apr 2026 02:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40489</strong></p>
  <p>editorconfig-core-c  is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec_glob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and .editorconfig file. This is an incomplete fix for CVE-2023-0341. The pcre_str buf…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15480 – In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15480</guid>
    <pubDate>Thu, 09 Apr 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15480</strong></p>
  <p>In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1258</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14551 – In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials durin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14551</guid>
    <pubDate>Thu, 09 Apr 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14551</strong></p>
  <p>In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1258</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23428 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23428</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23428</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free of share_conf in compound request  smb2_get_ksmbd_tcon() reuses work->tcon in compound requests without validating tcon->t_state. ksmbd_tree_conn_lookup() checks t_state == TREE_CONNECTED on the initial lookup path, but the compound reuse path bypasses this check entirely.  If a prior command in the com…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23427 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23427</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23427</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in durable v2 replay of active file handles  parse_durable_handle_context() unconditionally assigns dh_info->fp->conn to the current connection when handling a DURABLE_REQ_V2 context with SMB2_FLAGS_REPLAY_OPERATION. ksmbd_lookup_fd_cguid() does not filter by fp->conn, so it returns file handles that ar…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23321 – In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23321</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23321</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: in-kernel: always mark signal+subflow endp as used  Syzkaller managed to find a combination of actions that was generating this warning:    msk->pm.local_addr_used == 0   WARNING: net/mptcp/pm_kernel.c:1071 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1071 [inline], CPU#1: syz.2.17/961   WARNING: net/mptcp/p…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3888 – Local privilege escalation in snapd on Linux allows local attackers to get root ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3888</guid>
    <pubDate>Tue, 17 Mar 2026 14:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3888</strong></p>
  <p>Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-268</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13350 – Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13350</guid>
    <pubDate>Thu, 05 Mar 2026 20:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13350</strong></p>
  <p>Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queue reference, so the buffer is freed while stil…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27466 – BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27466</guid>
    <pubDate>Sat, 21 Feb 2026 08:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27466</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both ports (3310 and 7357) to the internet. A remote attacker can use this to send complex or large docume…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23086 – In the Linux kernel, the following vulnerability has been resolved:

vsock/virti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23086</guid>
    <pubDate>Wed, 04 Feb 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23086</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  vsock/virtio: cap TX credit to local buffer size  The virtio transports derives its TX credit directly from peer_buf_alloc, which is set from the remote endpoint's SO_VM_SOCKETS_BUFFER_SIZE value.  On the host side this means that the amount of data we are willing to queue for a connection is scaled by a guest-chosen buffer size…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-54090 – In the Linux kernel, the following vulnerability has been resolved:

ixgbe: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54090</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-54090</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ixgbe: Fix panic during XDP_TX with > 64 CPUs  Commit 4fe815850bdc ("ixgbe: let the xdpdrv work with more than 64 cpus") adds support to allow XDP programs to run on systems with more than 64 CPUs by locking the XDP TX rings and indexing them using cpu % 64 (IXGBE_MAX_XDP_QS).  Upon trying this out patch on a system with more th…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40351 – In the Linux kernel, the following vulnerability has been resolved:

hfsplus: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40351</guid>
    <pubDate>Tue, 16 Dec 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40351</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()  The syzbot reported issue in hfsplus_delete_cat():  [   70.682285][ T9333] ===================================================== [   70.682943][ T9333] BUG: KMSAN: uninit-value in hfsplus_subfolders_dec+0x1d7/0x220 [   70.683640][ T9333]  hfsplus_subfolders_dec+0x1d7…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40349 – In the Linux kernel, the following vulnerability has been resolved:

hfs: valida...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40349</guid>
    <pubDate>Tue, 16 Dec 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40349</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfs: validate record offset in hfsplus_bmap_alloc  hfsplus_bmap_alloc can trigger a crash if a record offset or length is larger than node_size  [   15.264282] BUG: KASAN: slab-out-of-bounds in hfsplus_bmap_alloc+0x887/0x8b0 [   15.265192] Read of size 8 at addr ffff8881085ca188 by task test/183 [   15.265949] [   15.266163] CPU…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40244 – In the Linux kernel, the following vulnerability has been resolved:

hfsplus: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40244</guid>
    <pubDate>Thu, 04 Dec 2025 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40244</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()  The syzbot reported issue in __hfsplus_ext_cache_extent():  [   70.194323][ T9350] BUG: KMSAN: uninit-value in __hfsplus_ext_cache_extent+0x7d0/0x990 [   70.195022][ T9350]  __hfsplus_ext_cache_extent+0x7d0/0x990 [   70.195530][ T9350]  hfsplus_file_extend+0x…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2486 – The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2486</guid>
    <pubDate>Wed, 26 Nov 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2486</strong></p>
  <p>The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secur…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40088 – In the Linux kernel, the following vulnerability has been resolved:

hfsplus: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40088</guid>
    <pubDate>Thu, 30 Oct 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40088</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()  The hfsplus_strcasecmp() logic can trigger the issue:  [  117.317703][ T9855] ================================================================== [  117.318353][ T9855] BUG: KASAN: slab-out-of-bounds in hfsplus_strcasecmp+0x1bc/0x490 [  117.318991][ T9855] Read of size…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40006 – In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40006</guid>
    <pubDate>Mon, 20 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40006</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mm/hugetlb: fix folio is still mapped when deleted  Migration may be raced with fallocating hole.  remove_inode_single_folio will unmap the folio if the folio is still mapped.  However, it's called without folio lock.  If the folio is migrated and the mapped pte has been converted to migration entry, folio_mapped() returns false…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43914 – Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Releas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43914</guid>
    <pubDate>Tue, 07 Oct 2025 18:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43914</strong></p>
  <p>Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34203 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34203</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34203</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior to 20.0.2614 (VA and SaaS deployments) contain multiple Docker containers that include outdated, end-of-life, unsupported, or otherwise vulnerable third-party components (examples: Nginx 1.17.x, OpenSSL 1.1.1d, various EOL Alpine/Debian/Ubuntu base images, and EOL Laravel/PHP lib…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34197 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34197</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34197</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-39833 – In the Linux kernel, the following vulnerability has been resolved:

mISDN: hfcp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39833</guid>
    <pubDate>Tue, 16 Sep 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-39833</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mISDN: hfcpci: Fix warning when deleting uninitialized timer  With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat:  [  250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0 [  250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobj…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50315 – In the Linux kernel, the following vulnerability has been resolved:

ata: ahci: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50315</guid>
    <pubDate>Mon, 15 Sep 2025 15:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50315</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS  UBSAN complains about array-index-out-of-bounds: [ 1.980703] kernel: UBSAN: array-index-out-of-bounds in /build/linux-9H675w/linux-5.15.0/drivers/ata/libahci.c:968:41 [ 1.980709] kernel: index 15 is out of range for type 'ahci_em_priv [8]' [ 1.980713] kernel: CPU: 0 PID: 209…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50299 – In the Linux kernel, the following vulnerability has been resolved:

md: Replace...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50299</guid>
    <pubDate>Mon, 15 Sep 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50299</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  md: Replace snprintf with scnprintf  Current code produces a warning as shown below when total characters in the constituent block device names plus the slashes exceeds 200. snprintf() returns the number of characters generated from the given input, which could cause the expression “200 – len” to wrap around to a large positive…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38734 – In the Linux kernel, the following vulnerability has been resolved:

net/smc: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38734</guid>
    <pubDate>Fri, 05 Sep 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38734</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/smc: fix UAF on smcsk after smc_listen_out()  BPF CI testing report a UAF issue:    [   16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003  0   [   16.447134] #PF: supervisor read access in kernel mod  e   [   16.447516] #PF: error_code(0x0000) - not-present pag  e   [   16.447878] PGD 0 P4D   0   […</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38716 – In the Linux kernel, the following vulnerability has been resolved:

hfs: fix ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38716</guid>
    <pubDate>Thu, 04 Sep 2025 16:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38716</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfs: fix general protection fault in hfs_find_init()  The hfs_find_init() method can trigger the crash if tree pointer is NULL:  [   45.746290][ T9787] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KAI [   45.747287][ T9787] KASAN: null-ptr-deref in range [0x0000000000000040…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38714 – In the Linux kernel, the following vulnerability has been resolved:

hfsplus: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38714</guid>
    <pubDate>Thu, 04 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38714</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()  The hfsplus_bnode_read() method can trigger the issue:  [  174.852007][ T9784] ================================================================== [  174.852709][ T9784] BUG: KASAN: slab-out-of-bounds in hfsplus_bnode_read+0x2f4/0x360 [  174.853412][ T9784] Read of size 8 a…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38713 – In the Linux kernel, the following vulnerability has been resolved:

hfsplus: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38713</guid>
    <pubDate>Thu, 04 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38713</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()  The hfsplus_readdir() method is capable to crash by calling hfsplus_uni2asc():  [  667.121659][ T9805] ================================================================== [  667.122651][ T9805] BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0x902/0xa10 [  667.123627][…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38500 – In the Linux kernel, the following vulnerability has been resolved:

xfrm: inter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38500</guid>
    <pubDate>Tue, 12 Aug 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38500</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  xfrm: interface: fix use-after-free after changing collect_md xfrm interface  collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fail when called on such interfaces.  The check to enforce this was done only in the case where the xi was returned from xfrmi_locate() which does…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38491 – In the Linux kernel, the following vulnerability has been resolved:

mptcp: make...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38491</guid>
    <pubDate>Mon, 28 Jul 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38491</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mptcp: make fallback action and fallback decision atomic  Syzkaller reported the following splat:    WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/protocol.h:1223 [inline]   WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 mptcp_do_fallback net/mptcp/protocol.h:1244 [inline]   WARNING…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38184 – In the Linux kernel, the following vulnerability has been resolved:

tipc: fix n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38184</guid>
    <pubDate>Fri, 04 Jul 2025 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38184</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer  The reproduction steps: 1. create a tun interface 2. enable l2 bearer 3. TIPC_NL_UDP_GET_REMOTEIP with media name set to tun  tipc: Started in network mode tipc: Node identity 8af312d38a21, cluster identity 4711 tipc: Enabled bearer <eth:syz_tun>, priority 1 O…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38146 – In the Linux kernel, the following vulnerability has been resolved:

net: openvs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38146</guid>
    <pubDate>Thu, 03 Jul 2025 09:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38146</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: openvswitch: Fix the dead loop of MPLS parse  The unexpected MPLS packet may not end with the bottom label stack. When there are many stacks, The label count value has wrapped around. A dead loop occurs, soft lockup/CPU stuck finally.  stack backtrace: UBSAN: array-index-out-of-bounds in /build/linux-0Pa0xK/linux-5.15.0/net…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38106 – In the Linux kernel, the following vulnerability has been resolved:

io_uring: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38106</guid>
    <pubDate>Thu, 03 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38106</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  io_uring: fix use-after-free of sq->thread in __io_uring_show_fdinfo()  syzbot reports:  BUG: KASAN: slab-use-after-free in getrusage+0x1109/0x1a60 Read of size 8 at addr ffff88810de2d2c8 by task a.out/304  CPU: 0 UID: 0 PID: 304 Comm: a.out Not tainted 6.16.0-rc1 #1 PREEMPT(voluntary) Hardware name: QEMU Ubuntu 24.04 PC (i440FX…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-38091 – In the Linux kernel, the following vulnerability has been resolved:

drm/amd/dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38091</guid>
    <pubDate>Wed, 02 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-38091</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: check stream id dml21 wrapper to get plane_id  [Why & How] Fix a false positive warning which occurs due to lack of correct checks when querying plane_id in DML21. This fixes the warning when performing a mode1 reset (cat /sys/kernel/debug/dri/1/amdgpu_gpu_recover):  [   35.751250] WARNING: CPU: 11 PID: 326 at /…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49986 – In the Linux kernel, the following vulnerability has been resolved:

scsi: storv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49986</guid>
    <pubDate>Wed, 18 Jun 2025 11:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49986</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: storvsc: Remove WQ_MEM_RECLAIM from storvsc_error_wq  storvsc_error_wq workqueue should not be marked as WQ_MEM_RECLAIM as it doesn't need to make forward progress under memory pressure.  Marking this workqueue as WQ_MEM_RECLAIM may cause deadlock while flushing a non-WQ_MEM_RECLAIM workqueue.  In the current state it caus…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38032 – In the Linux kernel, the following vulnerability has been resolved:

