Where
-Infinity
0

On Fri, Jun 06, 2025 at 06:00:09PM +0200, Attila Szasz wrote: I don't see how Canonical Product Security is a bad actor here for caring about the actual security of downstream users and acting in a timely manner about an issue that they considered to impact Ubuntu Linux, correctly.

Canonical has a scope of "All Canonical issues (including Ubuntu Linux) only."

kernel.rg has a scope of "Any vulnerabilities in the Linux kernel as listed on kernel.org, excluding end-of-life (EOL) versions."

Both of them were contacted. For the record, the CNA for kernel.org was NOT contacted here at all for this issue. You sent a message to security () kernel org, NOT cve () kernel org. security@k.o has nothing to do with CVE assignments and is NOT responsible for the kernel.org CNA. Our documentation should state this very clearly, if not, we will be glad to update it where needed, just let us know. 4.2.2.1 CNAs SHOULD assign a CVE ID if:

the CNA has reasonable evidence to determine the existence of a     Vulnerability (4.1), and     the Vulnerability has been or is expected to be Publicly Disclosed, and     the CNA has appropriate scope (3.1).

On 3rd Nov, 2024, Kees Cook writes: "The hfsplus filesystem currently has no maintainer, and since we don't view filesystem corruption flaws to be particularly sensitive, probably the best thing to do would be to send the patch like normal to the public linux-fsdevel () vger kernel org (please keep me and other others in this email's CC now on the CC for your patch).

Let's see if the VFS maintainers have any other thoughts on this? (I am forwarding them a copy of the original email now.)"

This is pretty much the last update—no patch is introduced, nor is a CVE issued. The issue is not viewed as sensitive. Again, no one asked for a CVE to be assigned, nor did anyone notify the kernel.org CNA about this issue. My understanding is that 4.1 was not satisfied according to them. Nope, we never were even notified. That being said, we defer to the filesystem maintainers here, and they have stated many times before that hand-crafted filesystems are not a vulnerability according to their rules. That is why we rejected the CVE eventually. CVE-2025-0927 was reserved by Canonical on 31st January, 2025, around the time they fixed the issue internally.

At this point, Canonical, as per 4.2.2.1, assigned a CVE for Canonical Ubuntu Linux for the issue they deemed a vulnerability in Ubuntu Linux.

The kernel neither assigned nor fixed anything regarding the email that was sent to them.

After Canonical’s fix went live, the public advisory was published on 18 March, 2025.

Now, according to:

4.2.1.2 For Publicly Disclosed Vulnerabilities, if the CNA with the most appropriate scope:

preemptively documents that it will not assign, or     responds within 72 hours that it will not assign, or     does not respond within 72 hours,

then an appropriate Root MUST make a Vulnerability determination.

So the kernel.org CNA team would have had 72 hours to respond to the public disclosure if they thought that the issue was in their scope—but they didn’t. Again, you never notified the kernel.org CNA about this, nor do we even attempt to watch all CVEs that are being created in the system as we just assume that all CNAs are "good actors" and don't do foolish things like this :) So what the hell happens to consumers of the Ubuntu Linux product that don't want their boxes rooted by non-sudoers according to the CNA?

How could Canonical be the bad cowboy here? Someone please enlighten me. They created a CVE against the upstream kernel.org codebase without EVER contacting the kernel.org CNA. That is against the CNA rules, which is why cve.org reassigned the CVE to kernel.org when notified of this. In fact, I'm not even sure upstream would have ever fixed this unless Salvatore reached out from Debian basically asking what had happened:

https://lore.kernel.org/lkml/Z9xsx-w4YCBuYjx5 () eldamar lan/

Note that the initial report was received by security@ early November, 2024. Salvatore's message is dated 20th March. Again, security@k.o has nothing to do with CVEs. After that, Canonical helps Debian by sharing the fix they used in the Ubuntu kernel.

