Search CVE reports


Toggle filters

61 – 70 of 541 results


CVE-2026-28390

Low priority

Some fixes available 9 of 20

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-28389

Low priority

Some fixes available 9 of 20

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-28388

Low priority

Some fixes available 10 of 21

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-28387

Low priority

Some fixes available 7 of 18

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Not affected
Show less packages

CVE-2026-28386

Low priority
Not affected

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 — Not affected Not affected Not affected Not affected
nodejs — Not affected Not affected Not affected Not affected
openssl — Not affected Not affected Not affected Not affected
openssl-fips — Not affected Not affected — —
openssl1.0 — Not in release Not in release — Not affected
Show less packages

CVE-2026-35414

Medium priority

Some fixes available 8 of 14

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35388

Medium priority

Some fixes available 4 of 14

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35387

Medium priority

Some fixes available 8 of 14

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35386

Medium priority

Some fixes available 5 of 11

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Not affected Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35385

Medium priority

Some fixes available 8 of 14

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages