Search CVE reports


Toggle filters

581 – 590 of 40627 results

Status is adjusted based on your filters.


CVE-2026-41054

Medium priority
Fixed

In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a...

1 affected package

haveged

Package 22.04 LTS
haveged Fixed
Show less packages

CVE-2026-47784

Medium priority
Fixed

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

1 affected package

memcached

Package 22.04 LTS
memcached Fixed
Show less packages

CVE-2026-47783

Medium priority
Fixed

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

1 affected package

memcached

Package 22.04 LTS
memcached Fixed
Show less packages

CVE-2026-5950

Medium priority

Some fixes available 1 of 2

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 22.04 LTS
bind9 Fixed
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-5947

Medium priority
Needs evaluation

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 22.04 LTS
bind9 Not affected
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-5946

Medium priority

Some fixes available 1 of 2

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 22.04 LTS
bind9 Fixed
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-46529

Medium priority

Some fixes available 1 of 2

PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen

4 affected packages

atril, evince, evince-gtk3, papers

Package 22.04 LTS
atril Needs evaluation
evince Fixed
evince-gtk3 Not in release
papers Not in release
Show less packages

CVE-2026-46433

Medium priority
Needs evaluation

[Heap OOB Read in VLAN Decapsulation memmove]

2 affected packages

lldpd, openvswitch

Package 22.04 LTS
lldpd Needs evaluation
openvswitch Needs evaluation
Show less packages

CVE-2026-45793

Medium priority
Not affected

[Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs]

1 affected package

composer

Package 22.04 LTS
composer Not affected
Show less packages

CVE-2026-45699

Medium priority
Needs evaluation

security update

1 affected package

netatalk

Package 22.04 LTS
netatalk Needs evaluation
Show less packages