Then, on 24th March, 2024, the Linux CNA finally expresses interest in owning the CVE—that is, 6 days after the disclosure and 72 hours past the deadline defined in 4.2.1.2. Again, no one ever notified cve () kernel org about this, so that is why we did not react until we actually were notified, and then we did act then to get the CVE assigned back to kernel.org

Hope this helps explain things as to why the kernel.org CNA didn't do anything here, because again, they were never notified.

Anyway, we know communication mistakes can happen, not a big deal, we got the CVE reassigned properly, which again, happens every few months with other companies accidentally assigning CVEs against kernel.org stuff, and we move on. Given we are running at a rate of 13+ CVEs a day, stuff like this is bound to happen. All we can do is properly deal with it when we are notified, like we did.

thanks,

greg k-h

If it is genuinely not a kernel vulnerability, but only a Ubuntu one for using the kernel outside of its supported operating parameters, then "make it very clear" does indeed sound correct.

If Ubuntu (or others) believe the kernel.org CNA is incorrect and a) abusing their authority / b) simply lacking good judgement on security matters, for something that is a legit kernel vulnerability, isn't that what the appeals arbitration process is for? Raise the dispute with the appropriate root, and have them overturn the kernel.org decision.

It is, anyways, inappropriate "cowboy justice" for a CNA to violate its scope and assign a CVE number they aren't authorized for, just because they disagree with the other CNA's decision. If Ubuntu (knowingly) isn't going through the correct process then for that reason alone Ubuntu is the bad actor here and should be penalized.

I don't see how Canonical Product Security is a bad actor here for caring about the actual security of downstream users and acting in a timely manner about an issue that they considered to impact Ubuntu Linux, correctly.

Canonical has a scope of "All Canonical issues (including Ubuntu Linux) only."

kernel.rg has a scope of "Any vulnerabilities in the Linux kernel as listed on kernel.org, excluding end-of-life (EOL) versions."

Both of them were contacted.

4.2.2.1 CNAs SHOULD assign a CVE ID if:

the CNA has reasonable evidence to determine the existence of a     Vulnerability (4.1), and the CNA has appropriate scope (3.1).

On 3rd Nov, 2024, Kees Cook writes: "The hfsplus filesystem currently has no maintainer, and since we don't view filesystem corruption flaws to be particularly sensitive, probably the best thing to do would be to send the patch like normal to the public linux-fsdevel () vger kernel org (please keep me and other others in this email's CC now on the CC for your patch).

Let's see if the VFS maintainers have any other thoughts on this? (I am forwarding them a copy of the original email now.)"

This is pretty much the last update—no patch is introduced, nor is a CVE issued. The issue is not viewed as sensitive.

My understanding is that 4.1 was not satisfied according to them.

CVE-2025-0927 was reserved by Canonical on 31st January, 2025, around the time they fixed the issue internally.

At this point, Canonical, as per 4.2.2.1, assigned a CVE for Canonical Ubuntu Linux for the issue they deemed a vulnerability in Ubuntu Linux.

The kernel neither assigned nor fixed anything regarding the email that was sent to them.

After Canonical’s fix went live, the public advisory was published on 18 March, 2025.

Now, according to:

4.2.1.2 For Publicly Disclosed Vulnerabilities, if the CNA with the most appropriate scope:

preemptively documents that it will not assign, or     responds within 72 hours that it will not assign, or     does not respond within 72 hours,

then an appropriate Root MUST make a Vulnerability determination.

So the kernel.org CNA team would have had 72 hours to respond to the public

So what the hell happens to consumers of the Ubuntu Linux product that don't want their boxes rooted by non-sudoers according to the CNA?

How could Canonical be the bad cowboy here? Someone please enlighten me. reached out from Debian basically asking what had happened:

https://lore.kernel.org/lkml/Z9xsx-w4YCBuYjx5 () eldamar lan/ Salvatore's message is dated 20th March.

After that, Canonical helps Debian by sharing the fix they used in the Ubuntu kernel.