mr: consoli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38032</guid>
    <pubDate>Wed, 18 Jun 2025 10:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38032</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mr: consolidate the ipmr_can_free_table() checks.  Guoyu Yin reported a splat in the ipmr netns cleanup path:  WARNING: CPU: 2 PID: 14564 at net/ipv4/ipmr.c:440 ipmr_free_table net/ipv4/ipmr.c:440 [inline] WARNING: CPU: 2 PID: 14564 at net/ipv4/ipmr.c:440 ipmr_rules_exit+0x135/0x1c0 net/ipv4/ipmr.c:361 Modules linked in: CPU: 2…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-37904 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37904</guid>
    <pubDate>Tue, 20 May 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-37904</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix the inode leak in btrfs_iget()  [BUG] There is a bug report that a syzbot reproducer can lead to the following busy inode at unmount time:    BTRFS info (device loop1): last unmount of filesystem 1680000e-3c1e-4c46-84b6-56bd3909af50   VFS: Busy inodes after unmount of loop1 (btrfs)   ------------[ cut here ]----------…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53112 – In the Linux kernel, the following vulnerability has been resolved:

drm/i915/ss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53112</guid>
    <pubDate>Fri, 02 May 2025 16:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53112</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/i915/sseu: fix max_subslices array-index-out-of-bounds access  It seems that commit bc3c5e0809ae ("drm/i915/sseu: Don't try to store EU mask internally in UAPI format") exposed a potential out-of-bounds access, reported by UBSAN as following on a laptop with a gen 11 i915 card:    UBSAN: array-index-out-of-bounds in drivers/…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32953 – z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32953</guid>
    <pubDate>Fri, 18 Apr 2025 21:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32953</strong></p>
  <p>z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubuntu.yml` workflow file uses `actions/upload-artifact@v4` to upload the `z80pack-ubuntu` artifact. This artifact is a zip of the current directory, which includes the automatically generated `.git/config` file containing the run's GITHUB_TOKEN. Seeing as the artifact can be downloa…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5616 – In Ubuntu, gnome-control-center did not properly reflect SSH remote login status...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5616</guid>
    <pubDate>Tue, 15 Apr 2025 19:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5616</strong></p>
  <p>In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49666 – In the Linux kernel, the following vulnerability has been resolved:

powerpc/mem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49666</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49666</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  powerpc/memhotplug: Add add_pages override for PPC  With commit ffa0b64e3be5 ("powerpc: Fix virt_addr_valid() for 64-bit Book3E & 32-bit") the kernel now validate the addr against high_memory value. This results in the below BUG_ON with dax pfns.  [  635.798741][T26531] kernel BUG at mm/page_alloc.c:5521! 1:mon> e cpu 0x1: Vecto…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49248 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: firew...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49248</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49248</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: firewire-lib: fix uninitialized flag for AV/C deferred transaction  AV/C deferred transaction was supported at a commit 00a7bb81c20f ("ALSA: firewire-lib: Add support for deferred transaction") while 'deferrable' flag can be uninitialized for non-control/notify AV/C transactions. UBSAN reports it:  kernel: ================…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-1736 – Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1736</guid>
    <pubDate>Fri, 31 Jan 2025 02:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-1736</strong></p>
  <p>Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56542 – In the Linux kernel, the following vulnerability has been resolved:

drm/amd/dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56542</guid>
    <pubDate>Fri, 27 Dec 2024 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56542</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: fix a memleak issue when driver is removed  Running "modprobe amdgpu" the second time (followed by a modprobe -r amdgpu) causes a call trace like:  [  845.212163] Memory manager not clean during takedown. [  845.212170] WARNING: CPU: 4 PID: 2481 at drivers/gpu/drm/drm_mm.c:999 drm_mm_takedown+0x2b/0x40 [  845.21…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11586 – Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11586</guid>
    <pubDate>Sat, 23 Nov 2024 03:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11586</strong></p>
  <p>Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-50177 – In the Linux kernel, the following vulnerability has been resolved:

