/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/openeuler_csaf.csv
101 строка4 MB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
openEuler-SA-2026-2332
An update for gnutls is now available for openEuler-22.03-LTS-SP4
High
2026-05-15 17:04:35+03:00
2026-05-15 17:04:35+03:00
['CVE-2026-33846']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-3.7.2-22.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-22.oe2203sp4.src.rpm', 'product_id': 'gnutls-3.7.2-22.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-3.7.2-22.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-help-3.7.2-22.oe2203sp4.noarch.rpm', 'product_id': 'gnutls-help-3.7.2-22.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2332', 'summary': 'openEuler-SA-2026-2332', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2332.json', 'summary': 'openEuler-SA-2026-2332 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.(CVE-2026-33846)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2332', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:35+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:35+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:35+08:00', 'initial_release_date': '2026-05-15T22:04:35+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2332', 'summary': 'openEuler-SA-2026-2332', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2332.json', 'summary': 'openEuler-SA-2026-2332 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.7.2-22.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.7.2-22.oe2203sp4.src.rpm', 'product': {'name': 'gnutls-3.7.2-22.oe2203sp4.src.rpm', 'product_id': 'gnutls-3.7.2-22.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.7.2-22.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.7.2-22.oe2203sp4.noarch.rpm', 'product': {'name': 'gnutls-help-3.7.2-22.oe2203sp4.noarch.rpm', 'product_id': 'gnutls-help-3.7.2-22.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-22.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-22.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-3.7.2-22.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-22.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-devel-3.7.2-22.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-22.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-utils-3.7.2-22.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-22.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-22.oe2203sp4.src'}, 'product_reference': 'gnutls-3.7.2-22.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-22.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-22.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-3.7.2-22.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-22.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-devel-3.7.2-22.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-22.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-utils-3.7.2-22.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.7.2-22.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-help-3.7.2-22.oe2203sp4.noarch'}, 'product_reference': 'gnutls-help-3.7.2-22.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33846', 'notes': [{'text': 'A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33846', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2332', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:gnutls-3.7.2-22.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-22.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-22.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-22.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-22.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-22.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-22.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-22.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-22.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-22.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-22.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-help-3.7.2-22.oe2203sp4.noarch']}}]}
be998aa8f8ef6a83135e3d11ef9777d7e3e2b2fc35ee1cc3eb93724652c73463
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2333
An update for gnutls is now available for openEuler-24.03-LTS
Critical
2026-05-15 17:04:35+03:00
2026-05-15 17:04:35+03:00
['CVE-2026-33846', 'CVE-2026-3833', 'CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260', 'CVE-2026-5419']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-dane-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-devel-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-utils-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-3.8.2-14.oe2403.src.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-dane-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-devel-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-utils-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-help-3.8.2-14.oe2403.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-14.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'summary': 'openEuler-SA-2026-2333', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5419&packageName=gnutls', 'summary': 'CVE-2026-5419', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5419', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2333.json', 'summary': 'openEuler-SA-2026-2333 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.(CVE-2026-33846)\n\nA flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.(CVE-2026-3833)\n\n(CVE-2026-42009)\n\nA flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.(CVE-2026-42010)\n\n(CVE-2026-42013)\n\n(CVE-2026-42014)\n\n(CVE-2026-42015)\n\n(CVE-2026-5260)\n\n(CVE-2026-5419)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2333', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:35+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:35+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:35+08:00', 'initial_release_date': '2026-05-15T22:04:35+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'summary': 'openEuler-SA-2026-2333', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5419&packageName=gnutls', 'summary': 'CVE-2026-5419', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5419', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2333.json', 'summary': 'openEuler-SA-2026-2333 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-14.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-14.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-14.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-14.oe2403.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403.src.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403.src.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-14.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-14.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-14.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-14.oe2403.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.8.2-14.oe2403.noarch.rpm', 'product': {'name': 'gnutls-help-3.8.2-14.oe2403.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-14.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-3.8.2-14.oe2403.aarch64'}, 'product_reference': 'gnutls-3.8.2-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-dane-3.8.2-14.oe2403.aarch64'}, 'product_reference': 'gnutls-dane-3.8.2-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-14.oe2403.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-14.oe2403.aarch64'}, 'product_reference': 'gnutls-debugsource-3.8.2-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-devel-3.8.2-14.oe2403.aarch64'}, 'product_reference': 'gnutls-devel-3.8.2-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-utils-3.8.2-14.oe2403.aarch64'}, 'product_reference': 'gnutls-utils-3.8.2-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-3.8.2-14.oe2403.src'}, 'product_reference': 'gnutls-3.8.2-14.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-3.8.2-14.oe2403.x86_64'}, 'product_reference': 'gnutls-3.8.2-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-dane-3.8.2-14.oe2403.x86_64'}, 'product_reference': 'gnutls-dane-3.8.2-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-14.oe2403.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-14.oe2403.x86_64'}, 'product_reference': 'gnutls-debugsource-3.8.2-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-devel-3.8.2-14.oe2403.x86_64'}, 'product_reference': 'gnutls-devel-3.8.2-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-utils-3.8.2-14.oe2403.x86_64'}, 'product_reference': 'gnutls-utils-3.8.2-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.8.2-14.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-help-3.8.2-14.oe2403.noarch'}, 'product_reference': 'gnutls-help-3.8.2-14.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33846', 'notes': [{'text': 'A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33846', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:gnutls-3.8.2-14.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-dane-3.8.2-14.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-14.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-14.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-devel-3.8.2-14.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-utils-3.8.2-14.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-3.8.2-14.oe2403.src', 'openEuler-24.03-LTS:gnutls-3.8.2-14.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-dane-3.8.2-14.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-14.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-14.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-devel-3.8.2-14.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-utils-3.8.2-14.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-help-3.8.2-14.oe2403.noarch']}}, {'cve': 'CVE-2026-3833', 'notes': [{'text': 'A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3833', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42009', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42010', 'notes': [{'text': 'A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42013', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42013', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42014', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42015', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42015', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5260', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5419', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5419', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.7, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2333', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
c1112ce65ef9574bc83198777c21779b32ff7780f400dcf1f1405428cc4cfff8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2334
An update for gnutls is now available for openEuler-24.03-LTS-SP1
Critical
2026-05-15 17:04:35+03:00
2026-05-15 17:04:35+03:00
['CVE-2026-33846', 'CVE-2026-3833', 'CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260', 'CVE-2026-5419']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-help-3.8.2-14.oe2403sp1.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-14.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-3.8.2-14.oe2403sp1.src.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp1.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'summary': 'openEuler-SA-2026-2334', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5419&packageName=gnutls', 'summary': 'CVE-2026-5419', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5419', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2334.json', 'summary': 'openEuler-SA-2026-2334 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.(CVE-2026-33846)\n\nA flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.(CVE-2026-3833)\n\n(CVE-2026-42009)\n\nA flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.(CVE-2026-42010)\n\n(CVE-2026-42013)\n\n(CVE-2026-42014)\n\n(CVE-2026-42015)\n\n(CVE-2026-5260)\n\n(CVE-2026-5419)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2334', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:35+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:35+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:35+08:00', 'initial_release_date': '2026-05-15T22:04:35+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'summary': 'openEuler-SA-2026-2334', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5419&packageName=gnutls', 'summary': 'CVE-2026-5419', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5419', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2334.json', 'summary': 'openEuler-SA-2026-2334 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.8.2-14.oe2403sp1.noarch.rpm', 'product': {'name': 'gnutls-help-3.8.2-14.oe2403sp1.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-14.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403sp1.src.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403sp1.src.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-14.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-3.8.2-14.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-14.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-dane-3.8.2-14.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-14.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-devel-3.8.2-14.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-14.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-utils-3.8.2-14.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.8.2-14.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-help-3.8.2-14.oe2403sp1.noarch'}, 'product_reference': 'gnutls-help-3.8.2-14.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-14.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-3.8.2-14.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-14.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-dane-3.8.2-14.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-14.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-devel-3.8.2-14.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-14.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-utils-3.8.2-14.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-14.oe2403sp1.src'}, 'product_reference': 'gnutls-3.8.2-14.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33846', 'notes': [{'text': 'A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33846', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:gnutls-3.8.2-14.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-14.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-14.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-14.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-14.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-14.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-help-3.8.2-14.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-14.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-14.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-14.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-14.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-14.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-14.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-14.oe2403sp1.src']}}, {'cve': 'CVE-2026-3833', 'notes': [{'text': 'A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3833', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42009', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42010', 'notes': [{'text': 'A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42013', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42013', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42014', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42015', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42015', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5260', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5419', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5419', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.7, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2334', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
a1d3d05556b7b3305c2806927653685353f3af24cbf67b7d4019a2b87d04b362
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2335
An update for gnutls is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-15 17:04:35+03:00
2026-05-15 17:04:35+03:00
['CVE-2026-33846', 'CVE-2026-3833', 'CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260', 'CVE-2026-5419']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-3.8.2-14.oe2403sp3.src.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-help-3.8.2-14.oe2403sp3.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-14.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'summary': 'openEuler-SA-2026-2335', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5419&packageName=gnutls', 'summary': 'CVE-2026-5419', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5419', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2335.json', 'summary': 'openEuler-SA-2026-2335 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.(CVE-2026-33846)\n\nA flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.(CVE-2026-3833)\n\n(CVE-2026-42009)\n\nA flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.(CVE-2026-42010)\n\n(CVE-2026-42013)\n\n(CVE-2026-42014)\n\n(CVE-2026-42015)\n\n(CVE-2026-5260)\n\n(CVE-2026-5419)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2335', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:35+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:35+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:35+08:00', 'initial_release_date': '2026-05-15T22:04:35+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'summary': 'openEuler-SA-2026-2335', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33846&packageName=gnutls', 'summary': 'CVE-2026-33846', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5419&packageName=gnutls', 'summary': 'CVE-2026-5419', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33846', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5419', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2335.json', 'summary': 'openEuler-SA-2026-2335 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403sp3.src.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403sp3.src.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.8.2-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.8.2-14.oe2403sp3.noarch.rpm', 'product': {'name': 'gnutls-help-3.8.2-14.oe2403sp3.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-14.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-14.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-3.8.2-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-14.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-dane-3.8.2-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-14.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-devel-3.8.2-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-14.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-utils-3.8.2-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-14.oe2403sp3.src'}, 'product_reference': 'gnutls-3.8.2-14.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-14.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-3.8.2-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-14.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-dane-3.8.2-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-14.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-devel-3.8.2-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-14.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-utils-3.8.2-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.8.2-14.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-14.oe2403sp3.noarch'}, 'product_reference': 'gnutls-help-3.8.2-14.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33846', 'notes': [{'text': 'A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33846', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:gnutls-3.8.2-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-14.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-14.oe2403sp3.noarch']}}, {'cve': 'CVE-2026-3833', 'notes': [{'text': 'A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3833', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42009', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42010', 'notes': [{'text': 'A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42013', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42013', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42014', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42015', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42015', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5260', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5419', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5419', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.7, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2335', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
d8655e4e75b9afad20a065025612f455144391000a4c8d6736fb5ec47e6a954f
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2336
An update for libssh2 is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4
High
2026-05-15 17:04:36+03:00
2026-05-15 17:04:36+03:00
['CVE-2026-7598']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-1.10.0-8.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-devel-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-1.9.0-10.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-1.10.0-8.oe2203sp4.src.rpm', 'product_id': 'libssh2-1.10.0-8.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-1.11.0-6.oe2403.src.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-1.11.0-6.oe2403sp1.src.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-1.11.0-6.oe2403sp3.src.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-1.9.0-10.oe2003sp4.src.rpm', 'product_id': 'libssh2-1.9.0-10.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-1.10.0-8.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-devel-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-1.9.0-10.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libssh2-help-1.10.0-8.oe2203sp4.noarch.rpm', 'product_id': 'libssh2-help-1.10.0-8.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libssh2-help-1.11.0-6.oe2403.noarch.rpm', 'product_id': 'libssh2-help-1.11.0-6.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libssh2-help-1.11.0-6.oe2403sp1.noarch.rpm', 'product_id': 'libssh2-help-1.11.0-6.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libssh2-help-1.11.0-6.oe2403sp3.noarch.rpm', 'product_id': 'libssh2-help-1.11.0-6.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libssh2-help-1.9.0-10.oe2003sp4.noarch.rpm', 'product_id': 'libssh2-help-1.9.0-10.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2336', 'summary': 'openEuler-SA-2026-2336', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7598&packageName=libssh2', 'summary': 'CVE-2026-7598', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7598', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2336.json', 'summary': 'openEuler-SA-2026-2336 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libssh2 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libssh2 is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10).\n\nSecurity Fix(es):\n\nA security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.(CVE-2026-7598)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libssh2 is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libssh2', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libssh2 is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2336', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:36+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:36+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:36+08:00', 'initial_release_date': '2026-05-15T22:04:36+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2336', 'summary': 'openEuler-SA-2026-2336', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7598&packageName=libssh2', 'summary': 'CVE-2026-7598', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7598', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2336.json', 'summary': 'openEuler-SA-2026-2336 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libssh2-1.10.0-8.oe2203sp4.aarch64.rpm', 'product': {'name': 'libssh2-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64.rpm', 'product': {'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64.rpm', 'product': {'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64.rpm', 'product': {'name': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_id': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403.aarch64.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64.rpm', 'product': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64.rpm', 'product': {'name': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.11.0-6.oe2403.aarch64.rpm', 'product': {'name': 'libssh2-devel-1.11.0-6.oe2403.aarch64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403sp1.aarch64.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64.rpm', 'product': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64.rpm', 'product': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64.rpm', 'product': {'name': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403sp3.aarch64.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64.rpm', 'product': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64.rpm', 'product': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64.rpm', 'product': {'name': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-1.9.0-10.oe2003sp4.aarch64.rpm', 'product': {'name': 'libssh2-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64.rpm', 'product': {'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64.rpm', 'product': {'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64.rpm', 'product': {'name': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_id': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libssh2-1.10.0-8.oe2203sp4.src.rpm', 'product': {'name': 'libssh2-1.10.0-8.oe2203sp4.src.rpm', 'product_id': 'libssh2-1.10.0-8.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403.src.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403.src.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403sp1.src.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403sp1.src.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403sp3.src.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403sp3.src.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-1.9.0-10.oe2003sp4.src.rpm', 'product': {'name': 'libssh2-1.9.0-10.oe2003sp4.src.rpm', 'product_id': 'libssh2-1.9.0-10.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libssh2-1.10.0-8.oe2203sp4.x86_64.rpm', 'product': {'name': 'libssh2-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64.rpm', 'product': {'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64.rpm', 'product': {'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64.rpm', 'product': {'name': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_id': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403.x86_64.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64.rpm', 'product': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64.rpm', 'product': {'name': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.11.0-6.oe2403.x86_64.rpm', 'product': {'name': 'libssh2-devel-1.11.0-6.oe2403.x86_64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403sp1.x86_64.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64.rpm', 'product': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64.rpm', 'product': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64.rpm', 'product': {'name': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-1.11.0-6.oe2403sp3.x86_64.rpm', 'product': {'name': 'libssh2-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64.rpm', 'product': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64.rpm', 'product': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64.rpm', 'product': {'name': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_id': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-1.9.0-10.oe2003sp4.x86_64.rpm', 'product': {'name': 'libssh2-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64.rpm', 'product': {'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64.rpm', 'product': {'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64.rpm', 'product': {'name': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_id': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libssh2-help-1.10.0-8.oe2203sp4.noarch.rpm', 'product': {'name': 'libssh2-help-1.10.0-8.oe2203sp4.noarch.rpm', 'product_id': 'libssh2-help-1.10.0-8.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libssh2-help-1.11.0-6.oe2403.noarch.rpm', 'product': {'name': 'libssh2-help-1.11.0-6.oe2403.noarch.rpm', 'product_id': 'libssh2-help-1.11.0-6.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libssh2-help-1.11.0-6.oe2403sp1.noarch.rpm', 'product': {'name': 'libssh2-help-1.11.0-6.oe2403sp1.noarch.rpm', 'product_id': 'libssh2-help-1.11.0-6.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libssh2-help-1.11.0-6.oe2403sp3.noarch.rpm', 'product': {'name': 'libssh2-help-1.11.0-6.oe2403sp3.noarch.rpm', 'product_id': 'libssh2-help-1.11.0-6.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libssh2-help-1.9.0-10.oe2003sp4.noarch.rpm', 'product': {'name': 'libssh2-help-1.9.0-10.oe2003sp4.noarch.rpm', 'product_id': 'libssh2-help-1.9.0-10.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.10.0-8.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-1.10.0-8.oe2203sp4.aarch64'}, 'product_reference': 'libssh2-1.10.0-8.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64'}, 'product_reference': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64'}, 'product_reference': 'libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-devel-1.10.0-8.oe2203sp4.aarch64'}, 'product_reference': 'libssh2-devel-1.10.0-8.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-1.11.0-6.oe2403.aarch64'}, 'product_reference': 'libssh2-1.11.0-6.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-debuginfo-1.11.0-6.oe2403.aarch64'}, 'product_reference': 'libssh2-debuginfo-1.11.0-6.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-debugsource-1.11.0-6.oe2403.aarch64'}, 'product_reference': 'libssh2-debugsource-1.11.0-6.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.11.0-6.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-devel-1.11.0-6.oe2403.aarch64'}, 'product_reference': 'libssh2-devel-1.11.0-6.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-1.11.0-6.oe2403sp1.aarch64'}, 'product_reference': 'libssh2-1.11.0-6.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64'}, 'product_reference': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64'}, 'product_reference': 'libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-devel-1.11.0-6.oe2403sp1.aarch64'}, 'product_reference': 'libssh2-devel-1.11.0-6.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-1.11.0-6.oe2403sp3.aarch64'}, 'product_reference': 'libssh2-1.11.0-6.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64'}, 'product_reference': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64'}, 'product_reference': 'libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-devel-1.11.0-6.oe2403sp3.aarch64'}, 'product_reference': 'libssh2-devel-1.11.0-6.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.9.0-10.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-1.9.0-10.oe2003sp4.aarch64'}, 'product_reference': 'libssh2-1.9.0-10.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64'}, 'product_reference': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64'}, 'product_reference': 'libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-devel-1.9.0-10.oe2003sp4.aarch64'}, 'product_reference': 'libssh2-devel-1.9.0-10.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.10.0-8.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-1.10.0-8.oe2203sp4.src'}, 'product_reference': 'libssh2-1.10.0-8.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-1.11.0-6.oe2403.src'}, 'product_reference': 'libssh2-1.11.0-6.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-1.11.0-6.oe2403sp1.src'}, 'product_reference': 'libssh2-1.11.0-6.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-1.11.0-6.oe2403sp3.src'}, 'product_reference': 'libssh2-1.11.0-6.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.9.0-10.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-1.9.0-10.oe2003sp4.src'}, 'product_reference': 'libssh2-1.9.0-10.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.10.0-8.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-1.10.0-8.oe2203sp4.x86_64'}, 'product_reference': 'libssh2-1.10.0-8.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64'}, 'product_reference': 'libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64'}, 'product_reference': 'libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-devel-1.10.0-8.oe2203sp4.x86_64'}, 'product_reference': 'libssh2-devel-1.10.0-8.