Then, on 24th March, 2024, the Linux CNA finally expresses interest in owning the CVE—that is, 6 days after the disclosure and 72 hours past the deadline defined in 4.2.1.2.

Only then is the bug finally fixed, on 7th April—156 days after the report, The CVE, now transferred to kernel.org's scope is rejected on the 8th of April UTC 4am - from my timezone, on the same day.

Canonical addressed everything within 90 days. What's the problem? legitimate Product Security team as a "bad actor" and to focus on systems and users—is categorically stupid.

The real priority should be ensuring that users and businesses are:

properly informed about the risks, and

provided with the necessary remediation steps.

Anything else is a distraction from what truly matters.

USN-7490-1 fixed vulnerabilities in libsoup. It was discovered that the fix for CVE-2025-32912 was incomplete. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Tan Wei Chong discovered that libsoup incorrectly handled memory when parsing HTTP request headers. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service. (CVE-2025-32906) Alon Zahavi discovered that libsoup incorrectly parsed video files. An attacker could possibly use this issue to send a maliciously crafted HTTP response back to the client, causing a denial of service, or leading to undefined behavior. (CVE-2025-32909) Jan Różański discovered that libsoup incorrectly handled memory when parsing authentication headers. An attacker could possibly use this issue to send a maliciously crafted HTTP response back to the client, causing a denial of service. (CVE-2025-32910, CVE-2025-32912) It was discovered that libsoup incorrectly handled data in the hash table data type. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service or remote code execution. (CVE-2025-32911) Jan Różański discovered that libsoup incorrectly handled memory when parsing the content disposition HTTP header. An attacker could possibly use this issue to send maliciously crafted data to a client or server, causing a denial of service. (CVE-2025-32913) Alon Zahavi discovered that libsoup incorrectly handled memory when parsing HTTP requests. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service or obtaining sensitive information. (CVE-2025-32914) It was discovered that libsoup incorrectly handled memory when parsing quality-list headers. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service. (CVE-2025-46420) Jan Różański discovered that libsoup did not strip authorization information upon redirects. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-46421)

First published (updated )
Advisory
USN-7490-2

It was discovered that Corosync incorrectly handled certain large UDP packets. If encryption is disabled, or an attacker knows the encryption key, this issue could be used to cause Corosync to crash, resulting in a denial of service.

First published (updated )
Advisory
USN-7478-1

It was discovered that c-ares incorrectly handled re-enqueuing certain queries. A remote attacker could possibly use this issue to cause c-ares to crash, resulting in a denial of service.

First published (updated )
Advisory
USN-7477-1

It was discovered that poppler did not properly verify adbe.pkcs7.sha1 signatures in PDF documents. An attacker could possibly use this issue to create documents with forged signatures that are treated as legitimately signed.

First published (updated )
Advisory
USN-7471-1

It was discovered that Jupyter Notebook did not properly parse HTML comments under certain circumstances. An attacker could possibly use this issue to cause a regular expression denial of service (ReDoS).

First published (updated )
Advisory
USN-7464-1

Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:

First published (updated )
Advisory
USN-7468-1

It was discovered that KiCad incorrectly handled memory when opening malicious files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary commands.

First published (updated )
Advisory
USN-7466-1

It was discovered that Mistral incorrectly handled nested anchors in YAML files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848) Pierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH private key filename commands. An attacker could possibly use this issue to expose sensitive information. (CVE-2018-16849) It was discovered that Mistral incorrectly handled the permissions of sensitive log files. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-3866)

First published (updated )
Advisory
USN-7465-1

USN-7467-1 fixed several vulnerabilities in libxml2. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that the libxml2 Python bindings incorrectly handled certain return values. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32414) It was discovered that libxml2 incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32415)

First published (updated )
Advisory
USN-7467-2

It was discovered that OpenSSH incorrectly handled the DisableForwarding directive. The directive would fail to disable X11 and agent forwarding, contrary to documentation and expectations.