drm/amd/dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50177</guid>
    <pubDate>Fri, 08 Nov 2024 06:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-50177</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: fix a UBSAN warning in DML2.1  When programming phantom pipe, since cursor_width is explicity set to 0, this causes calculation logic to trigger overflow for an unsigned int triggering the kernel's UBSAN check as below:  [   40.962845] UBSAN: shift-out-of-bounds in /tmp/amd.EfpumTkO/amd/amdgpu/../display/dc/dml2…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-49863 – In the Linux kernel, the following vulnerability has been resolved:

vhost/scsi:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49863</guid>
    <pubDate>Mon, 21 Oct 2024 18:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49863</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  vhost/scsi: null-ptr-dereference in vhost_scsi_get_req()  Since commit 3f8ca2e115e5 ("vhost/scsi: Extract common handling code from control queue handler") a null pointer dereference bug can be triggered when guest sends an SCSI AN request.  In vhost_scsi_ctl_handle_vq(), `vc.target` is assigned with `&v_req.tmf.lun[1]` within a…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47684 – In the Linux kernel, the following vulnerability has been resolved:

tcp: check ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47684</guid>
    <pubDate>Mon, 21 Oct 2024 12:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47684</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tcp: check skb is non-NULL in tcp_rto_delta_us()  We have some machines running stock Ubuntu 20.04.6 which is their 5.4.0-174-generic kernel that are running ceph and recently hit a null ptr dereference in tcp_rearm_rto(). Initially hitting it from the TLP path, but then later we also saw it getting hit from the RACK case as wel…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-44984 – In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44984</guid>
    <pubDate>Wed, 04 Sep 2024 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-44984</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bnxt_en: Fix double DMA unmapping for XDP_REDIRECT  Remove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT code path.  This should have been removed when we let the page pool handle the DMA mapping.  This bug causes the warning:  WARNING: CPU: 7 PID: 59 at drivers/iommu/dma-iommu.c:1198 iommu_dma_unmap_page+0xd5/0x1…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43899 – In the Linux kernel, the following vulnerability has been resolved:

drm/amd/dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43899</guid>
    <pubDate>Mon, 26 Aug 2024 11:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43899</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix null pointer deref in dcn20_resource.c  Fixes a hang thats triggered when MPV is run on a DCN401 dGPU:  mpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all  and then enabling fullscreen playback (double click on the video)  The following calltrace will be seen:  [  181.843989] BUG: kernel NULL pointer dereference,…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0115 – NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0115</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0115</strong></p>
  <p>NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service and data loss.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5290 – An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5290</guid>
    <pubDate>Wed, 07 Aug 2024 09:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5290</strong></p>
  <p>An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root).     Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the w…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1724 – In snapd versions prior to 2.62, when using AppArmor for enforcement of 
sandbox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1724</guid>
    <pubDate>Thu, 25 Jul 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1724</strong></p>
  <p>In snapd versions prior to 2.62, when using AppArmor for enforcement of  sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6388 – Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6388</guid>
    <pubDate>Thu, 27 Jun 2024 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6388</strong></p>
  <p>Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35235 – OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35235</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35235</strong></p>
  <p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as ro…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52816 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52816</guid>
    <pubDate>Tue, 21 May 2024 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52816</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Fix shift out-of-bounds issue  [  567.613292] shift exponent 255 is too large for 64-bit type 'long unsigned int' [  567.614498] CPU: 5 PID: 238 Comm: kworker/5:1 Tainted: G           OE      6.2.0-34-generic #34~22.04.1-Ubuntu [  567.614502] Hardware name: AMD Splinter/Splinter-RPL, BIOS WS43927N_871 09/25/2023 [  5…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35931 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35931</guid>
    <pubDate>Sun, 19 May 2024 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35931</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Skip do PCI error slot reset during RAS recovery  Why:     The PCI error slot reset maybe triggered after inject ue to UMC multi times, this     caused system hang.     [  557.371857] amdgpu 0000:af:00.0: amdgpu: GPU reset succeeded, trying to resume     [  557.373718] [drm] PCIE GART of 512M enabled.     [  557.3737…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35907 – In the Linux kernel, the following vulnerability has been resolved:

mlxbf_gige:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35907</guid>
    <pubDate>Sun, 19 May 2024 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35907</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mlxbf_gige: call request_irq() after NAPI initialized  The mlxbf_gige driver encounters a NULL pointer exception in mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce the exception is as follows: a) enable kdump b) trigger kdump via "echo c > /proc/sysrq-trigger" c) kdump kernel executes d) kdump kernel loads ml…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26907 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26907</guid>
    <pubDate>Wed, 17 Apr 2024 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26907</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Fix fortify source warning while accessing Eth segment   ------------[ cut here ]------------  memcpy: detected field-spanning write (size 56) of single field "eseg->inline_hdr.start" at /var/lib/dkms/mlnx-ofed-kernel/5.8/build/drivers/infiniband/hw/mlx5/wr.c:131 (size 2)  WARNING: CPU: 0 PID: 293779 at /var/lib/dkms/…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-2312 – GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2312</guid>
    <pubDate>Fri, 05 Apr 2024 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-2312</strong></p>
  <p>GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0081 – NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0081</guid>
    <pubDate>Fri, 05 Apr 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0081</strong></p>
  <p>NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful exploit of this vulnerability may lead to a server-side denial of service.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46960 – In the Linux kernel, the following vulnerability has been resolved:

cifs: Retur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46960</guid>
    <pubDate>Tue, 27 Feb 2024 19:04:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46960</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cifs: Return correct error code from smb2_get_enc_key  Avoid a warning if the error percolates back up:  [440700.376476] CIFS VFS: \\otters.example.com crypt_message: Could not get encryption key [440700.386947] ------------[ cut here ]------------ [440700.386948] err = 1 [440700.386977] WARNING: CPU: 11 PID: 2733 at /build/linu…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-48733 – An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48733</guid>
    <pubDate>Wed, 14 Feb 2024 22:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-48733</strong></p>
  <p>An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-4964 – Ubuntu's pipewire-pulse in snap grants microphone access even when the snap inte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4964</guid>
    <pubDate>Wed, 24 Jan 2024 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-4964</strong></p>
  <p>Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5536 – A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5536</guid>
    <pubDate>Tue, 12 Dec 2023 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5536</strong></p>
  <p>A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45866 – Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45866</guid>
    <pubDate>Fri, 08 Dec 2023 06:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45866</strong></p>
  <p>Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CV…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3297 – In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-aft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3297</guid>
    <pubDate>Fri, 01 Sep 2023 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3297</strong></p>
  <p>In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32629 – Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32629</guid>
    <pubDate>Wed, 26 Jul 2023 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32629</strong></p>
  <p>Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2640 – On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2640</guid>
    <pubDate>Wed, 26 Jul 2023 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2640</strong></p>
  <p>On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-24492 – A vulnerability has been discovered in the Citrix Secure Access client for Ubunt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24492</guid>
    <pubDate>Tue, 11 Jul 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-24492</strong></p>
  <p>A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-2612 – Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2612</guid>
    <pubDate>Wed, 31 May 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-2612</strong></p>
  <p>Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30549 – Apptainer is an open source container platform for Linux. There is an ext4 use-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30549</guid>
    <pubDate>Tue, 25 Apr 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30549</strong></p>
  <p>Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian 10 buster (unless the linux-5.10 package is installed), Ubuntu 18.04 bionic and…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27705 – APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27705</guid>
    <pubDate>Mon, 17 Apr 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27705</strong></p>
  <p>APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25595 – A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25595</guid>
    <pubDate>Wed, 22 Mar 2023 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25595</strong></p>
  <p>A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a sensitive nature to the ClearPass/OnGuard environment.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-1277 – A vulnerability, which was classified as critical, was found in kylin-system-upd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1277</guid>
    <pubDate>Wed, 08 Mar 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-1277</strong></p>
  <p>A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222600.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44544 – Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44544</guid>
    <pubDate>Sun, 06 Nov 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44544</strong></p>
  <p>Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-41352 – An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41352</guid>
    <pubDate>Mon, 26 Sep 2022 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41352</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-40297 – UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40297</guid>
    <pubDate>Fri, 09 Sep 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-40297</strong></p>
  <p>UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40297">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