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-1.11.0-6.oe2403.x86_64'}, 'product_reference': 'libssh2-1.11.0-6.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-debuginfo-1.11.0-6.oe2403.x86_64'}, 'product_reference': 'libssh2-debuginfo-1.11.0-6.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-debugsource-1.11.0-6.oe2403.x86_64'}, 'product_reference': 'libssh2-debugsource-1.11.0-6.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.11.0-6.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-devel-1.11.0-6.oe2403.x86_64'}, 'product_reference': 'libssh2-devel-1.11.0-6.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-1.11.0-6.oe2403sp1.x86_64'}, 'product_reference': 'libssh2-1.11.0-6.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64'}, 'product_reference': 'libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64'}, 'product_reference': 'libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-devel-1.11.0-6.oe2403sp1.x86_64'}, 'product_reference': 'libssh2-devel-1.11.0-6.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.11.0-6.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-1.11.0-6.oe2403sp3.x86_64'}, 'product_reference': 'libssh2-1.11.0-6.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64'}, 'product_reference': 'libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64'}, 'product_reference': 'libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-devel-1.11.0-6.oe2403sp3.x86_64'}, 'product_reference': 'libssh2-devel-1.11.0-6.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-1.9.0-10.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-1.9.0-10.oe2003sp4.x86_64'}, 'product_reference': 'libssh2-1.9.0-10.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64'}, 'product_reference': 'libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64'}, 'product_reference': 'libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-devel-1.9.0-10.oe2003sp4.x86_64'}, 'product_reference': 'libssh2-devel-1.9.0-10.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-help-1.10.0-8.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libssh2-help-1.10.0-8.oe2203sp4.noarch'}, 'product_reference': 'libssh2-help-1.10.0-8.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-help-1.11.0-6.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libssh2-help-1.11.0-6.oe2403.noarch'}, 'product_reference': 'libssh2-help-1.11.0-6.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-help-1.11.0-6.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libssh2-help-1.11.0-6.oe2403sp1.noarch'}, 'product_reference': 'libssh2-help-1.11.0-6.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-help-1.11.0-6.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libssh2-help-1.11.0-6.oe2403sp3.noarch'}, 'product_reference': 'libssh2-help-1.11.0-6.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libssh2-help-1.9.0-10.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libssh2-help-1.9.0-10.oe2003sp4.noarch'}, 'product_reference': 'libssh2-help-1.9.0-10.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-7598', 'notes': [{'text': 'A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7598', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2336', 'details': 'libssh2 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:libssh2-1.10.0-8.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libssh2-debuginfo-1.10.0-8.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libssh2-debugsource-1.10.0-8.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libssh2-devel-1.10.0-8.oe2203sp4.aarch64', 'openEuler-24.03-LTS:libssh2-1.11.0-6.oe2403.aarch64', 'openEuler-24.03-LTS:libssh2-debuginfo-1.11.0-6.oe2403.aarch64', 'openEuler-24.03-LTS:libssh2-debugsource-1.11.0-6.oe2403.aarch64', 'openEuler-24.03-LTS:libssh2-devel-1.11.0-6.oe2403.aarch64', 'openEuler-24.03-LTS-SP1:libssh2-1.11.0-6.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libssh2-debuginfo-1.11.0-6.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libssh2-debugsource-1.11.0-6.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libssh2-devel-1.11.0-6.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP3:libssh2-1.11.0-6.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libssh2-debuginfo-1.11.0-6.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libssh2-debugsource-1.11.0-6.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libssh2-devel-1.11.0-6.oe2403sp3.aarch64', 'openEuler-20.03-LTS-SP4:libssh2-1.9.0-10.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:libssh2-debuginfo-1.9.0-10.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:libssh2-debugsource-1.9.0-10.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:libssh2-devel-1.9.0-10.oe2003sp4.aarch64', 'openEuler-22.03-LTS-SP4:libssh2-1.10.0-8.oe2203sp4.src', 'openEuler-24.03-LTS:libssh2-1.11.0-6.oe2403.src', 'openEuler-24.03-LTS-SP1:libssh2-1.11.0-6.oe2403sp1.src', 'openEuler-24.03-LTS-SP3:libssh2-1.11.0-6.oe2403sp3.src', 'openEuler-20.03-LTS-SP4:libssh2-1.9.0-10.oe2003sp4.src', 'openEuler-22.03-LTS-SP4:libssh2-1.10.0-8.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libssh2-debuginfo-1.10.0-8.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libssh2-debugsource-1.10.0-8.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libssh2-devel-1.10.0-8.oe2203sp4.x86_64', 'openEuler-24.03-LTS:libssh2-1.11.0-6.oe2403.x86_64', 'openEuler-24.03-LTS:libssh2-debuginfo-1.11.0-6.oe2403.x86_64', 'openEuler-24.03-LTS:libssh2-debugsource-1.11.0-6.oe2403.x86_64', 'openEuler-24.03-LTS:libssh2-devel-1.11.0-6.oe2403.x86_64', 'openEuler-24.03-LTS-SP1:libssh2-1.11.0-6.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libssh2-debuginfo-1.11.0-6.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libssh2-debugsource-1.11.0-6.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libssh2-devel-1.11.0-6.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP3:libssh2-1.11.0-6.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libssh2-debuginfo-1.11.0-6.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libssh2-debugsource-1.11.0-6.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libssh2-devel-1.11.0-6.oe2403sp3.x86_64', 'openEuler-20.03-LTS-SP4:libssh2-1.9.0-10.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:libssh2-debuginfo-1.9.0-10.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:libssh2-debugsource-1.9.0-10.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:libssh2-devel-1.9.0-10.oe2003sp4.x86_64', 'openEuler-22.03-LTS-SP4:libssh2-help-1.10.0-8.oe2203sp4.noarch', 'openEuler-24.03-LTS:libssh2-help-1.11.0-6.oe2403.noarch', 'openEuler-24.03-LTS-SP1:libssh2-help-1.11.0-6.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP3:libssh2-help-1.11.0-6.oe2403sp3.noarch', 'openEuler-20.03-LTS-SP4:libssh2-help-1.9.0-10.oe2003sp4.noarch']}}]}
e39fead0e40e629d0950651bf6b34d536023a2bc118875ea24c238d3410f7c0e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2337
An update for libsoup3 is now available for openEuler-24.03-LTS
High
2026-05-15 17:04:44+03:00
2026-05-15 17:04:44+03:00
['CVE-2025-12105', 'CVE-2025-14523', 'CVE-2025-46420', 'CVE-2025-4945', 'CVE-2025-4948', 'CVE-2025-4969', 'CVE-2026-0716', 'CVE-2026-1467', 'CVE-2026-1536', 'CVE-2026-1539']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-devel-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-help-3.4.5-13.oe2403.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-13.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-devel-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-3.4.5-13.oe2403.src.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'summary': 'openEuler-SA-2026-2337', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-12105&packageName=libsoup3', 'summary': 'CVE-2025-12105', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14523&packageName=libsoup3', 'summary': 'CVE-2025-14523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-46420&packageName=libsoup3', 'summary': 'CVE-2025-46420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4945&packageName=libsoup3', 'summary': 'CVE-2025-4945', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4948&packageName=libsoup3', 'summary': 'CVE-2025-4948', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4969&packageName=libsoup3', 'summary': 'CVE-2025-4969', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-0716&packageName=libsoup3', 'summary': 'CVE-2026-0716', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1467&packageName=libsoup3', 'summary': 'CVE-2026-1467', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1536&packageName=libsoup3', 'summary': 'CVE-2026-1536', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1539&packageName=libsoup3', 'summary': 'CVE-2026-1539', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-12105', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-46420', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4948', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4969', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-0716', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1467', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1536', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1539', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2337.json', 'summary': 'openEuler-SA-2026-2337 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libsoup3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.\n\nSecurity Fix(es):\n\nA flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.(CVE-2025-12105)\n\nA flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.(CVE-2025-14523)\n\nA flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.(CVE-2025-46420)\n\nA flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.(CVE-2025-4945)\n\nA flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.(CVE-2025-4948)\n\nA vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).(CVE-2025-4969)\n\nA flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.(CVE-2026-0716)\n\nA flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.(CVE-2026-1467)\n\nA flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.(CVE-2026-1536)\n\nA flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.(CVE-2026-1539)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libsoup3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libsoup3 is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2337', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:44+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:44+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:44+08:00', 'initial_release_date': '2026-05-15T22:04:44+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'summary': 'openEuler-SA-2026-2337', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-12105&packageName=libsoup3', 'summary': 'CVE-2025-12105', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14523&packageName=libsoup3', 'summary': 'CVE-2025-14523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-46420&packageName=libsoup3', 'summary': 'CVE-2025-46420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4945&packageName=libsoup3', 'summary': 'CVE-2025-4945', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4948&packageName=libsoup3', 'summary': 'CVE-2025-4948', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4969&packageName=libsoup3', 'summary': 'CVE-2025-4969', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-0716&packageName=libsoup3', 'summary': 'CVE-2026-0716', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1467&packageName=libsoup3', 'summary': 'CVE-2026-1467', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1536&packageName=libsoup3', 'summary': 'CVE-2026-1536', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1539&packageName=libsoup3', 'summary': 'CVE-2026-1539', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-12105', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-46420', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4948', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4969', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-0716', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1467', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1536', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1539', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2337.json', 'summary': 'openEuler-SA-2026-2337 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'libsoup3-3.4.5-13.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-13.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-13.oe2403.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libsoup3-help-3.4.5-13.oe2403.noarch.rpm', 'product': {'name': 'libsoup3-help-3.4.5-13.oe2403.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-13.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'libsoup3-3.4.5-13.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-13.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-13.oe2403.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libsoup3-3.4.5-13.oe2403.src.rpm', 'product': {'name': 'libsoup3-3.4.5-13.oe2403.src.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-13.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-3.4.5-13.oe2403.x86_64'}, 'product_reference': 'libsoup3-3.4.5-13.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-13.oe2403.x86_64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-13.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-13.oe2403.x86_64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-13.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-13.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-13.oe2403.x86_64'}, 'product_reference': 'libsoup3-devel-3.4.5-13.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-help-3.4.5-13.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-help-3.4.5-13.oe2403.noarch'}, 'product_reference': 'libsoup3-help-3.4.5-13.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-13.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-3.4.5-13.oe2403.aarch64'}, 'product_reference': 'libsoup3-3.4.5-13.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-13.oe2403.aarch64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-13.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-13.oe2403.aarch64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-13.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-13.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-13.oe2403.aarch64'}, 'product_reference': 'libsoup3-devel-3.4.5-13.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-13.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-3.4.5-13.oe2403.src'}, 'product_reference': 'libsoup3-3.4.5-13.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-12105', 'notes': [{'text': 'A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-12105', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:libsoup3-3.4.5-13.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-13.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-13.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-13.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-help-3.4.5-13.oe2403.noarch', 'openEuler-24.03-LTS:libsoup3-3.4.5-13.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-13.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-13.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-13.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-3.4.5-13.oe2403.src']}}, {'cve': 'CVE-2025-14523', 'notes': [{'text': 'A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-46420', 'notes': [{'text': 'A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-46420', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4945', 'notes': [{'text': 'A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.7, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4948', 'notes': [{'text': 'A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4948', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4969', 'notes': [{'text': 'A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4969', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-0716', 'notes': [{'text': 'A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-0716', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1467', 'notes': [{'text': 'A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1467', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1536', 'notes': [{'text': 'A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1536', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1539', 'notes': [{'text': 'A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1539', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2337', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
11452087b6a5bcae1231a2ac1a443eefcdcf5494b8503c5a79b825d21033f79b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2338
An update for libsoup3 is now available for openEuler-24.03-LTS-SP1
High
2026-05-15 17:04:47+03:00
2026-05-15 17:04:47+03:00
['CVE-2025-12105', 'CVE-2025-14523', 'CVE-2025-32052', 'CVE-2025-32053', 'CVE-2025-46420', 'CVE-2025-4945', 'CVE-2025-4948', 'CVE-2025-4969', 'CVE-2026-0716', 'CVE-2026-1467', 'CVE-2026-1536', 'CVE-2026-1539']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-3.4.4-17.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-3.4.4-17.oe2403sp1.src.rpm', 'product_id': 'libsoup3-3.4.4-17.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-3.4.4-17.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch.rpm', 'product_id': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'summary': 'openEuler-SA-2026-2338', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-12105&packageName=libsoup3', 'summary': 'CVE-2025-12105', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14523&packageName=libsoup3', 'summary': 'CVE-2025-14523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-32052&packageName=libsoup3', 'summary': 'CVE-2025-32052', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-32053&packageName=libsoup3', 'summary': 'CVE-2025-32053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-46420&packageName=libsoup3', 'summary': 'CVE-2025-46420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4945&packageName=libsoup3', 'summary': 'CVE-2025-4945', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4948&packageName=libsoup3', 'summary': 'CVE-2025-4948', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4969&packageName=libsoup3', 'summary': 'CVE-2025-4969', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-0716&packageName=libsoup3', 'summary': 'CVE-2026-0716', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1467&packageName=libsoup3', 'summary': 'CVE-2026-1467', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1536&packageName=libsoup3', 'summary': 'CVE-2026-1536', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1539&packageName=libsoup3', 'summary': 'CVE-2026-1539', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-12105', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-32052', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-32053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-46420', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4948', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4969', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-0716', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1467', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1536', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1539', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2338.json', 'summary': 'openEuler-SA-2026-2338 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libsoup3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.\n\nSecurity Fix(es):\n\nA flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.(CVE-2025-12105)\n\nA flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.(CVE-2025-14523)\n\nA flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.(CVE-2025-32052)\n\nA flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.(CVE-2025-32053)\n\nA flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.(CVE-2025-46420)\n\nA flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.(CVE-2025-4945)\n\nA flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.(CVE-2025-4948)\n\nA vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).(CVE-2025-4969)\n\nA flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.(CVE-2026-0716)\n\nA flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.(CVE-2026-1467)\n\nA flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.(CVE-2026-1536)\n\nA flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.(CVE-2026-1539)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libsoup3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2338', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:47+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:47+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:47+08:00', 'initial_release_date': '2026-05-15T22:04:47+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'summary': 'openEuler-SA-2026-2338', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-12105&packageName=libsoup3', 'summary': 'CVE-2025-12105', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14523&packageName=libsoup3', 'summary': 'CVE-2025-14523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-32052&packageName=libsoup3', 'summary': 'CVE-2025-32052', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-32053&packageName=libsoup3', 'summary': 'CVE-2025-32053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-46420&packageName=libsoup3', 'summary': 'CVE-2025-46420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4945&packageName=libsoup3', 'summary': 'CVE-2025-4945', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4948&packageName=libsoup3', 'summary': 'CVE-2025-4948', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4969&packageName=libsoup3', 'summary': 'CVE-2025-4969', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-0716&packageName=libsoup3', 'summary': 'CVE-2026-0716', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1467&packageName=libsoup3', 'summary': 'CVE-2026-1467', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1536&packageName=libsoup3', 'summary': 'CVE-2026-1536', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1539&packageName=libsoup3', 'summary': 'CVE-2026-1539', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-12105', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-32052', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-32053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-46420', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4948', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4969', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-0716', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1467', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1536', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1539', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2338.json', 'summary': 'openEuler-SA-2026-2338 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libsoup3-3.4.4-17.oe2403sp1.aarch64.rpm', 'product': {'name': 'libsoup3-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64.rpm', 'product': {'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libsoup3-3.4.4-17.oe2403sp1.src.rpm', 'product': {'name': 'libsoup3-3.4.4-17.oe2403sp1.src.rpm', 'product_id': 'libsoup3-3.4.4-17.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libsoup3-3.4.4-17.oe2403sp1.x86_64.rpm', 'product': {'name': 'libsoup3-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64.rpm', 'product': {'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch.rpm', 'product': {'name': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch.rpm', 'product_id': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.4-17.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-3.4.4-17.oe2403sp1.aarch64'}, 'product_reference': 'libsoup3-3.4.4-17.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64'}, 'product_reference': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64'}, 'product_reference': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-devel-3.4.4-17.oe2403sp1.aarch64'}, 'product_reference': 'libsoup3-devel-3.4.4-17.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.4-17.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-3.4.4-17.oe2403sp1.src'}, 'product_reference': 'libsoup3-3.4.4-17.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.4-17.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-3.4.4-17.oe2403sp1.x86_64'}, 'product_reference': 'libsoup3-3.4.4-17.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64'}, 'product_reference': 'libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64'}, 'product_reference': 'libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-devel-3.4.4-17.oe2403sp1.x86_64'}, 'product_reference': 'libsoup3-devel-3.4.4-17.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libsoup3-help-3.4.4-17.oe2403sp1.noarch'}, 'product_reference': 'libsoup3-help-3.4.4-17.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-12105', 'notes': [{'text': 'A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-12105', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:libsoup3-3.4.4-17.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libsoup3-debuginfo-3.4.4-17.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libsoup3-debugsource-3.4.4-17.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libsoup3-devel-3.4.4-17.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libsoup3-3.4.4-17.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:libsoup3-3.4.4-17.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libsoup3-debuginfo-3.4.4-17.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libsoup3-debugsource-3.4.4-17.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libsoup3-devel-3.4.4-17.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libsoup3-help-3.4.4-17.oe2403sp1.noarch']}}, {'cve': 'CVE-2025-14523', 'notes': [{'text': 'A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-32052', 'notes': [{'text': 'A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-32052', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-32053', 'notes': [{'text': 'A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-32053', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-46420', 'notes': [{'text': 'A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-46420', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4945', 'notes': [{'text': 'A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.7, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4948', 'notes': [{'text': 'A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4948', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4969', 'notes': [{'text': 'A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4969', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-0716', 'notes': [{'text': 'A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-0716', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1467', 'notes': [{'text': 'A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1467', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1536', 'notes': [{'text': 'A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1536', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1539', 'notes': [{'text': 'A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1539', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2338', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
d8255f00019926ea9fd6c60f9466a78b3d43a22862827cbdf350be1a883cca7c
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2339
An update for libsoup3 is now available for openEuler-24.03-LTS-SP3
High
2026-05-15 17:04:55+03:00
2026-05-15 17:04:55+03:00
['CVE-2025-12105', 'CVE-2025-14523', 'CVE-2025-46420', 'CVE-2025-4945', 'CVE-2025-4948', 'CVE-2025-4969', 'CVE-2026-0716', 'CVE-2026-1467', 'CVE-2026-1536', 'CVE-2026-1539']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-3.4.5-13.oe2403sp3.src.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'summary': 'openEuler-SA-2026-2339', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-12105&packageName=libsoup3', 'summary': 'CVE-2025-12105', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14523&packageName=libsoup3', 'summary': 'CVE-2025-14523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-46420&packageName=libsoup3', 'summary': 'CVE-2025-46420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4945&packageName=libsoup3', 'summary': 'CVE-2025-4945', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4948&packageName=libsoup3', 'summary': 'CVE-2025-4948', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4969&packageName=libsoup3', 'summary': 'CVE-2025-4969', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-0716&packageName=libsoup3', 'summary': 'CVE-2026-0716', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1467&packageName=libsoup3', 'summary': 'CVE-2026-1467', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1536&packageName=libsoup3', 'summary': 'CVE-2026-1536', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1539&packageName=libsoup3', 'summary': 'CVE-2026-1539', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-12105', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-46420', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4948', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4969', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-0716', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1467', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1536', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1539', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2339.json', 'summary': 'openEuler-SA-2026-2339 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libsoup3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.\n\nSecurity Fix(es):\n\nA flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.(CVE-2025-12105)\n\nA flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.(CVE-2025-14523)\n\nA flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.(CVE-2025-46420)\n\nA flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.(CVE-2025-4945)\n\nA flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.(CVE-2025-4948)\n\nA vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).(CVE-2025-4969)\n\nA flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.(CVE-2026-0716)\n\nA flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.(CVE-2026-1467)\n\nA flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.(CVE-2026-1536)\n\nA flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.(CVE-2026-1539)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libsoup3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2339', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:55+08:00', 'initial_release_date': '2026-05-15T22:04:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'summary': 'openEuler-SA-2026-2339', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-12105&packageName=libsoup3', 'summary': 'CVE-2025-12105', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14523&packageName=libsoup3', 'summary': 'CVE-2025-14523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-46420&packageName=libsoup3', 'summary': 'CVE-2025-46420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4945&packageName=libsoup3', 'summary': 'CVE-2025-4945', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4948&packageName=libsoup3', 'summary': 'CVE-2025-4948', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-4969&packageName=libsoup3', 'summary': 'CVE-2025-4969', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-0716&packageName=libsoup3', 'summary': 'CVE-2026-0716', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1467&packageName=libsoup3', 'summary': 'CVE-2026-1467', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1536&packageName=libsoup3', 'summary': 'CVE-2026-1536', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-1539&packageName=libsoup3', 'summary': 'CVE-2026-1539', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-12105', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-46420', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4948', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-4969', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-0716', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1467', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1536', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-1539', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2339.json', 'summary': 'openEuler-SA-2026-2339 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libsoup3-3.4.5-13.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libsoup3-3.4.5-13.oe2403sp3.src.rpm', 'product': {'name': 'libsoup3-3.4.5-13.oe2403sp3.src.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libsoup3-3.4.5-13.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch.rpm', 'product': {'name': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-13.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-13.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-3.4.5-13.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-13.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-devel-3.4.5-13.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-13.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-13.oe2403sp3.src'}, 'product_reference': 'libsoup3-3.4.5-13.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-13.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-13.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-3.4.5-13.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-13.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-devel-3.4.5-13.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-help-3.4.5-13.oe2403sp3.noarch'}, 'product_reference': 'libsoup3-help-3.4.5-13.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-12105', 'notes': [{'text': 'A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-12105', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:libsoup3-3.4.5-13.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-13.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-13.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-13.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-13.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-13.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-13.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-13.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-13.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-help-3.4.5-13.oe2403sp3.noarch']}}, {'cve': 'CVE-2025-14523', 'notes': [{'text': 'A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-46420', 'notes': [{'text': 'A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-46420', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4945', 'notes': [{'text': 'A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.7, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4948', 'notes': [{'text': 'A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4948', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-4969', 'notes': [{'text': 'A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-4969', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-0716', 'notes': [{'text': 'A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-0716', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1467', 'notes': [{'text': 'A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1467', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1536', 'notes': [{'text': 'A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1536', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-1539', 'notes': [{'text': 'A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-1539', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2339', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