First published (updated )
Advisory
USN-7457-1

Fabien Potencier discovered that Twig did not run sandbox security checks in some circumstances. An attacker could possibly use this issue to cause a denial of service or execute arbitrary commands. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-45411) Jamie Schouten discovered that Twig could bypass the security policy for an object call. An attacker could possibly use this issue to obtain sensitive information. (CVE-2024-51754)

First published (updated )
Advisory
USN-7456-1

It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:

First published (updated )
Advisory
USN-7448-1

USN-7431-1 fixed a vulnerability in HAProxy. This update provides the corresponding update for Ubuntu 25.04. Original advisory details: Aleandro Prudenzano and Edoardo Geraci discovered that HAProxy incorrectly handled certain uncommon configurations that replace multiple short patterns with a longer one. A remote attacker could use this issue to cause HAProxy to crash, resulting in a denial of service, or possibly execute arbitrary code.

First published (updated )
Advisory
USN-7431-2

It was discovered that Yelp incorrectly handled paths in ghelp URLs. A remote attacker could use this issue to trick users into opening malicious downloaded help files and exfiltrate sensitive information.

First published (updated )
Advisory
USN-7447-1

USN-7434-1 fixed a vulnerability in Perl. This update provides the corresponding update for Ubuntu 25.04. Original advisory details: It was discovered that Perl incorrectly handled transliterating non-ASCII bytes. A remote attacker could use this issue to cause Perl to crash, resulting in a denial of service, or possibly execute arbitrary code.

First published (updated )
Advisory
USN-7434-2

USN-7443-1 fixed a vulnerability in Erlang. This update provides the corresponding update for Ubuntu 25.04. Original advisory details: Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk discovered that Erlang OTP’s SSH module incorrect handled authentication. A remote attacker could use this issue to execute arbitrary commands without authentication, possibly leading to a system compromise.

First published (updated )
Advisory
USN-7443-2

It was discovered that modauthopenidc incorrectly handled certain POST requests. An attacker could possibly use this issue to obtain sensitive information.

First published (updated )
Advisory
USN-7446-1

It was discovered that the libarchive bsdunzip utility incorrectly handled certain ZIP archive files. If a user or automated system were tricked into processing a specially crafted ZIP archive, an attacker could use this issue to cause libarchive to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-1632) It was discovered that libarchive incorrectly handled certain TAR archive files. If a user or automated system were tricked into processing a specially crafted TAR archive, an attacker could use this issue to cause libarchive to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-25724)

First published (updated )
Advisory
USN-7454-1

It was discovered that Synapse network policies could be bypassed via specially crafted URLs. An attacker could possibly use this issue to bypass authentication mechanisms. (CVE-2023-32683) It was discovered that Synapse exposed cached device information. An attacker could possibly use this issue to gain access to sensitive information. (CVE-2023-43796) It was discovered that Synapse could be tricked into rejecting state changes in rooms. An attacker could possibly use this issue to cause Synapse to stop functioning properly, resulting in a denial of service. This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-39374) It was discovered that Synapse stored user credentials in a server's database temporarily. An attacker could possibly use this issue to gain access to sensitive information. This issue was only fixed in Ubuntu 22.04 LTS. (CVE-2023-41335) It was discovered that Synapse could incorrectly respond to server authorization events. An attacker could possibly use this issue to bypass authentication mechanisms. This issue was only fixed in Ubuntu 22.04 LTS. (CVE-2022-39335) It was discovered that Synapse could be manipulated to mark messages as read when they had not been viewed. An attacker could possibly use this issue to perform repudiation-based attacks. This issue was only fixed in Ubuntu 22.04 LTS. (CVE-2023-42453) It was discovered that Synapse had several memory-related issues. An attacker could possibly use this issue to cause Synapse to crash, resulting in a denial of service. This issue was only fixed in Ubuntu 22.04 LTS. (CVE-2024-31208) It was discovered that Synapse could run external tools due to a unchecked thumbnail rendering routine. An attacker could possibly use this issue to cause Synapse to crash, resulting in a denial of service, or execute arbitrary code. This issue was only fixed in Ubuntu 22.04 LTS. (CVE-2024-53863)

First published (updated )
Advisory
USN-7444-1

Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk discovered that Erlang OTP’s SSH module incorrect handled authentication. A remote attacker could use this issue to execute arbitrary commands without authentication, possibly leading to a system compromise.