6ea606eae809119724fdcaadf967bbb1409ee2d7f191d8113d18285e5bba5414
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2340
An update for php is now available for openEuler-20.03-LTS-SP4
Medium
2026-05-15 17:04:55+03:00
2026-05-15 17:04:55+03:00
['CVE-2026-6722', 'CVE-2026-7259', 'CVE-2026-7262', 'CVE-2026-7568']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-help-8.0.30-12.oe2003sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-12.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-cli-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-common-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dba-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dbg-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-devel-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-embedded-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-enchant-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ffi-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-fpm-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-intl-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ldap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-odbc-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-opcache-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pdo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-process-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-snmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-soap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-sodium-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-tidy-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-xml-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-8.0.30-12.oe2003sp4.src.rpm', 'product_id': 'php-8.0.30-12.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-cli-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-common-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dba-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dbg-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-devel-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-embedded-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-enchant-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ffi-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-fpm-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-intl-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ldap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-odbc-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-opcache-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pdo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-process-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-snmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-soap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-sodium-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-tidy-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-xml-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2003sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2340', 'summary': 'openEuler-SA-2026-2340', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2340.json', 'summary': 'openEuler-SA-2026-2340 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.(CVE-2026-6722)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().(CVE-2026-7259)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.(CVE-2026-7262)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.(CVE-2026-7568)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2340', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:55+08:00', 'initial_release_date': '2026-05-15T22:04:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2340', 'summary': 'openEuler-SA-2026-2340', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2340.json', 'summary': 'openEuler-SA-2026-2340 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.0.30-12.oe2003sp4.noarch.rpm', 'product': {'name': 'php-help-8.0.30-12.oe2003sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-12.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-cli-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-common-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-dba-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-dbg-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-devel-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-embedded-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-enchant-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-ffi-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-fpm-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-gd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-gmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-intl-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-ldap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-odbc-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-opcache-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-pdo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-process-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-snmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-soap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-sodium-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-tidy-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-12.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-xml-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.0.30-12.oe2003sp4.src.rpm', 'product': {'name': 'php-8.0.30-12.oe2003sp4.src.rpm', 'product_id': 'php-8.0.30-12.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-cli-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-common-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-dba-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-dbg-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-devel-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-embedded-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-enchant-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-ffi-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-fpm-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-gd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-gmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-intl-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-ldap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-odbc-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-opcache-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-pdo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-process-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-snmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-soap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-sodium-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-tidy-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-12.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-xml-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.0.30-12.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-help-8.0.30-12.oe2003sp4.noarch'}, 'product_reference': 'php-help-8.0.30-12.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-bcmath-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-cli-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-common-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-common-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-dba-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-dbg-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-debuginfo-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-debugsource-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-devel-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-embedded-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-enchant-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-ffi-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-fpm-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-gd-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-gmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-intl-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-ldap-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-mbstring-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-mysqlnd-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-odbc-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-opcache-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-pdo-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-pgsql-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-process-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-process-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-snmp-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-soap-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-sodium-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-tidy-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-12.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-12.oe2003sp4.aarch64'}, 'product_reference': 'php-xml-8.0.30-12.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-12.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-8.0.30-12.oe2003sp4.src'}, 'product_reference': 'php-8.0.30-12.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-bcmath-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-cli-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-common-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-common-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-dba-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-dbg-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-debuginfo-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-debugsource-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-devel-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-embedded-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-enchant-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-ffi-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-fpm-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-gd-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-gmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-intl-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-ldap-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-mbstring-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-mysqlnd-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-odbc-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-opcache-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-pdo-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-pgsql-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-process-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-process-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-snmp-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-soap-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-sodium-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-tidy-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-12.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-12.oe2003sp4.x86_64'}, 'product_reference': 'php-xml-8.0.30-12.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-6722', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6722', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2340', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:php-help-8.0.30-12.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:php-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-common-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-process-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-12.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-8.0.30-12.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:php-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-common-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-process-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-12.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-12.oe2003sp4.x86_64']}}, {'cve': 'CVE-2026-7259', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7259', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2340', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7262', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7262', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2340', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7568', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7568', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2340', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
c1b926f93c8190e7c07e4377576284b3855b1e1f3c4038b63f7d82b9f1d81814
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2341
An update for php is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-15 17:04:55+03:00
2026-05-15 17:04:55+03:00
['CVE-2026-6722', 'CVE-2026-7259', 'CVE-2026-7262', 'CVE-2026-7568']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-cli-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-common-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dba-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dbg-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-devel-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-embedded-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-enchant-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ffi-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-fpm-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-intl-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ldap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-odbc-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-opcache-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pdo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-process-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-snmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-soap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-sodium-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-tidy-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-xml-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-8.0.30-12.oe2203sp4.src.rpm', 'product_id': 'php-8.0.30-12.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-cli-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-common-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dba-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dbg-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-devel-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-embedded-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-enchant-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ffi-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-fpm-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-intl-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ldap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-odbc-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-opcache-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pdo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-process-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-snmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-soap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-sodium-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-tidy-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-xml-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-help-8.0.30-12.oe2203sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-12.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2341', 'summary': 'openEuler-SA-2026-2341', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2341.json', 'summary': 'openEuler-SA-2026-2341 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.(CVE-2026-6722)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().(CVE-2026-7259)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.(CVE-2026-7262)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.(CVE-2026-7568)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2341', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:04:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:04:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:04:55+08:00', 'initial_release_date': '2026-05-15T22:04:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2341', 'summary': 'openEuler-SA-2026-2341', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2341.json', 'summary': 'openEuler-SA-2026-2341 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-cli-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-common-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-dba-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-dbg-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-devel-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-embedded-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-enchant-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-ffi-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-fpm-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-gd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-gmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-intl-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-ldap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-odbc-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-opcache-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-pdo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-process-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-snmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-soap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-sodium-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-tidy-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-12.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-xml-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.0.30-12.oe2203sp4.src.rpm', 'product': {'name': 'php-8.0.30-12.oe2203sp4.src.rpm', 'product_id': 'php-8.0.30-12.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-cli-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-common-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-dba-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-dbg-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-devel-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-embedded-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-enchant-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-ffi-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-fpm-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-gd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-gmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-intl-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-ldap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-odbc-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-opcache-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-pdo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-process-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-snmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-soap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-sodium-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-tidy-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-12.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-xml-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-12.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.0.30-12.oe2203sp4.noarch.rpm', 'product': {'name': 'php-help-8.0.30-12.oe2203sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-12.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-bcmath-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-cli-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-common-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-common-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-dba-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-dbg-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-debuginfo-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-debugsource-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-devel-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-embedded-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-enchant-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-ffi-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-fpm-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-gd-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-gmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-intl-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-ldap-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-mbstring-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-mysqlnd-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-odbc-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-opcache-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-pdo-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-pgsql-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-process-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-process-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-snmp-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-soap-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-sodium-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-tidy-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-12.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-12.oe2203sp4.aarch64'}, 'product_reference': 'php-xml-8.0.30-12.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-12.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-8.0.30-12.oe2203sp4.src'}, 'product_reference': 'php-8.0.30-12.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-bcmath-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-cli-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-common-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-common-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-dba-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-dbg-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-debuginfo-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-debugsource-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-devel-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-embedded-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-enchant-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-ffi-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-fpm-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-gd-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-gmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-intl-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-ldap-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-mbstring-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-mysqlnd-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-odbc-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-opcache-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-pdo-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-pgsql-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-process-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-process-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-snmp-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-soap-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-sodium-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-tidy-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-12.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-12.oe2203sp4.x86_64'}, 'product_reference': 'php-xml-8.0.30-12.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.0.30-12.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-help-8.0.30-12.oe2203sp4.noarch'}, 'product_reference': 'php-help-8.0.30-12.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-6722', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6722', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2341', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:php-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-common-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-process-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-12.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-8.0.30-12.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:php-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-common-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-process-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-12.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-help-8.0.30-12.oe2203sp4.noarch']}}, {'cve': 'CVE-2026-7259', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7259', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2341', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7262', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7262', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2341', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7568', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7568', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2341', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
514537d99c0848f9ffe97908ae3cf1820a755f3c9f434591e2753fb5fca7c73e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2342
An update for php is now available for openEuler-24.03-LTS
Critical
2026-05-15 17:05:11+03:00
2026-05-15 17:05:11+03:00
['CVE-2025-14179', 'CVE-2026-6722', 'CVE-2026-6735', 'CVE-2026-7258', 'CVE-2026-7259', 'CVE-2026-7261', 'CVE-2026-7262', 'CVE-2026-7568']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-bcmath-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-cli-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-common-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-dba-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-dbg-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-debuginfo-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-debugsource-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-devel-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-embedded-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-enchant-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-ffi-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-fpm-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-gd-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-gmp-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-intl-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-ldap-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-mbstring-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-mysqlnd-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-odbc-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-opcache-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-pdo-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-pgsql-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-process-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-snmp-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-soap-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-sodium-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-tidy-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-xml-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-8.3.31-1.oe2403.src.rpm', 'product_id': 'php-8.3.31-1.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-bcmath-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-cli-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-common-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-dba-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-dbg-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-debuginfo-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-debugsource-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-devel-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-embedded-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-enchant-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-ffi-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-fpm-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-gd-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-gmp-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-intl-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-ldap-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-mbstring-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-mysqlnd-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-odbc-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-opcache-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-pdo-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-pgsql-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-process-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-snmp-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-soap-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-sodium-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-tidy-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-xml-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'php-help-8.3.31-1.oe2403.noarch.rpm', 'product_id': 'php-help-8.3.31-1.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'summary': 'openEuler-SA-2026-2342', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2342.json', 'summary': 'openEuler-SA-2026-2342 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.(CVE-2025-14179)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.(CVE-2026-6722)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.(CVE-2026-6735)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.(CVE-2026-7258)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().(CVE-2026-7259)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.(CVE-2026-7261)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.(CVE-2026-7262)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.