First published (updated )
Advisory
USN-7443-1

USN-6200-2 fixed a vulnerability in ImageMagick. It was discovered that the fix for CVE-2023-34151 was incomplete. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted image file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. (CVE-2023-34151)

First published (updated )
Advisory
USN-7440-1

It was discovered that Eclipse Mosquitto client incorrectly handled memory when receiving a SUBACK packet. An attacker with a malicious broker could possibly use this issue to execute arbitrary code or cause a denial of service. (CVE-2024-10525) Xiangpu Song discovered that Eclipse Mosquitto broker did not properly manage memory under certain circumstances. A malicious client with a remote connection could possibly use this issue to cause the broker to crash resulting in a denial of service, or another unspecified impact. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-3935)

First published (updated )
Advisory
USN-7441-1
Buffer Overflow

It was discovered that the CImg library did not properly check the size of images before loading them. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-1325) It was discovered that the CImg library did not correctly handle certain memory operations, which could lead to a buffer overflow. An attacker could possibly use this issue to execute arbitrary code or cause a denial of service. (CVE-2024-26540)

First published (updated )
Advisory
USN-7437-1

USN-7161-1 and USN-7161-2 fixed CVE-2024-41110 for source package docker.io in Ubuntu 18.04 LTS and for source package docker.io-app in Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. This update fixes it for source package docker.io in Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. These updates only address the docker library and not the docker.io application itself, which was already patched in the previous USNs (USN-7161-1 and USN-7161-2). Original advisory details: Yair Zak discovered that Docker could unexpectedly forward DNS requests from internal networks in an unexpected manner. An attacker could possibly use this issue to exfiltrate data by encoding information in DNS queries to controlled nameservers. This issue was only addressed for the source package docker.io-app in Ubuntu 24.04 LTS. (CVE-2024-29018) Cory Snider discovered that Docker did not properly handle authorization plugin request processing. An attacker could possibly use this issue to bypass authorization controls by forwarding API requests without their full body, leading to unauthorized actions. This issue was only addressed for the source package docker.io-app in Ubuntu 24.10 and Ubuntu 24.04 LTS, and the source package docker.io in Ubuntu 18.04 LTS. (CVE-2024-41110)

First published (updated )
Advisory
USN-7161-3

It was discovered that QuickJS could be forced to reference uninitialized memory in certain instances. An attacker could possibly use this issue to cause QuickJS to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2023-48183) It was discovered that QuickJS incorrectly managed memory in certain circumstances. An attacker could possibly use this issue to exhaust system resources, resulting in a denial of service. (CVE-2023-48184) It was discovered that QuickJS could be forced to crash due to a failing test. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-33263)

First published (updated )
Advisory
USN-7439-1

Igor Pavlov discovered that 7-Zip had several memory-related issues. An attacker could possibly use these issues to cause 7-Zip to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2023-52168, CVE-2023-52169)

First published (updated )
Advisory
USN-7438-1

It was discovered that GraphicsMagick did not properly limit image dimensions, which could lead to excessive memory consumption. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-27795) It was discovered that GraphicsMagick did not properly handle certain memory operations, which could lead to a out-of-bounds memory access. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 24.10. (CVE-2025-27796)

First published (updated )
Advisory
USN-7433-1

It was discovered that Perl incorrectly handled transliterating non-ASCII bytes. A remote attacker could use this issue to cause Perl to crash, resulting in a denial of service, or possibly execute arbitrary code.

First published (updated )
Advisory
USN-7434-1

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203