(CVE-2026-7568)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2342', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:11+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:11+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:11+08:00', 'initial_release_date': '2026-05-15T22:05:11+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'summary': 'openEuler-SA-2026-2342', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2342.json', 'summary': 'openEuler-SA-2026-2342 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-bcmath-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-cli-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-cli-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-common-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-common-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-dba-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-dba-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-dbg-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-debugsource-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-devel-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-devel-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-embedded-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-enchant-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-ffi-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-fpm-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-gd-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-gd-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-gmp-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-intl-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-intl-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-ldap-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-mbstring-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-odbc-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-opcache-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-pdo-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-pgsql-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-process-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-process-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-snmp-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-soap-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-soap-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-sodium-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-tidy-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-xml-8.3.31-1.oe2403.aarch64.rpm', 'product': {'name': 'php-xml-8.3.31-1.oe2403.aarch64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.3.31-1.oe2403.src.rpm', 'product': {'name': 'php-8.3.31-1.oe2403.src.rpm', 'product_id': 'php-8.3.31-1.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-bcmath-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-cli-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-cli-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-common-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-common-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-dba-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-dba-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-dbg-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-debugsource-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-devel-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-devel-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-embedded-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-enchant-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-ffi-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-fpm-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-gd-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-gd-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-gmp-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-intl-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-intl-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-ldap-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-mbstring-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-odbc-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-opcache-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-pdo-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-pgsql-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-process-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-process-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-snmp-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-soap-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-soap-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-sodium-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-tidy-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'php-xml-8.3.31-1.oe2403.x86_64.rpm', 'product': {'name': 'php-xml-8.3.31-1.oe2403.x86_64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.3.31-1.oe2403.noarch.rpm', 'product': {'name': 'php-help-8.3.31-1.oe2403.noarch.rpm', 'product_id': 'php-help-8.3.31-1.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-bcmath-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-bcmath-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-cli-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-cli-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-common-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-common-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-dba-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-dba-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-dbg-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-dbg-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-debuginfo-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-debuginfo-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-debugsource-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-debugsource-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-devel-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-devel-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-embedded-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-embedded-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-enchant-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-enchant-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-ffi-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-ffi-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-fpm-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-fpm-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-gd-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-gd-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-gmp-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-gmp-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-intl-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-intl-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-ldap-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-ldap-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-mbstring-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-mbstring-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-mysqlnd-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-mysqlnd-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-odbc-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-odbc-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-opcache-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-opcache-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-pdo-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-pdo-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-pgsql-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-pgsql-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-process-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-process-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-snmp-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-snmp-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-soap-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-soap-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-sodium-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-sodium-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-tidy-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-tidy-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.3.31-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-xml-8.3.31-1.oe2403.aarch64'}, 'product_reference': 'php-xml-8.3.31-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-8.3.31-1.oe2403.src'}, 'product_reference': 'php-8.3.31-1.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-bcmath-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-bcmath-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-cli-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-cli-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-common-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-common-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-dba-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-dba-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-dbg-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-dbg-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-debuginfo-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-debuginfo-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-debugsource-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-debugsource-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-devel-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-devel-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-embedded-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-embedded-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-enchant-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-enchant-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-ffi-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-ffi-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-fpm-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-fpm-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-gd-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-gd-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-gmp-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-gmp-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-intl-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-intl-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-ldap-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-ldap-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-mbstring-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-mbstring-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-mysqlnd-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-mysqlnd-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-odbc-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-odbc-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-opcache-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-opcache-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-pdo-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-pdo-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-pgsql-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-pgsql-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-process-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-process-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-snmp-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-snmp-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-soap-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-soap-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-sodium-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-sodium-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-tidy-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-tidy-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.3.31-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-xml-8.3.31-1.oe2403.x86_64'}, 'product_reference': 'php-xml-8.3.31-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.3.31-1.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:php-help-8.3.31-1.oe2403.noarch'}, 'product_reference': 'php-help-8.3.31-1.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14179', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14179', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:php-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-bcmath-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-cli-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-common-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-dba-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-dbg-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-debuginfo-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-debugsource-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-devel-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-embedded-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-enchant-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-ffi-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-fpm-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-gd-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-gmp-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-intl-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-ldap-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-mbstring-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-mysqlnd-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-odbc-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-opcache-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-pdo-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-pgsql-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-process-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-snmp-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-soap-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-sodium-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-tidy-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-xml-8.3.31-1.oe2403.aarch64', 'openEuler-24.03-LTS:php-8.3.31-1.oe2403.src', 'openEuler-24.03-LTS:php-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-bcmath-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-cli-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-common-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-dba-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-dbg-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-debuginfo-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-debugsource-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-devel-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-embedded-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-enchant-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-ffi-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-fpm-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-gd-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-gmp-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-intl-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-ldap-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-mbstring-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-mysqlnd-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-odbc-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-opcache-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-pdo-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-pgsql-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-process-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-snmp-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-soap-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-sodium-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-tidy-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-xml-8.3.31-1.oe2403.x86_64', 'openEuler-24.03-LTS:php-help-8.3.31-1.oe2403.noarch']}}, {'cve': 'CVE-2026-6722', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6722', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6735', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6735', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7258', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7258', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7259', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7259', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7261', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7262', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7262', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7568', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7568', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2342', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
29a7de53f55e1b7e32764590e99f000c060a2b0b1cd110e4dca4dc4a64a4e1ef
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2343
An update for php is now available for openEuler-24.03-LTS-SP1
Critical
2026-05-15 17:05:11+03:00
2026-05-15 17:05:11+03:00
['CVE-2025-14179', 'CVE-2026-6722', 'CVE-2026-6735', 'CVE-2026-7258', 'CVE-2026-7259', 'CVE-2026-7261', 'CVE-2026-7262', 'CVE-2026-7568']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-help-8.3.31-1.oe2403sp1.noarch.rpm', 'product_id': 'php-help-8.3.31-1.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-cli-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-common-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-dba-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-dbg-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-devel-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-embedded-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-enchant-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-ffi-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-fpm-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-gd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-gmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-intl-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-ldap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-odbc-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-opcache-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-pdo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-process-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-snmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-soap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-sodium-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-tidy-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-xml-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-8.3.31-1.oe2403sp1.src.rpm', 'product_id': 'php-8.3.31-1.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-cli-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-common-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-dba-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-dbg-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-devel-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-embedded-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-enchant-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-ffi-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-fpm-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-gd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-gmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-intl-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-ldap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-odbc-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-opcache-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-pdo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-process-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-snmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-soap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-sodium-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-tidy-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'php-xml-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp1.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'summary': 'openEuler-SA-2026-2343', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2343.json', 'summary': 'openEuler-SA-2026-2343 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.(CVE-2025-14179)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.(CVE-2026-6722)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.(CVE-2026-6735)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.(CVE-2026-7258)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().(CVE-2026-7259)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.(CVE-2026-7261)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.(CVE-2026-7262)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.(CVE-2026-7568)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2343', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:11+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:11+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:11+08:00', 'initial_release_date': '2026-05-15T22:05:11+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'summary': 'openEuler-SA-2026-2343', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2343.json', 'summary': 'openEuler-SA-2026-2343 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.3.31-1.oe2403sp1.noarch.rpm', 'product': {'name': 'php-help-8.3.31-1.oe2403sp1.noarch.rpm', 'product_id': 'php-help-8.3.31-1.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-cli-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-cli-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-common-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-common-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-dba-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-dba-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-dbg-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-devel-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-devel-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-embedded-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-enchant-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-ffi-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-fpm-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-gd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-gd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-gmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-intl-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-intl-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-ldap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-odbc-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-opcache-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-pdo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-process-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-process-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-snmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-soap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-soap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-sodium-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-tidy-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-xml-8.3.31-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'php-xml-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.3.31-1.oe2403sp1.src.rpm', 'product': {'name': 'php-8.3.31-1.oe2403sp1.src.rpm', 'product_id': 'php-8.3.31-1.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-cli-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-cli-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-common-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-common-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-dba-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-dba-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-dbg-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-devel-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-devel-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-embedded-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-enchant-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-ffi-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-fpm-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-gd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-gd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-gmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-intl-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-intl-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-ldap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-odbc-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-opcache-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-pdo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-process-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-process-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-snmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-soap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-soap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-sodium-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-tidy-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'php-xml-8.3.31-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'php-xml-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.3.31-1.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-help-8.3.31-1.oe2403sp1.noarch'}, 'product_reference': 'php-help-8.3.31-1.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-bcmath-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-bcmath-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-cli-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-cli-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-common-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-common-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-dba-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-dba-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-dbg-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-dbg-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-debuginfo-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-debuginfo-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-debugsource-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-debugsource-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-devel-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-devel-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-embedded-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-embedded-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-enchant-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-enchant-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-ffi-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-ffi-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-fpm-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-fpm-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-gd-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-gd-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-gmp-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-gmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-intl-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-intl-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-ldap-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-ldap-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-mbstring-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-mbstring-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-mysqlnd-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-mysqlnd-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-odbc-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-odbc-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-opcache-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-opcache-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-pdo-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-pdo-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-pgsql-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-pgsql-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-process-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-process-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-snmp-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-snmp-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-soap-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-soap-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-sodium-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-sodium-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-tidy-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-tidy-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.3.31-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-xml-8.3.31-1.oe2403sp1.aarch64'}, 'product_reference': 'php-xml-8.3.31-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-8.3.31-1.oe2403sp1.src'}, 'product_reference': 'php-8.3.31-1.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-bcmath-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-bcmath-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-cli-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-cli-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-common-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-common-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-dba-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-dba-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-dbg-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-dbg-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-debuginfo-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-debuginfo-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-debugsource-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-debugsource-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-devel-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-devel-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-embedded-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-embedded-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-enchant-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-enchant-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-ffi-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-ffi-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-fpm-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-fpm-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-gd-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-gd-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-gmp-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-gmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-intl-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-intl-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-ldap-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-ldap-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-mbstring-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-mbstring-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-mysqlnd-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-mysqlnd-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-odbc-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-odbc-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-opcache-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-opcache-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-pdo-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-pdo-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-pgsql-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-pgsql-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-process-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-process-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-snmp-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-snmp-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-soap-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-soap-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-sodium-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-sodium-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-tidy-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-tidy-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.3.31-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:php-xml-8.3.31-1.oe2403sp1.x86_64'}, 'product_reference': 'php-xml-8.3.31-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14179', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14179', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:php-help-8.3.31-1.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP1:php-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-bcmath-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-cli-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-common-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-dba-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-dbg-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-debuginfo-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-debugsource-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-devel-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-embedded-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-enchant-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-ffi-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-fpm-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-gd-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-gmp-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-intl-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-ldap-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-mbstring-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-mysqlnd-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-odbc-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-opcache-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-pdo-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-pgsql-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-process-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-snmp-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-soap-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-sodium-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-tidy-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-xml-8.3.31-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:php-8.3.31-1.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:php-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-bcmath-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-cli-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-common-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-dba-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-dbg-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-debuginfo-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-debugsource-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-devel-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-embedded-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-enchant-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-ffi-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-fpm-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-gd-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-gmp-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-intl-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-ldap-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-mbstring-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-mysqlnd-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-odbc-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-opcache-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-pdo-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-pgsql-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-process-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-snmp-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-soap-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-sodium-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-tidy-8.3.31-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:php-xml-8.3.31-1.oe2403sp1.x86_64']}}, {'cve': 'CVE-2026-6722', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6722', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6735', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6735', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7258', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7258', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7259', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7259', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7261', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7262', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7262', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7568', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7568', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2343', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
ba3f5b0dfc16cf4791447d6ac2bee8184a2015f50efb93b95e009585c00a02c0
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2344
An update for php is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-15 17:05:18+03:00
2026-05-15 17:05:18+03:00
['CVE-2025-14179', 'CVE-2026-6722', 'CVE-2026-6735', 'CVE-2026-7258', 'CVE-2026-7259', 'CVE-2026-7261', 'CVE-2026-7262', 'CVE-2026-7568']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-cli-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-common-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-dba-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-dbg-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-devel-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-embedded-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-enchant-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-ffi-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-fpm-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-gd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-gmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-intl-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-ldap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-odbc-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-opcache-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-pdo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-process-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-snmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-soap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-sodium-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-tidy-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-xml-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-help-8.3.31-1.oe2403sp3.noarch.rpm', 'product_id': 'php-help-8.3.31-1.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-cli-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-common-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-dba-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-dbg-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-devel-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-embedded-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-enchant-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-ffi-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-fpm-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-gd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-gmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-intl-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-ldap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-odbc-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-opcache-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-pdo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-process-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-snmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-soap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-sodium-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-tidy-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-xml-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'php-8.3.31-1.oe2403sp3.src.rpm', 'product_id': 'php-8.3.31-1.oe2403sp3.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'summary': 'openEuler-SA-2026-2344', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2344.json', 'summary': 'openEuler-SA-2026-2344 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.(CVE-2025-14179)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.(CVE-2026-6722)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.(CVE-2026-6735)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.(CVE-2026-7258)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().(CVE-2026-7259)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.(CVE-2026-7261)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.(CVE-2026-7262)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.(CVE-2026-7568)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2344', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:18+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:18+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:18+08:00', 'initial_release_date': '2026-05-15T22:05:18+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'summary': 'openEuler-SA-2026-2344', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6722&packageName=php', 'summary': 'CVE-2026-6722', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7259&packageName=php', 'summary': 'CVE-2026-7259', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7262&packageName=php', 'summary': 'CVE-2026-7262', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7568&packageName=php', 'summary': 'CVE-2026-7568', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6722', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7259', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7262', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7568', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2344.json', 'summary': 'openEuler-SA-2026-2344 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-cli-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-cli-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-common-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-common-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-dba-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-dba-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-dbg-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-devel-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-devel-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-embedded-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-enchant-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-ffi-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-fpm-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-gd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-gd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-gmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-intl-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-intl-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-ldap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-odbc-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-opcache-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-pdo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-process-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-process-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-snmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-soap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-soap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-sodium-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-tidy-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-xml-8.3.31-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'php-xml-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.3.31-1.oe2403sp3.noarch.rpm', 'product': {'name': 'php-help-8.3.31-1.oe2403sp3.noarch.rpm', 'product_id': 'php-help-8.3.31-1.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-cli-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-cli-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-cli-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-common-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-common-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-common-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-dba-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-dba-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-dba-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-dbg-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-dbg-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-devel-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-devel-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-devel-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-embedded-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-embedded-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-enchant-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-enchant-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-ffi-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-ffi-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-fpm-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-fpm-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-gd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-gd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-gd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-gmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-gmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-intl-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-intl-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-intl-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-ldap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-ldap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-odbc-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-odbc-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-opcache-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-opcache-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-pdo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-pdo-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-process-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-process-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-process-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-snmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-snmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-soap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-soap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-soap-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-sodium-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-sodium-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-tidy-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-tidy-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'php-xml-8.3.31-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'php-xml-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_id': 'php-xml-8.3.31-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.3.31-1.oe2403sp3.src.rpm', 'product': {'name': 'php-8.3.31-1.oe2403sp3.src.rpm', 'product_id': 'php-8.3.31-1.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-bcmath-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-bcmath-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-cli-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-cli-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-common-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-common-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-dba-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-dba-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-dbg-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-dbg-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-debuginfo-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-debuginfo-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-debugsource-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-debugsource-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-devel-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-devel-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-embedded-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-embedded-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-enchant-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-enchant-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-ffi-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-ffi-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-fpm-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-fpm-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-gd-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-gd-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-gmp-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-gmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-intl-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-intl-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-ldap-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-ldap-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-mbstring-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-mbstring-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-mysqlnd-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-mysqlnd-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-odbc-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-odbc-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-opcache-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-opcache-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-pdo-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-pdo-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-pgsql-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-pgsql-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-process-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-process-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-snmp-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-snmp-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-soap-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-soap-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-sodium-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-sodium-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-tidy-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-tidy-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.3.31-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-xml-8.3.31-1.oe2403sp3.x86_64'}, 'product_reference': 'php-xml-8.3.31-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.3.31-1.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-help-8.3.31-1.oe2403sp3.noarch'}, 'product_reference': 'php-help-8.3.31-1.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-bcmath-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-bcmath-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-cli-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-cli-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-common-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-common-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-dba-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-dba-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-dbg-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-dbg-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-debuginfo-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-debuginfo-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-debugsource-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-debugsource-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-devel-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-devel-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-embedded-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-embedded-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-enchant-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-enchant-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-ffi-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-ffi-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-fpm-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-fpm-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-gd-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-gd-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-gmp-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-gmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-intl-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-intl-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-ldap-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-ldap-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-mbstring-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-mbstring-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-mysqlnd-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-mysqlnd-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-odbc-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-odbc-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-opcache-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-opcache-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-pdo-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-pdo-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-pgsql-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-pgsql-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-process-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-process-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-snmp-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-snmp-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-soap-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-soap-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-sodium-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-sodium-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-tidy-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-tidy-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.3.31-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-xml-8.3.31-1.oe2403sp3.aarch64'}, 'product_reference': 'php-xml-8.3.31-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.3.31-1.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:php-8.3.31-1.oe2403sp3.src'}, 'product_reference': 'php-8.3.31-1.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14179', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14179', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:php-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-bcmath-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-cli-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-common-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-dba-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-dbg-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-debuginfo-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-debugsource-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-devel-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-embedded-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-enchant-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-ffi-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-fpm-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-gd-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-gmp-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-intl-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-ldap-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-mbstring-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-mysqlnd-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-odbc-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-opcache-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-pdo-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-pgsql-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-process-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-snmp-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-soap-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-sodium-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-tidy-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-xml-8.3.31-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:php-help-8.3.31-1.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:php-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-bcmath-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-cli-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-common-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-dba-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-dbg-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-debuginfo-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-debugsource-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-devel-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-embedded-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-enchant-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-ffi-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-fpm-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-gd-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-gmp-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-intl-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-ldap-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-mbstring-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-mysqlnd-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-odbc-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-opcache-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-pdo-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-pgsql-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-process-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-snmp-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-soap-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-sodium-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-tidy-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-xml-8.3.31-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:php-8.3.31-1.oe2403sp3.src']}}, {'cve': 'CVE-2026-6722', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map\xa0without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6722', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6735', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6735', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7258', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7258', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7259', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to\xa0\xa0a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to\xa0mb_regex_encoding().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7259', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7261', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7262', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.\xa0 This leads to\xa0dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7262', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7568', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7568', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2344', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
432cb5bfb9b93bd9b67e11870a84fb503a84fd2fc49b2d475f3db38b6b36f67f
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2345
An update for libgcrypt is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-15 17:05:20+03:00
2026-05-15 17:05:20+03:00
['CVE-2026-41989']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-1.10.2-4.oe2403sp3.src.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2345', 'summary': 'openEuler-SA-2026-2345', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2345.json', 'summary': 'openEuler-SA-2026-2345 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libgcrypt security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Libgcrypt is a general purpose cryptographic library originally based on code from GnuPG.\n\nSecurity Fix(es):\n\nLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.(CVE-2026-41989)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'libgcrypt', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libgcrypt is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2345', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:20+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:20+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:20+08:00', 'initial_release_date': '2026-05-15T22:05:20+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2345', 'summary': 'openEuler-SA-2026-2345', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2345.json', 'summary': 'openEuler-SA-2026-2345 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libgcrypt-1.10.2-4.oe2403sp3.src.rpm', 'product': {'name': 'libgcrypt-1.10.2-4.oe2403sp3.src.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch.rpm', 'product': {'name': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-1.10.2-4.oe2403sp3.aarch64'}, 'product_reference': 'libgcrypt-1.10.2-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64'}, 'product_reference': 'libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-4.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-1.10.2-4.oe2403sp3.src'}, 'product_reference': 'libgcrypt-1.10.2-4.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-1.10.2-4.oe2403sp3.x86_64'}, 'product_reference': 'libgcrypt-1.10.2-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64'}, 'product_reference': 'libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libgcrypt-help-1.10.2-4.oe2403sp3.noarch'}, 'product_reference': 'libgcrypt-help-1.10.2-4.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41989', 'notes': [{'text': 'Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41989', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2345', 'details': 'libgcrypt security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:libgcrypt-1.10.2-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libgcrypt-debuginfo-1.10.2-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libgcrypt-debugsource-1.10.2-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libgcrypt-devel-1.10.2-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libgcrypt-1.10.2-4.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:libgcrypt-1.10.2-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libgcrypt-debuginfo-1.10.2-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libgcrypt-debugsource-1.10.2-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libgcrypt-devel-1.10.2-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libgcrypt-help-1.10.2-4.oe2403sp3.noarch']}}]}
005ca677775c0d70250cf0c3571e25f1ae87fccd025c1fa89a33d42740626a45
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2346
An update for libgcrypt is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-15 17:05:40+03:00
2026-05-15 17:05:40+03:00
['CVE-2026-41989']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-1.10.2-3.oe2203sp4.src.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2346', 'summary': 'openEuler-SA-2026-2346', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2346.json', 'summary': 'openEuler-SA-2026-2346 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libgcrypt security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Libgcrypt is a general purpose cryptographic library originally based on code from GnuPG.\n\nSecurity Fix(es):\n\nLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.(CVE-2026-41989)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'libgcrypt', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libgcrypt is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2346', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:40+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:40+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:40+08:00', 'initial_release_date': '2026-05-15T22:05:40+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2346', 'summary': 'openEuler-SA-2026-2346', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2346.json', 'summary': 'openEuler-SA-2026-2346 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64.rpm', 'product': {'name': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libgcrypt-1.10.2-3.oe2203sp4.src.rpm', 'product': {'name': 'libgcrypt-1.10.2-3.oe2203sp4.src.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64.rpm', 'product': {'name': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch.rpm', 'product': {'name': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-1.10.2-3.oe2203sp4.aarch64'}, 'product_reference': 'libgcrypt-1.10.2-3.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64'}, 'product_reference': 'libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-3.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-1.10.2-3.oe2203sp4.src'}, 'product_reference': 'libgcrypt-1.10.2-3.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-1.10.2-3.oe2203sp4.x86_64'}, 'product_reference': 'libgcrypt-1.10.2-3.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64'}, 'product_reference': 'libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libgcrypt-help-1.10.2-3.oe2203sp4.noarch'}, 'product_reference': 'libgcrypt-help-1.10.2-3.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41989', 'notes': [{'text': 'Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41989', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2346', 'details': 'libgcrypt security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:libgcrypt-1.10.2-3.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libgcrypt-debuginfo-1.10.2-3.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libgcrypt-debugsource-1.10.2-3.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libgcrypt-devel-1.10.2-3.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libgcrypt-1.10.2-3.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:libgcrypt-1.10.2-3.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libgcrypt-debuginfo-1.10.2-3.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libgcrypt-debugsource-1.10.2-3.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libgcrypt-devel-1.10.2-3.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libgcrypt-help-1.10.2-3.oe2203sp4.noarch']}}]}
f6f84799cf6f5d68dc99aaee0c4b41ddc1260465e58623b5ce23aeb9d07a498d
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2347
An update for libgcrypt is now available for openEuler-24.03-LTS
Medium
2026-05-15 17:05:41+03:00
2026-05-15 17:05:41+03:00
['CVE-2026-41989']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-1.10.2-3.oe2403.src.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libgcrypt-help-1.10.2-3.oe2403.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-3.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2347', 'summary': 'openEuler-SA-2026-2347', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2347.json', 'summary': 'openEuler-SA-2026-2347 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libgcrypt security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Libgcrypt is a general purpose cryptographic library originally based on code from GnuPG.\n\nSecurity Fix(es):\n\nLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.(CVE-2026-41989)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'libgcrypt', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libgcrypt is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2347', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:41+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:41+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:41+08:00', 'initial_release_date': '2026-05-15T22:05:41+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2347', 'summary': 'openEuler-SA-2026-2347', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2347.json', 'summary': 'openEuler-SA-2026-2347 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libgcrypt-1.10.2-3.oe2403.aarch64.rpm', 'product': {'name': 'libgcrypt-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libgcrypt-1.10.2-3.oe2403.src.rpm', 'product': {'name': 'libgcrypt-1.10.2-3.oe2403.src.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libgcrypt-1.10.2-3.oe2403.x86_64.rpm', 'product': {'name': 'libgcrypt-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libgcrypt-help-1.10.2-3.oe2403.noarch.rpm', 'product': {'name': 'libgcrypt-help-1.10.2-3.oe2403.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-3.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-1.10.2-3.oe2403.aarch64'}, 'product_reference': 'libgcrypt-1.10.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-debugsource-1.10.2-3.oe2403.aarch64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-devel-1.10.2-3.oe2403.aarch64'}, 'product_reference': 'libgcrypt-devel-1.10.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-3.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-1.10.2-3.oe2403.src'}, 'product_reference': 'libgcrypt-1.10.2-3.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-1.10.2-3.oe2403.x86_64'}, 'product_reference': 'libgcrypt-1.10.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-debugsource-1.10.2-3.oe2403.x86_64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-devel-1.10.2-3.oe2403.x86_64'}, 'product_reference': 'libgcrypt-devel-1.10.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-help-1.10.2-3.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libgcrypt-help-1.10.2-3.oe2403.noarch'}, 'product_reference': 'libgcrypt-help-1.10.2-3.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41989', 'notes': [{'text': 'Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41989', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2347', 'details': 'libgcrypt security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:libgcrypt-1.10.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:libgcrypt-debuginfo-1.10.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:libgcrypt-debugsource-1.10.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:libgcrypt-devel-1.10.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:libgcrypt-1.10.2-3.oe2403.src', 'openEuler-24.03-LTS:libgcrypt-1.10.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:libgcrypt-debuginfo-1.10.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:libgcrypt-debugsource-1.10.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:libgcrypt-devel-1.10.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:libgcrypt-help-1.10.2-3.oe2403.noarch']}}]}
64aace5304a0a55807d67c63e7b97368965747d979795672a4002e9c4b4de407
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2348
An update for libgcrypt is now available for openEuler-24.03-LTS-SP1
Medium
2026-05-15 17:05:43+03:00
2026-05-15 17:05:43+03:00
['CVE-2026-41989']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-1.10.2-4.oe2403sp1.src.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2348', 'summary': 'openEuler-SA-2026-2348', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2348.json', 'summary': 'openEuler-SA-2026-2348 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libgcrypt security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'Libgcrypt is a general purpose cryptographic library originally based on code from GnuPG.\n\nSecurity Fix(es):\n\nLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.(CVE-2026-41989)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libgcrypt is now available for openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'libgcrypt', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libgcrypt is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2348', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:43+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:43+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:43+08:00', 'initial_release_date': '2026-05-15T22:05:43+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2348', 'summary': 'openEuler-SA-2026-2348', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41989&packageName=libgcrypt', 'summary': 'CVE-2026-41989', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2348.json', 'summary': 'openEuler-SA-2026-2348 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libgcrypt-1.10.2-4.oe2403sp1.src.rpm', 'product': {'name': 'libgcrypt-1.10.2-4.oe2403sp1.src.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_id': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch.rpm', 'product': {'name': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch.rpm', 'product_id': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-1.10.2-4.oe2403sp1.aarch64'}, 'product_reference': 'libgcrypt-1.10.2-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64'}, 'product_reference': 'libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-4.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-1.10.2-4.oe2403sp1.src'}, 'product_reference': 'libgcrypt-1.10.2-4.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-1.10.2-4.oe2403sp1.x86_64'}, 'product_reference': 'libgcrypt-1.10.2-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64'}, 'product_reference': 'libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64'}, 'product_reference': 'libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64'}, 'product_reference': 'libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:libgcrypt-help-1.10.2-4.oe2403sp1.noarch'}, 'product_reference': 'libgcrypt-help-1.10.2-4.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41989', 'notes': [{'text': 'Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41989', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2348', 'details': 'libgcrypt security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:libgcrypt-1.10.2-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libgcrypt-debuginfo-1.10.2-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libgcrypt-debugsource-1.10.2-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libgcrypt-devel-1.10.2-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:libgcrypt-1.10.2-4.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:libgcrypt-1.10.2-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libgcrypt-debuginfo-1.10.2-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libgcrypt-debugsource-1.10.2-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libgcrypt-devel-1.10.2-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:libgcrypt-help-1.10.2-4.oe2403sp1.noarch']}}]}
9879aec0333d6d6ddb54533d86e83d79f88fceab97001fe691665b627cbc7490
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2349
An update for firefox is now available for openEuler-22.03-LTS-SP4
Critical
2026-05-15 17:05:43+03:00
2026-05-15 17:05:43+03:00
['CVE-2026-8090', 'CVE-2026-8092', 'CVE-2026-8094']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-140.10.2-1.oe2203sp4.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2349', 'summary': 'openEuler-SA-2026-2349', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2349.json', 'summary': 'openEuler-SA-2026-2349 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nUse-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8090)\n\nMemory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8092)\n\nOther issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.(CVE-2026-8094)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2349', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:43+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:43+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:43+08:00', 'initial_release_date': '2026-05-15T22:05:43+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2349', 'summary': 'openEuler-SA-2026-2349', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2349.json', 'summary': 'openEuler-SA-2026-2349 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.10.2-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.10.2-1.oe2203sp4.src.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2203sp4.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.10.2-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-140.10.2-1.oe2203sp4.aarch64'}, 'product_reference': 'firefox-140.10.2-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.10.2-1.oe2203sp4.aarch64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-140.10.2-1.oe2203sp4.src'}, 'product_reference': 'firefox-140.10.2-1.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-140.10.2-1.oe2203sp4.x86_64'}, 'product_reference': 'firefox-140.10.2-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.10.2-1.oe2203sp4.x86_64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8090', 'notes': [{'text': 'Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8090', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2349', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:firefox-140.10.2-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.10.2-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.10.2-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:firefox-140.10.2-1.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:firefox-140.10.2-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.10.2-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.10.2-1.oe2203sp4.x86_64']}}, {'cve': 'CVE-2026-8092', 'notes': [{'text': 'Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8092', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2349', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8094', 'notes': [{'text': 'Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8094', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2349', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
12d29c4507ee5b1481fb8e58b4d81525ab5794b17c97b767328deb3e04da4774
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2350
An update for firefox is now available for openEuler-24.03-LTS
Critical
2026-05-15 17:05:43+03:00
2026-05-15 17:05:43+03:00
['CVE-2026-8090', 'CVE-2026-8092', 'CVE-2026-8094']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-140.10.2-1.oe2403.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debugsource-140.10.2-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-140.10.2-1.oe2403.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-140.10.2-1.oe2403.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debugsource-140.10.2-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2350', 'summary': 'openEuler-SA-2026-2350', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2350.json', 'summary': 'openEuler-SA-2026-2350 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nUse-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8090)\n\nMemory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8092)\n\nOther issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.(CVE-2026-8094)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2350', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:43+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:43+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:43+08:00', 'initial_release_date': '2026-05-15T22:05:43+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2350', 'summary': 'openEuler-SA-2026-2350', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2350.json', 'summary': 'openEuler-SA-2026-2350 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.10.2-1.oe2403.aarch64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2403.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.10.2-1.oe2403.src.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.10.2-1.oe2403.x86_64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2403.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-140.10.2-1.oe2403.aarch64'}, 'product_reference': 'firefox-140.10.2-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debuginfo-140.10.2-1.oe2403.aarch64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debugsource-140.10.2-1.oe2403.aarch64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-140.10.2-1.oe2403.src'}, 'product_reference': 'firefox-140.10.2-1.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-140.10.2-1.oe2403.x86_64'}, 'product_reference': 'firefox-140.10.2-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debuginfo-140.10.2-1.oe2403.x86_64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debugsource-140.10.2-1.oe2403.x86_64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8090', 'notes': [{'text': 'Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8090', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2350', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:firefox-140.10.2-1.oe2403.aarch64', 'openEuler-24.03-LTS:firefox-debuginfo-140.10.2-1.oe2403.aarch64', 'openEuler-24.03-LTS:firefox-debugsource-140.10.2-1.oe2403.aarch64', 'openEuler-24.03-LTS:firefox-140.10.2-1.oe2403.src', 'openEuler-24.03-LTS:firefox-140.10.2-1.oe2403.x86_64', 'openEuler-24.03-LTS:firefox-debuginfo-140.10.2-1.oe2403.x86_64', 'openEuler-24.03-LTS:firefox-debugsource-140.10.2-1.oe2403.x86_64']}}, {'cve': 'CVE-2026-8092', 'notes': [{'text': 'Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8092', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2350', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8094', 'notes': [{'text': 'Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8094', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2350', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
073d8233da4acfc803eb3b0d5d8b81610fb1f0893b0544b3e53c84aa641451eb
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2351
An update for firefox is now available for openEuler-24.03-LTS-SP1
Critical
2026-05-15 17:05:43+03:00
2026-05-15 17:05:43+03:00
['CVE-2026-8090', 'CVE-2026-8092', 'CVE-2026-8094']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-140.10.2-1.oe2403sp1.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2351', 'summary': 'openEuler-SA-2026-2351', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2351.json', 'summary': 'openEuler-SA-2026-2351 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nUse-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8090)\n\nMemory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8092)\n\nOther issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.(CVE-2026-8094)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2351', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:43+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:43+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:43+08:00', 'initial_release_date': '2026-05-15T22:05:43+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2351', 'summary': 'openEuler-SA-2026-2351', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2351.json', 'summary': 'openEuler-SA-2026-2351 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.10.2-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.10.2-1.oe2403sp1.src.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403sp1.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.10.2-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-140.10.2-1.oe2403sp1.aarch64'}, 'product_reference': 'firefox-140.10.2-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-debugsource-140.10.2-1.oe2403sp1.aarch64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-140.10.2-1.oe2403sp1.src'}, 'product_reference': 'firefox-140.10.2-1.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-140.10.2-1.oe2403sp1.x86_64'}, 'product_reference': 'firefox-140.10.2-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:firefox-debugsource-140.10.2-1.oe2403sp1.x86_64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8090', 'notes': [{'text': 'Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8090', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2351', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:firefox-140.10.2-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:firefox-debuginfo-140.10.2-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:firefox-debugsource-140.10.2-1.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:firefox-140.10.2-1.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:firefox-140.10.2-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:firefox-debuginfo-140.10.2-1.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:firefox-debugsource-140.10.2-1.oe2403sp1.x86_64']}}, {'cve': 'CVE-2026-8092', 'notes': [{'text': 'Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8092', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2351', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8094', 'notes': [{'text': 'Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8094', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2351', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
60140f618d3b49cf0280d3d8c72c0ff28369ae2a56a0ed06d83b6521d4aaaa2a
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2352
An update for firefox is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-15 17:05:45+03:00
2026-05-15 17:05:45+03:00
['CVE-2026-8090', 'CVE-2026-8092', 'CVE-2026-8094']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-140.10.2-1.oe2403sp3.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2352', 'summary': 'openEuler-SA-2026-2352', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2352.json', 'summary': 'openEuler-SA-2026-2352 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nUse-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8090)\n\nMemory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.(CVE-2026-8092)\n\nOther issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.(CVE-2026-8094)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2352', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:45+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:45+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:45+08:00', 'initial_release_date': '2026-05-15T22:05:45+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2352', 'summary': 'openEuler-SA-2026-2352', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8090&packageName=firefox', 'summary': 'CVE-2026-8090', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8092&packageName=firefox', 'summary': 'CVE-2026-8092', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8094&packageName=firefox', 'summary': 'CVE-2026-8094', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8090', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8092', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8094', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2352.json', 'summary': 'openEuler-SA-2026-2352 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.10.2-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.10.2-1.oe2403sp3.src.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403sp3.src.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.10.2-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'firefox-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-140.10.2-1.oe2403sp3.aarch64'}, 'product_reference': 'firefox-140.10.2-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.10.2-1.oe2403sp3.aarch64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-140.10.2-1.oe2403sp3.src'}, 'product_reference': 'firefox-140.10.2-1.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.10.2-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-140.10.2-1.oe2403sp3.x86_64'}, 'product_reference': 'firefox-140.10.2-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64'}, 'product_reference': 'firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.10.2-1.oe2403sp3.x86_64'}, 'product_reference': 'firefox-debugsource-140.10.2-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8090', 'notes': [{'text': 'Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8090', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2352', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:firefox-140.10.2-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.10.2-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.10.2-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:firefox-140.10.2-1.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:firefox-140.10.2-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.10.2-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.10.2-1.oe2403sp3.x86_64']}}, {'cve': 'CVE-2026-8092', 'notes': [{'text': 'Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8092', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2352', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8094', 'notes': [{'text': 'Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8094', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2352', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
d69894b1051fa19c638bcc8a3a3837dc0d285b338ea4231c03d38976fd5d2907
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2221
An update for gnutls is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1
High
2026-05-09 15:34:48+03:00
2026-05-09 15:34:48+03:00
['CVE-2026-33845']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-help-3.8.2-12.oe2403sp3.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-12.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-help-3.6.14-20.oe2003sp4.noarch.rpm', 'product_id': 'gnutls-help-3.6.14-20.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-help-3.7.2-21.oe2203sp4.noarch.rpm', 'product_id': 'gnutls-help-3.7.2-21.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-help-3.8.2-12.oe2403.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-12.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-help-3.8.2-12.oe2403sp1.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-12.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-3.6.14-20.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-3.7.2-21.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-dane-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-devel-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-utils-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-3.8.2-12.oe2403sp3.src.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-3.6.14-20.oe2003sp4.src.rpm', 'product_id': 'gnutls-3.6.14-20.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-21.oe2203sp4.src.rpm', 'product_id': 'gnutls-3.7.2-21.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-3.8.2-12.oe2403.src.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-3.8.2-12.oe2403sp1.src.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-3.6.14-20.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-3.7.2-21.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-dane-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-devel-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'gnutls-utils-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2221', 'summary': 'openEuler-SA-2026-2221', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33845&packageName=gnutls', 'summary': 'CVE-2026-33845', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33845', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2221.json', 'summary': 'openEuler-SA-2026-2221 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.(CVE-2026-33845)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2221', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-09T20:34:48+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-09T20:34:48+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-09T20:34:48+08:00', 'initial_release_date': '2026-05-09T20:34:48+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2221', 'summary': 'openEuler-SA-2026-2221', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33845&packageName=gnutls', 'summary': 'CVE-2026-33845', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33845', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2221.json', 'summary': 'openEuler-SA-2026-2221 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.8.2-12.oe2403sp3.noarch.rpm', 'product': {'name': 'gnutls-help-3.8.2-12.oe2403sp3.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-12.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-help-3.6.14-20.oe2003sp4.noarch.rpm', 'product': {'name': 'gnutls-help-3.6.14-20.oe2003sp4.noarch.rpm', 'product_id': 'gnutls-help-3.6.14-20.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-help-3.7.2-21.oe2203sp4.noarch.rpm', 'product': {'name': 'gnutls-help-3.7.2-21.oe2203sp4.noarch.rpm', 'product_id': 'gnutls-help-3.7.2-21.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-help-3.8.2-12.oe2403.noarch.rpm', 'product': {'name': 'gnutls-help-3.8.2-12.oe2403.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-12.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-help-3.8.2-12.oe2403sp1.noarch.rpm', 'product': {'name': 'gnutls-help-3.8.2-12.oe2403sp1.noarch.rpm', 'product_id': 'gnutls-help-3.8.2-12.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.8.2-12.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-3.6.14-20.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-3.7.2-21.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-3.8.2-12.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-12.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-12.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-12.oe2403.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-12.oe2403.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-3.8.2-12.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.8.2-12.oe2403sp3.src.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403sp3.src.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-3.6.14-20.oe2003sp4.src.rpm', 'product': {'name': 'gnutls-3.6.14-20.oe2003sp4.src.rpm', 'product_id': 'gnutls-3.6.14-20.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-3.7.2-21.oe2203sp4.src.rpm', 'product': {'name': 'gnutls-3.7.2-21.oe2203sp4.src.rpm', 'product_id': 'gnutls-3.7.2-21.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-3.8.2-12.oe2403.src.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403.src.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-3.8.2-12.oe2403sp1.src.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403sp1.src.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.8.2-12.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'gnutls-3.6.14-20.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-3.7.2-21.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-3.8.2-12.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-12.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-12.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-12.oe2403.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-12.oe2403.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'gnutls-3.8.2-12.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_id': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.8.2-12.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-12.oe2403sp3.noarch'}, 'product_reference': 'gnutls-help-3.8.2-12.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.6.14-20.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-help-3.6.14-20.oe2003sp4.noarch'}, 'product_reference': 'gnutls-help-3.6.14-20.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.7.2-21.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-help-3.7.2-21.oe2203sp4.noarch'}, 'product_reference': 'gnutls-help-3.7.2-21.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.8.2-12.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-help-3.8.2-12.oe2403.noarch'}, 'product_reference': 'gnutls-help-3.8.2-12.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.8.2-12.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-help-3.8.2-12.oe2403sp1.noarch'}, 'product_reference': 'gnutls-help-3.8.2-12.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-12.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-3.8.2-12.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-12.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-dane-3.8.2-12.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-12.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-devel-3.8.2-12.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-12.oe2403sp3.aarch64'}, 'product_reference': 'gnutls-utils-3.8.2-12.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.6.14-20.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-20.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-3.6.14-20.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-20.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-devel-3.6.14-20.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-20.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-utils-3.6.14-20.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-21.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-21.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-3.7.2-21.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-21.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-devel-3.7.2-21.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-21.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-utils-3.7.2-21.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-3.8.2-12.oe2403.aarch64'}, 'product_reference': 'gnutls-3.8.2-12.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-12.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-dane-3.8.2-12.oe2403.aarch64'}, 'product_reference': 'gnutls-dane-3.8.2-12.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-12.oe2403.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-12.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-12.oe2403.aarch64'}, 'product_reference': 'gnutls-debugsource-3.8.2-12.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-12.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-devel-3.8.2-12.oe2403.aarch64'}, 'product_reference': 'gnutls-devel-3.8.2-12.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-12.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-utils-3.8.2-12.oe2403.aarch64'}, 'product_reference': 'gnutls-utils-3.8.2-12.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-12.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-3.8.2-12.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-12.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-dane-3.8.2-12.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-12.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-devel-3.8.2-12.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-12.oe2403sp1.aarch64'}, 'product_reference': 'gnutls-utils-3.8.2-12.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-12.oe2403sp3.src'}, 'product_reference': 'gnutls-3.8.2-12.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.6.14-20.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-20.oe2003sp4.src'}, 'product_reference': 'gnutls-3.6.14-20.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-21.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-21.oe2203sp4.src'}, 'product_reference': 'gnutls-3.7.2-21.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-3.8.2-12.oe2403.src'}, 'product_reference': 'gnutls-3.8.2-12.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-12.oe2403sp1.src'}, 'product_reference': 'gnutls-3.8.2-12.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-12.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-3.8.2-12.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-12.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-dane-3.8.2-12.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-12.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-devel-3.8.2-12.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-12.oe2403sp3.x86_64'}, 'product_reference': 'gnutls-utils-3.8.2-12.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.6.14-20.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-20.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-3.6.14-20.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-20.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-devel-3.6.14-20.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-20.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-utils-3.6.14-20.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-21.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-21.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-3.7.2-21.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-21.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-devel-3.7.2-21.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-21.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-utils-3.7.2-21.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-3.8.2-12.oe2403.x86_64'}, 'product_reference': 'gnutls-3.8.2-12.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-12.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-dane-3.8.2-12.oe2403.x86_64'}, 'product_reference': 'gnutls-dane-3.8.2-12.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-12.oe2403.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-12.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-12.oe2403.x86_64'}, 'product_reference': 'gnutls-debugsource-3.8.2-12.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-12.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-devel-3.8.2-12.oe2403.x86_64'}, 'product_reference': 'gnutls-devel-3.8.2-12.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-12.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:gnutls-utils-3.8.2-12.oe2403.x86_64'}, 'product_reference': 'gnutls-utils-3.8.2-12.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.8.2-12.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-12.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-3.8.2-12.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-12.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-dane-3.8.2-12.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-12.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-devel-3.8.2-12.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-12.oe2403sp1.x86_64'}, 'product_reference': 'gnutls-utils-3.8.2-12.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33845', 'notes': [{'text': 'A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33845', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2221', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-12.oe2403sp3.noarch', 'openEuler-20.03-LTS-SP4:gnutls-help-3.6.14-20.oe2003sp4.noarch', 'openEuler-22.03-LTS-SP4:gnutls-help-3.7.2-21.oe2203sp4.noarch', 'openEuler-24.03-LTS:gnutls-help-3.8.2-12.oe2403.noarch', 'openEuler-24.03-LTS-SP1:gnutls-help-3.8.2-12.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-12.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-12.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-12.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-12.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-12.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-12.oe2403sp3.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-20.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-20.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-20.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-20.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-20.oe2003sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-21.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-21.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-21.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-21.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-21.oe2203sp4.aarch64', 'openEuler-24.03-LTS:gnutls-3.8.2-12.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-dane-3.8.2-12.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-12.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-12.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-devel-3.8.2-12.oe2403.aarch64', 'openEuler-24.03-LTS:gnutls-utils-3.8.2-12.oe2403.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-12.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-12.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-12.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-12.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-12.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-12.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-12.oe2403sp3.src', 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-20.oe2003sp4.src', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-21.oe2203sp4.src', 'openEuler-24.03-LTS:gnutls-3.8.2-12.oe2403.src', 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-12.oe2403sp1.src', 'openEuler-24.03-LTS-SP3:gnutls-3.8.2-12.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-12.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-12.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-12.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-12.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-12.oe2403sp3.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-20.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-20.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-20.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-20.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-20.oe2003sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-21.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-21.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-21.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-21.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-21.oe2203sp4.x86_64', 'openEuler-24.03-LTS:gnutls-3.8.2-12.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-dane-3.8.2-12.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-debuginfo-3.8.2-12.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-debugsource-3.8.2-12.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-devel-3.8.2-12.oe2403.x86_64', 'openEuler-24.03-LTS:gnutls-utils-3.8.2-12.oe2403.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-3.8.2-12.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-dane-3.8.2-12.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-debuginfo-3.8.2-12.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-debugsource-3.8.2-12.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-devel-3.8.2-12.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:gnutls-utils-3.8.2-12.oe2403sp1.x86_64']}}]}
044b3d467bdbd59849252601ab9d81094e21a26d8221b02d862d7f6fc50db3da
2026-06-01 21:24:54.157429+03:00
2026-06-23 02:36:22.792272+03:00
openEuler-SA-2026-2353
An update for audiofile is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS
High
2026-05-15 17:05:45+03:00
2026-05-15 17:05:45+03:00
['CVE-2018-13440', 'CVE-2018-17095', 'CVE-2022-24599']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-devel-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-0.3.6-32.oe2403sp1.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-0.3.6-32.oe2403sp3.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-0.3.6-32.oe2003sp4.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-0.3.6-32.oe2203sp4.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-0.3.6-32.oe2403.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-devel-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'audiofile-help-0.3.6-32.oe2403sp1.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'audiofile-help-0.3.6-32.oe2403sp3.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'audiofile-help-0.3.6-32.oe2003sp4.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'audiofile-help-0.3.6-32.oe2203sp4.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'audiofile-help-0.3.6-32.oe2403.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2353', 'summary': 'openEuler-SA-2026-2353', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2018-13440&packageName=audiofile', 'summary': 'CVE-2018-13440', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2018-17095&packageName=audiofile', 'summary': 'CVE-2018-17095', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2022-24599&packageName=audiofile', 'summary': 'CVE-2022-24599', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-13440', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-17095', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2022-24599', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2353.json', 'summary': 'openEuler-SA-2026-2353 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'audiofile security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for audiofile is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': "The Audio File Library is a C-based library for reading and writing audio files in many common formats.\n\nSecurity Fix(es):\n\nThe audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.(CVE-2018-13440)\n\nAn issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.(CVE-2018-17095)\n\nIn autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.(CVE-2022-24599)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for audiofile is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'audiofile', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for audiofile is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2353', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:45+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:45+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:45+08:00', 'initial_release_date': '2026-05-15T22:05:45+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2353', 'summary': 'openEuler-SA-2026-2353', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2018-13440&packageName=audiofile', 'summary': 'CVE-2018-13440', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2018-17095&packageName=audiofile', 'summary': 'CVE-2018-17095', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2022-24599&packageName=audiofile', 'summary': 'CVE-2022-24599', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-13440', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-17095', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2022-24599', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2353.json', 'summary': 'openEuler-SA-2026-2353 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'audiofile-0.3.6-32.oe2403sp1.aarch64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2403sp3.aarch64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2003sp4.aarch64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2203sp4.aarch64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2403.aarch64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2403.aarch64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2403.aarch64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'audiofile-0.3.6-32.oe2403sp1.src.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403sp1.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2403sp3.src.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403sp3.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2003sp4.src.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2003sp4.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2203sp4.src.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2203sp4.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2403.src.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403.src.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'audiofile-0.3.6-32.oe2403sp1.x86_64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2403sp3.x86_64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2003sp4.x86_64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2203sp4.x86_64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-0.3.6-32.oe2403.x86_64.rpm', 'product': {'name': 'audiofile-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-0.3.6-32.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64.rpm', 'product': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64.rpm', 'product': {'name': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'audiofile-devel-0.3.6-32.oe2403.x86_64.rpm', 'product': {'name': 'audiofile-devel-0.3.6-32.oe2403.x86_64.rpm', 'product_id': 'audiofile-devel-0.3.6-32.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'audiofile-help-0.3.6-32.oe2403sp1.noarch.rpm', 'product': {'name': 'audiofile-help-0.3.6-32.oe2403sp1.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'audiofile-help-0.3.6-32.oe2403sp3.noarch.rpm', 'product': {'name': 'audiofile-help-0.3.6-32.oe2403sp3.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'audiofile-help-0.3.6-32.oe2003sp4.noarch.rpm', 'product': {'name': 'audiofile-help-0.3.6-32.oe2003sp4.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-help-0.3.6-32.oe2203sp4.noarch.rpm', 'product': {'name': 'audiofile-help-0.3.6-32.oe2203sp4.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'audiofile-help-0.3.6-32.oe2403.noarch.rpm', 'product': {'name': 'audiofile-help-0.3.6-32.oe2403.noarch.rpm', 'product_id': 'audiofile-help-0.3.6-32.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-0.3.6-32.oe2403sp1.aarch64'}, 'product_reference': 'audiofile-0.3.6-32.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-devel-0.3.6-32.oe2403sp1.aarch64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-0.3.6-32.oe2403sp3.aarch64'}, 'product_reference': 'audiofile-0.3.6-32.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-devel-0.3.6-32.oe2403sp3.aarch64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-0.3.6-32.oe2003sp4.aarch64'}, 'product_reference': 'audiofile-0.3.6-32.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2003sp4.aarch64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-0.3.6-32.oe2203sp4.aarch64'}, 'product_reference': 'audiofile-0.3.6-32.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2203sp4.aarch64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-0.3.6-32.oe2403.aarch64'}, 'product_reference': 'audiofile-0.3.6-32.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-debuginfo-0.3.6-32.oe2403.aarch64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-debugsource-0.3.6-32.oe2403.aarch64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-devel-0.3.6-32.oe2403.aarch64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-0.3.6-32.oe2403sp1.src'}, 'product_reference': 'audiofile-0.3.6-32.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-0.3.6-32.oe2403sp3.src'}, 'product_reference': 'audiofile-0.3.6-32.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-0.3.6-32.oe2003sp4.src'}, 'product_reference': 'audiofile-0.3.6-32.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-0.3.6-32.oe2203sp4.src'}, 'product_reference': 'audiofile-0.3.6-32.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-0.3.6-32.oe2403.src'}, 'product_reference': 'audiofile-0.3.6-32.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-0.3.6-32.oe2403sp1.x86_64'}, 'product_reference': 'audiofile-0.3.6-32.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-devel-0.3.6-32.oe2403sp1.x86_64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-0.3.6-32.oe2403sp3.x86_64'}, 'product_reference': 'audiofile-0.3.6-32.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-devel-0.3.6-32.oe2403sp3.x86_64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-0.3.6-32.oe2003sp4.x86_64'}, 'product_reference': 'audiofile-0.3.6-32.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2003sp4.x86_64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-0.3.6-32.oe2203sp4.x86_64'}, 'product_reference': 'audiofile-0.3.6-32.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2203sp4.x86_64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-0.3.6-32.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-0.3.6-32.oe2403.x86_64'}, 'product_reference': 'audiofile-0.3.6-32.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-debuginfo-0.3.6-32.oe2403.x86_64'}, 'product_reference': 'audiofile-debuginfo-0.3.6-32.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-debugsource-0.3.6-32.oe2403.x86_64'}, 'product_reference': 'audiofile-debugsource-0.3.6-32.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-devel-0.3.6-32.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-devel-0.3.6-32.oe2403.x86_64'}, 'product_reference': 'audiofile-devel-0.3.6-32.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-help-0.3.6-32.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:audiofile-help-0.3.6-32.oe2403sp1.noarch'}, 'product_reference': 'audiofile-help-0.3.6-32.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-help-0.3.6-32.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:audiofile-help-0.3.6-32.oe2403sp3.noarch'}, 'product_reference': 'audiofile-help-0.3.6-32.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-help-0.3.6-32.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:audiofile-help-0.3.6-32.oe2003sp4.noarch'}, 'product_reference': 'audiofile-help-0.3.6-32.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-help-0.3.6-32.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:audiofile-help-0.3.6-32.oe2203sp4.noarch'}, 'product_reference': 'audiofile-help-0.3.6-32.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'audiofile-help-0.3.6-32.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:audiofile-help-0.3.6-32.oe2403.noarch'}, 'product_reference': 'audiofile-help-0.3.6-32.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2018-13440', 'notes': [{'text': 'The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-13440', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2353', 'details': 'audiofile security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:audiofile-0.3.6-32.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:audiofile-debuginfo-0.3.6-32.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:audiofile-debugsource-0.3.6-32.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:audiofile-devel-0.3.6-32.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP3:audiofile-0.3.6-32.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:audiofile-debuginfo-0.3.6-32.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:audiofile-debugsource-0.3.6-32.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:audiofile-devel-0.3.6-32.oe2403sp3.aarch64', 'openEuler-20.03-LTS-SP4:audiofile-0.3.6-32.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2003sp4.aarch64', 'openEuler-22.03-LTS-SP4:audiofile-0.3.6-32.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2203sp4.aarch64', 'openEuler-24.03-LTS:audiofile-0.3.6-32.oe2403.aarch64', 'openEuler-24.03-LTS:audiofile-debuginfo-0.3.6-32.oe2403.aarch64', 'openEuler-24.03-LTS:audiofile-debugsource-0.3.6-32.oe2403.aarch64', 'openEuler-24.03-LTS:audiofile-devel-0.3.6-32.oe2403.aarch64', 'openEuler-24.03-LTS-SP1:audiofile-0.3.6-32.oe2403sp1.src', 'openEuler-24.03-LTS-SP3:audiofile-0.3.6-32.oe2403sp3.src', 'openEuler-20.03-LTS-SP4:audiofile-0.3.6-32.oe2003sp4.src', 'openEuler-22.03-LTS-SP4:audiofile-0.3.6-32.oe2203sp4.src', 'openEuler-24.03-LTS:audiofile-0.3.6-32.oe2403.src', 'openEuler-24.03-LTS-SP1:audiofile-0.3.6-32.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:audiofile-debuginfo-0.3.6-32.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:audiofile-debugsource-0.3.6-32.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:audiofile-devel-0.3.6-32.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP3:audiofile-0.3.6-32.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:audiofile-debuginfo-0.3.6-32.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:audiofile-debugsource-0.3.6-32.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:audiofile-devel-0.3.6-32.oe2403sp3.x86_64', 'openEuler-20.03-LTS-SP4:audiofile-0.3.6-32.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2003sp4.x86_64', 'openEuler-22.03-LTS-SP4:audiofile-0.3.6-32.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:audiofile-debuginfo-0.3.6-32.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:audiofile-debugsource-0.3.6-32.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:audiofile-devel-0.3.6-32.oe2203sp4.x86_64', 'openEuler-24.03-LTS:audiofile-0.3.6-32.oe2403.x86_64', 'openEuler-24.03-LTS:audiofile-debuginfo-0.3.6-32.oe2403.x86_64', 'openEuler-24.03-LTS:audiofile-debugsource-0.3.6-32.oe2403.x86_64', 'openEuler-24.03-LTS:audiofile-devel-0.3.6-32.oe2403.x86_64', 'openEuler-24.03-LTS-SP1:audiofile-help-0.3.6-32.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP3:audiofile-help-0.3.6-32.oe2403sp3.noarch', 'openEuler-20.03-LTS-SP4:audiofile-help-0.3.6-32.oe2003sp4.noarch', 'openEuler-22.03-LTS-SP4:audiofile-help-0.3.6-32.oe2203sp4.noarch', 'openEuler-24.03-LTS:audiofile-help-0.3.6-32.oe2403.noarch']}}, {'cve': 'CVE-2018-17095', 'notes': [{'text': 'An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-17095', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2353', 'details': 'audiofile security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2022-24599', 'notes': [{'text': "In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-24599', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2353', 'details': 'audiofile security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
02c73814e8468627edb230eba7bb127e69a1278a5bb0d4c7aa65f0ffdcd0b274
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2354
An update for evolution-data-server is now available for openEuler-24.03-LTS
Medium
2026-05-15 17:05:46+03:00
2026-05-15 17:05:46+03:00
['CVE-2026-2604']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-3.46.2-3.oe2403.src.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-help-3.46.2-3.oe2403.noarch.rpm', 'product_id': 'evolution-data-server-help-3.46.2-3.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch.rpm', 'product_id': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2354', 'summary': 'openEuler-SA-2026-2354', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-2604&packageName=evolution-data-server', 'summary': 'CVE-2026-2604', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-2604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2354.json', 'summary': 'openEuler-SA-2026-2354 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'evolution-data-server security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for evolution-data-server is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'The evolution-data-server package provides a personal information management application that provides integrated mail, calendaring and address book functionality. The evolution-data-server package provides a single database for common, desktop-wide information, such as a user's address book or calendar events.\n\nSecurity Fix(es):\n\nA flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.(CVE-2026-2604)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for evolution-data-server is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'evolution-data-server', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for evolution-data-server is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2354', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:46+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:46+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:46+08:00', 'initial_release_date': '2026-05-15T22:05:46+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2354', 'summary': 'openEuler-SA-2026-2354', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-2604&packageName=evolution-data-server', 'summary': 'CVE-2026-2604', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-2604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2354.json', 'summary': 'openEuler-SA-2026-2354 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403.aarch64.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64.rpm', 'product': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64.rpm', 'product': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64.rpm', 'product': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64.rpm', 'product': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403.src.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403.src.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403.x86_64.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64.rpm', 'product': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64.rpm', 'product': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64.rpm', 'product': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64.rpm', 'product': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'evolution-data-server-help-3.46.2-3.oe2403.noarch.rpm', 'product': {'name': 'evolution-data-server-help-3.46.2-3.oe2403.noarch.rpm', 'product_id': 'evolution-data-server-help-3.46.2-3.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch.rpm', 'product': {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch.rpm', 'product_id': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-3.46.2-3.oe2403.aarch64'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64'}, 'product_reference': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64'}, 'product_reference': 'evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-devel-3.46.2-3.oe2403.aarch64'}, 'product_reference': 'evolution-data-server-devel-3.46.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-perl-3.46.2-3.oe2403.aarch64'}, 'product_reference': 'evolution-data-server-perl-3.46.2-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-3.46.2-3.oe2403.src'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-3.46.2-3.oe2403.x86_64'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64'}, 'product_reference': 'evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64'}, 'product_reference': 'evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-devel-3.46.2-3.oe2403.x86_64'}, 'product_reference': 'evolution-data-server-devel-3.46.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-perl-3.46.2-3.oe2403.x86_64'}, 'product_reference': 'evolution-data-server-perl-3.46.2-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-help-3.46.2-3.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-help-3.46.2-3.oe2403.noarch'}, 'product_reference': 'evolution-data-server-help-3.46.2-3.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:evolution-data-server-langpacks-3.46.2-3.oe2403.noarch'}, 'product_reference': 'evolution-data-server-langpacks-3.46.2-3.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-2604', 'notes': [{'text': 'A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-2604', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2354', 'details': 'evolution-data-server security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:evolution-data-server-3.46.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:evolution-data-server-debuginfo-3.46.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:evolution-data-server-debugsource-3.46.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:evolution-data-server-devel-3.46.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:evolution-data-server-perl-3.46.2-3.oe2403.aarch64', 'openEuler-24.03-LTS:evolution-data-server-3.46.2-3.oe2403.src', 'openEuler-24.03-LTS:evolution-data-server-3.46.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:evolution-data-server-debuginfo-3.46.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:evolution-data-server-debugsource-3.46.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:evolution-data-server-devel-3.46.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:evolution-data-server-perl-3.46.2-3.oe2403.x86_64', 'openEuler-24.03-LTS:evolution-data-server-help-3.46.2-3.oe2403.noarch', 'openEuler-24.03-LTS:evolution-data-server-langpacks-3.46.2-3.oe2403.noarch']}}]}
36200df7ef7fd1877d37875fbd8296bd0f7af7501a82bd26fd541d0aa63b5a37
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2355
An update for evolution-data-server is now available for openEuler-24.03-LTS-SP1
Medium
2026-05-15 17:05:46+03:00
2026-05-15 17:05:46+03:00
['CVE-2026-2604']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-3.46.2-3.oe2403sp1.src.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch.rpm', 'product_id': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch.rpm', 'product_id': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2355', 'summary': 'openEuler-SA-2026-2355', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-2604&packageName=evolution-data-server', 'summary': 'CVE-2026-2604', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-2604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2355.json', 'summary': 'openEuler-SA-2026-2355 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'evolution-data-server security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for evolution-data-server is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'The evolution-data-server package provides a personal information management application that provides integrated mail, calendaring and address book functionality. The evolution-data-server package provides a single database for common, desktop-wide information, such as a user's address book or calendar events.\n\nSecurity Fix(es):\n\nA flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.(CVE-2026-2604)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for evolution-data-server is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'evolution-data-server', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for evolution-data-server is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2355', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:46+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:46+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:46+08:00', 'initial_release_date': '2026-05-15T22:05:46+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2355', 'summary': 'openEuler-SA-2026-2355', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-2604&packageName=evolution-data-server', 'summary': 'CVE-2026-2604', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-2604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2355.json', 'summary': 'openEuler-SA-2026-2355 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64.rpm', 'product': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64.rpm', 'product': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64.rpm', 'product': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64.rpm', 'product': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403sp1.src.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403sp1.src.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64.rpm', 'product': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64.rpm', 'product': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64.rpm', 'product': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64.rpm', 'product': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch.rpm', 'product': {'name': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch.rpm', 'product_id': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch.rpm', 'product': {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch.rpm', 'product_id': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-3.46.2-3.oe2403sp1.aarch64'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64'}, 'product_reference': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64'}, 'product_reference': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64'}, 'product_reference': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64'}, 'product_reference': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-3.46.2-3.oe2403sp1.src'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-3.46.2-3.oe2403sp1.x86_64'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64'}, 'product_reference': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64'}, 'product_reference': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64'}, 'product_reference': 'evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64'}, 'product_reference': 'evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-help-3.46.2-3.oe2403sp1.noarch'}, 'product_reference': 'evolution-data-server-help-3.46.2-3.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch'}, 'product_reference': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-2604', 'notes': [{'text': 'A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-2604', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2355', 'details': 'evolution-data-server security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:evolution-data-server-3.46.2-3.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:evolution-data-server-debugsource-3.46.2-3.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:evolution-data-server-devel-3.46.2-3.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:evolution-data-server-perl-3.46.2-3.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:evolution-data-server-3.46.2-3.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:evolution-data-server-3.46.2-3.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:evolution-data-server-debuginfo-3.46.2-3.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:evolution-data-server-debugsource-3.46.2-3.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:evolution-data-server-devel-3.46.2-3.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:evolution-data-server-perl-3.46.2-3.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:evolution-data-server-help-3.46.2-3.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP1:evolution-data-server-langpacks-3.46.2-3.oe2403sp1.noarch']}}]}
5a86102453fdae9e5d5803e0e8a0a9f843f90a5ea2ece5047e2a442ade981b93
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2356
An update for evolution-data-server is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-15 17:05:46+03:00
2026-05-15 17:05:46+03:00
['CVE-2026-2604']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch.rpm', 'product_id': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch.rpm', 'product_id': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-3.46.2-3.oe2403sp3.src.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2356', 'summary': 'openEuler-SA-2026-2356', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-2604&packageName=evolution-data-server', 'summary': 'CVE-2026-2604', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-2604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2356.json', 'summary': 'openEuler-SA-2026-2356 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'evolution-data-server security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for evolution-data-server is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'The evolution-data-server package provides a personal information management application that provides integrated mail, calendaring and address book functionality. The evolution-data-server package provides a single database for common, desktop-wide information, such as a user's address book or calendar events.\n\nSecurity Fix(es):\n\nA flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.(CVE-2026-2604)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for evolution-data-server is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'evolution-data-server', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for evolution-data-server is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2356', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:46+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:46+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:46+08:00', 'initial_release_date': '2026-05-15T22:05:46+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2356', 'summary': 'openEuler-SA-2026-2356', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-2604&packageName=evolution-data-server', 'summary': 'CVE-2026-2604', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-2604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2356.json', 'summary': 'openEuler-SA-2026-2356 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch.rpm', 'product': {'name': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch.rpm', 'product_id': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch.rpm', 'product': {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch.rpm', 'product_id': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403sp3.src.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403sp3.src.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_id': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-help-3.46.2-3.oe2403sp3.noarch'}, 'product_reference': 'evolution-data-server-help-3.46.2-3.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch'}, 'product_reference': 'evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-3.46.2-3.oe2403sp3.aarch64'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64'}, 'product_reference': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64'}, 'product_reference': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64'}, 'product_reference': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64'}, 'product_reference': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-3.46.2-3.oe2403sp3.src'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-3.46.2-3.oe2403sp3.x86_64'}, 'product_reference': 'evolution-data-server-3.46.2-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64'}, 'product_reference': 'evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64'}, 'product_reference': 'evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64'}, 'product_reference': 'evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64'}, 'product_reference': 'evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-2604', 'notes': [{'text': 'A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-2604', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2356', 'details': 'evolution-data-server security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:evolution-data-server-help-3.46.2-3.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:evolution-data-server-langpacks-3.46.2-3.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:evolution-data-server-3.46.2-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:evolution-data-server-debugsource-3.46.2-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:evolution-data-server-devel-3.46.2-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:evolution-data-server-perl-3.46.2-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:evolution-data-server-3.46.2-3.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:evolution-data-server-3.46.2-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:evolution-data-server-debuginfo-3.46.2-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:evolution-data-server-debugsource-3.46.2-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:evolution-data-server-devel-3.46.2-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:evolution-data-server-perl-3.46.2-3.oe2403sp3.x86_64']}}]}
f0c70497cd49afb0a96dc140dfe784c0803bfeb32c733c92c7511988acf05931
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2357
An update for busybox is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1
High
2026-05-15 17:05:48+03:00
2026-05-15 17:05:48+03:00
['CVE-2026-29004']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-1.31.1-30.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-help-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-help-1.31.1-30.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-1.34.1-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-help-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-help-1.34.1-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-debugsource-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-petitboot-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-help-1.36.1-16.oe2403sp3.noarch.rpm', 'product_id': 'busybox-help-1.36.1-16.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-help-1.36.1-16.oe2403.noarch.rpm', 'product_id': 'busybox-help-1.36.1-16.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-help-1.36.1-16.oe2403sp1.noarch.rpm', 'product_id': 'busybox-help-1.36.1-16.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-1.31.1-30.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-help-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-help-1.31.1-30.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-1.34.1-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-help-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-help-1.34.1-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-debugsource-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-petitboot-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'busybox-1.36.1-16.oe2403sp3.src.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'busybox-1.31.1-30.oe2003sp4.src.rpm', 'product_id': 'busybox-1.31.1-30.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'busybox-1.34.1-30.oe2203sp4.src.rpm', 'product_id': 'busybox-1.34.1-30.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'busybox-1.36.1-16.oe2403.src.rpm', 'product_id': 'busybox-1.36.1-16.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'busybox-1.36.1-16.oe2403sp1.src.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp1.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2357', 'summary': 'openEuler-SA-2026-2357', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-29004&packageName=busybox', 'summary': 'CVE-2026-29004', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-29004', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2357.json', 'summary': 'openEuler-SA-2026-2357 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'busybox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for busybox is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'The Swiss Army Knife of Embedded Linux\n\nSecurity Fix(es):\n\nBusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.(CVE-2026-29004)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for busybox is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'busybox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for busybox is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2357', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:48+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:48+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:48+08:00', 'initial_release_date': '2026-05-15T22:05:48+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2357', 'summary': 'openEuler-SA-2026-2357', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-29004&packageName=busybox', 'summary': 'CVE-2026-29004', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-29004', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2357.json', 'summary': 'openEuler-SA-2026-2357 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'busybox-1.36.1-16.oe2403sp3.x86_64.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64.rpm', 'product': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64.rpm', 'product': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64.rpm', 'product': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-1.31.1-30.oe2003sp4.x86_64.rpm', 'product': {'name': 'busybox-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64.rpm', 'product': {'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64.rpm', 'product': {'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-help-1.31.1-30.oe2003sp4.x86_64.rpm', 'product': {'name': 'busybox-help-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-help-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64.rpm', 'product': {'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_id': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-1.34.1-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'busybox-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-help-1.34.1-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'busybox-help-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-help-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_id': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-1.36.1-16.oe2403.x86_64.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64.rpm', 'product': {'name': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.36.1-16.oe2403.x86_64.rpm', 'product': {'name': 'busybox-debugsource-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.36.1-16.oe2403.x86_64.rpm', 'product': {'name': 'busybox-petitboot-1.36.1-16.oe2403.x86_64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-1.36.1-16.oe2403sp1.x86_64.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64.rpm', 'product': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64.rpm', 'product': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64.rpm', 'product': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'busybox-help-1.36.1-16.oe2403sp3.noarch.rpm', 'product': {'name': 'busybox-help-1.36.1-16.oe2403sp3.noarch.rpm', 'product_id': 'busybox-help-1.36.1-16.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-help-1.36.1-16.oe2403.noarch.rpm', 'product': {'name': 'busybox-help-1.36.1-16.oe2403.noarch.rpm', 'product_id': 'busybox-help-1.36.1-16.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-help-1.36.1-16.oe2403sp1.noarch.rpm', 'product': {'name': 'busybox-help-1.36.1-16.oe2403sp1.noarch.rpm', 'product_id': 'busybox-help-1.36.1-16.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'busybox-1.36.1-16.oe2403sp3.aarch64.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64.rpm', 'product': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64.rpm', 'product': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64.rpm', 'product': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-1.31.1-30.oe2003sp4.aarch64.rpm', 'product': {'name': 'busybox-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64.rpm', 'product': {'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64.rpm', 'product': {'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-help-1.31.1-30.oe2003sp4.aarch64.rpm', 'product': {'name': 'busybox-help-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-help-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64.rpm', 'product': {'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_id': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-1.34.1-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'busybox-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-help-1.34.1-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'busybox-help-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-help-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_id': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-1.36.1-16.oe2403.aarch64.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64.rpm', 'product': {'name': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.36.1-16.oe2403.aarch64.rpm', 'product': {'name': 'busybox-debugsource-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.36.1-16.oe2403.aarch64.rpm', 'product': {'name': 'busybox-petitboot-1.36.1-16.oe2403.aarch64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-1.36.1-16.oe2403sp1.aarch64.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64.rpm', 'product': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64.rpm', 'product': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64.rpm', 'product': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_id': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'busybox-1.36.1-16.oe2403sp3.src.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403sp3.src.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'busybox-1.31.1-30.oe2003sp4.src.rpm', 'product': {'name': 'busybox-1.31.1-30.oe2003sp4.src.rpm', 'product_id': 'busybox-1.31.1-30.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-1.34.1-30.oe2203sp4.src.rpm', 'product': {'name': 'busybox-1.34.1-30.oe2203sp4.src.rpm', 'product_id': 'busybox-1.34.1-30.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'busybox-1.36.1-16.oe2403.src.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403.src.rpm', 'product_id': 'busybox-1.36.1-16.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'busybox-1.36.1-16.oe2403sp1.src.rpm', 'product': {'name': 'busybox-1.36.1-16.oe2403sp1.src.rpm', 'product_id': 'busybox-1.36.1-16.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-1.36.1-16.oe2403sp3.x86_64'}, 'product_reference': 'busybox-1.36.1-16.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64'}, 'product_reference': 'busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-debugsource-1.36.1-16.oe2403sp3.x86_64'}, 'product_reference': 'busybox-debugsource-1.36.1-16.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-petitboot-1.36.1-16.oe2403sp3.x86_64'}, 'product_reference': 'busybox-petitboot-1.36.1-16.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.31.1-30.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-1.31.1-30.oe2003sp4.x86_64'}, 'product_reference': 'busybox-1.31.1-30.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64'}, 'product_reference': 'busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-debugsource-1.31.1-30.oe2003sp4.x86_64'}, 'product_reference': 'busybox-debugsource-1.31.1-30.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.31.1-30.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-help-1.31.1-30.oe2003sp4.x86_64'}, 'product_reference': 'busybox-help-1.31.1-30.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-petitboot-1.31.1-30.oe2003sp4.x86_64'}, 'product_reference': 'busybox-petitboot-1.31.1-30.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.34.1-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-1.34.1-30.oe2203sp4.x86_64'}, 'product_reference': 'busybox-1.34.1-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64'}, 'product_reference': 'busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-debugsource-1.34.1-30.oe2203sp4.x86_64'}, 'product_reference': 'busybox-debugsource-1.34.1-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.34.1-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-help-1.34.1-30.oe2203sp4.x86_64'}, 'product_reference': 'busybox-help-1.34.1-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-petitboot-1.34.1-30.oe2203sp4.x86_64'}, 'product_reference': 'busybox-petitboot-1.34.1-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-1.36.1-16.oe2403.x86_64'}, 'product_reference': 'busybox-1.36.1-16.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-debuginfo-1.36.1-16.oe2403.x86_64'}, 'product_reference': 'busybox-debuginfo-1.36.1-16.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.36.1-16.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-debugsource-1.36.1-16.oe2403.x86_64'}, 'product_reference': 'busybox-debugsource-1.36.1-16.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.36.1-16.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-petitboot-1.36.1-16.oe2403.x86_64'}, 'product_reference': 'busybox-petitboot-1.36.1-16.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-1.36.1-16.oe2403sp1.x86_64'}, 'product_reference': 'busybox-1.36.1-16.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64'}, 'product_reference': 'busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-debugsource-1.36.1-16.oe2403sp1.x86_64'}, 'product_reference': 'busybox-debugsource-1.36.1-16.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-petitboot-1.36.1-16.oe2403sp1.x86_64'}, 'product_reference': 'busybox-petitboot-1.36.1-16.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.36.1-16.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-help-1.36.1-16.oe2403sp3.noarch'}, 'product_reference': 'busybox-help-1.36.1-16.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.36.1-16.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-help-1.36.1-16.oe2403.noarch'}, 'product_reference': 'busybox-help-1.36.1-16.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.36.1-16.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-help-1.36.1-16.oe2403sp1.noarch'}, 'product_reference': 'busybox-help-1.36.1-16.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-1.36.1-16.oe2403sp3.aarch64'}, 'product_reference': 'busybox-1.36.1-16.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64'}, 'product_reference': 'busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-debugsource-1.36.1-16.oe2403sp3.aarch64'}, 'product_reference': 'busybox-debugsource-1.36.1-16.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-petitboot-1.36.1-16.oe2403sp3.aarch64'}, 'product_reference': 'busybox-petitboot-1.36.1-16.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.31.1-30.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-1.31.1-30.oe2003sp4.aarch64'}, 'product_reference': 'busybox-1.31.1-30.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64'}, 'product_reference': 'busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-debugsource-1.31.1-30.oe2003sp4.aarch64'}, 'product_reference': 'busybox-debugsource-1.31.1-30.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.31.1-30.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-help-1.31.1-30.oe2003sp4.aarch64'}, 'product_reference': 'busybox-help-1.31.1-30.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-petitboot-1.31.1-30.oe2003sp4.aarch64'}, 'product_reference': 'busybox-petitboot-1.31.1-30.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.34.1-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-1.34.1-30.oe2203sp4.aarch64'}, 'product_reference': 'busybox-1.34.1-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64'}, 'product_reference': 'busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-debugsource-1.34.1-30.oe2203sp4.aarch64'}, 'product_reference': 'busybox-debugsource-1.34.1-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-help-1.34.1-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-help-1.34.1-30.oe2203sp4.aarch64'}, 'product_reference': 'busybox-help-1.34.1-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-petitboot-1.34.1-30.oe2203sp4.aarch64'}, 'product_reference': 'busybox-petitboot-1.34.1-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-1.36.1-16.oe2403.aarch64'}, 'product_reference': 'busybox-1.36.1-16.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-debuginfo-1.36.1-16.oe2403.aarch64'}, 'product_reference': 'busybox-debuginfo-1.36.1-16.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.36.1-16.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-debugsource-1.36.1-16.oe2403.aarch64'}, 'product_reference': 'busybox-debugsource-1.36.1-16.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.36.1-16.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-petitboot-1.36.1-16.oe2403.aarch64'}, 'product_reference': 'busybox-petitboot-1.36.1-16.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-1.36.1-16.oe2403sp1.aarch64'}, 'product_reference': 'busybox-1.36.1-16.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64'}, 'product_reference': 'busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-debugsource-1.36.1-16.oe2403sp1.aarch64'}, 'product_reference': 'busybox-debugsource-1.36.1-16.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-petitboot-1.36.1-16.oe2403sp1.aarch64'}, 'product_reference': 'busybox-petitboot-1.36.1-16.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:busybox-1.36.1-16.oe2403sp3.src'}, 'product_reference': 'busybox-1.36.1-16.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.31.1-30.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:busybox-1.31.1-30.oe2003sp4.src'}, 'product_reference': 'busybox-1.31.1-30.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.34.1-30.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:busybox-1.34.1-30.oe2203sp4.src'}, 'product_reference': 'busybox-1.34.1-30.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:busybox-1.36.1-16.oe2403.src'}, 'product_reference': 'busybox-1.36.1-16.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'busybox-1.36.1-16.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:busybox-1.36.1-16.oe2403sp1.src'}, 'product_reference': 'busybox-1.36.1-16.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-29004', 'notes': [{'text': 'BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-29004', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2357', 'details': 'busybox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:busybox-1.36.1-16.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:busybox-debuginfo-1.36.1-16.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:busybox-debugsource-1.36.1-16.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:busybox-petitboot-1.36.1-16.oe2403sp3.x86_64', 'openEuler-20.03-LTS-SP4:busybox-1.31.1-30.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:busybox-debuginfo-1.31.1-30.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:busybox-debugsource-1.31.1-30.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:busybox-help-1.31.1-30.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:busybox-petitboot-1.31.1-30.oe2003sp4.x86_64', 'openEuler-22.03-LTS-SP4:busybox-1.34.1-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:busybox-debuginfo-1.34.1-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:busybox-debugsource-1.34.1-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:busybox-help-1.34.1-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:busybox-petitboot-1.34.1-30.oe2203sp4.x86_64', 'openEuler-24.03-LTS:busybox-1.36.1-16.oe2403.x86_64', 'openEuler-24.03-LTS:busybox-debuginfo-1.36.1-16.oe2403.x86_64', 'openEuler-24.03-LTS:busybox-debugsource-1.36.1-16.oe2403.x86_64', 'openEuler-24.03-LTS:busybox-petitboot-1.36.1-16.oe2403.x86_64', 'openEuler-24.03-LTS-SP1:busybox-1.36.1-16.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:busybox-debuginfo-1.36.1-16.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:busybox-debugsource-1.36.1-16.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:busybox-petitboot-1.36.1-16.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP3:busybox-help-1.36.1-16.oe2403sp3.noarch', 'openEuler-24.03-LTS:busybox-help-1.36.1-16.oe2403.noarch', 'openEuler-24.03-LTS-SP1:busybox-help-1.36.1-16.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP3:busybox-1.36.1-16.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:busybox-debuginfo-1.36.1-16.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:busybox-debugsource-1.36.1-16.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:busybox-petitboot-1.36.1-16.oe2403sp3.aarch64', 'openEuler-20.03-LTS-SP4:busybox-1.31.1-30.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:busybox-debuginfo-1.31.1-30.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:busybox-debugsource-1.31.1-30.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:busybox-help-1.31.1-30.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:busybox-petitboot-1.31.1-30.oe2003sp4.aarch64', 'openEuler-22.03-LTS-SP4:busybox-1.34.1-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:busybox-debuginfo-1.34.1-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:busybox-debugsource-1.34.1-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:busybox-help-1.34.1-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:busybox-petitboot-1.34.1-30.oe2203sp4.aarch64', 'openEuler-24.03-LTS:busybox-1.36.1-16.oe2403.aarch64', 'openEuler-24.03-LTS:busybox-debuginfo-1.36.1-16.oe2403.aarch64', 'openEuler-24.03-LTS:busybox-debugsource-1.36.1-16.oe2403.aarch64', 'openEuler-24.03-LTS:busybox-petitboot-1.36.1-16.oe2403.aarch64', 'openEuler-24.03-LTS-SP1:busybox-1.36.1-16.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:busybox-debuginfo-1.36.1-16.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:busybox-debugsource-1.36.1-16.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:busybox-petitboot-1.36.1-16.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP3:busybox-1.36.1-16.oe2403sp3.src', 'openEuler-20.03-LTS-SP4:busybox-1.31.1-30.oe2003sp4.src', 'openEuler-22.03-LTS-SP4:busybox-1.34.1-30.oe2203sp4.src', 'openEuler-24.03-LTS:busybox-1.36.1-16.oe2403.src', 'openEuler-24.03-LTS-SP1:busybox-1.36.1-16.oe2403sp1.src']}}]}
bbe9e3260d0de9fa660b1e303ffddba2a90babc5dc14298069354d88783e296b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2358
An update for systemd is now available for openEuler-20.03-LTS-SP4
Medium
2026-05-15 17:05:48+03:00
2026-05-15 17:05:48+03:00
['CVE-2026-40226']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-container-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-container-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-debuginfo-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-debuginfo-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-debugsource-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-debugsource-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-devel-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-devel-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-journal-remote-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-journal-remote-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-libs-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-libs-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-udev-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-udev-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-udev-compat-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-udev-compat-243-90.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-243-90.oe2003sp4.src.rpm', 'product_id': 'systemd-243-90.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-container-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-container-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-debuginfo-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-debuginfo-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-debugsource-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-debugsource-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-devel-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-devel-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-journal-remote-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-journal-remote-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-libs-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-libs-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-udev-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-udev-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-udev-compat-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-udev-compat-243-90.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'systemd-help-243-90.oe2003sp4.noarch.rpm', 'product_id': 'systemd-help-243-90.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2358', 'summary': 'openEuler-SA-2026-2358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40226&packageName=systemd', 'summary': 'CVE-2026-40226', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40226', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2358.json', 'summary': 'openEuler-SA-2026-2358 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'systemd security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for systemd is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'systemd is a system and service manager that runs as PID 1 and starts the rest of the system.\n\nSecurity Fix(es):\n\nIn nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.(CVE-2026-40226)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for systemd is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'systemd', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for systemd is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2358', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-15T22:05:48+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-15T22:05:48+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-15T22:05:48+08:00', 'initial_release_date': '2026-05-15T22:05:48+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2358', 'summary': 'openEuler-SA-2026-2358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40226&packageName=systemd', 'summary': 'CVE-2026-40226', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40226', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2358.json', 'summary': 'openEuler-SA-2026-2358 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'systemd-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-container-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-container-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-container-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-debuginfo-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-debuginfo-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-debuginfo-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-debugsource-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-debugsource-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-debugsource-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-devel-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-devel-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-devel-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-journal-remote-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-journal-remote-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-journal-remote-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-libs-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-libs-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-libs-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-udev-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-udev-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-udev-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-udev-compat-243-90.oe2003sp4.aarch64.rpm', 'product': {'name': 'systemd-udev-compat-243-90.oe2003sp4.aarch64.rpm', 'product_id': 'systemd-udev-compat-243-90.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'systemd-243-90.oe2003sp4.src.rpm', 'product': {'name': 'systemd-243-90.oe2003sp4.src.rpm', 'product_id': 'systemd-243-90.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'systemd-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-container-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-container-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-container-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-debuginfo-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-debuginfo-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-debuginfo-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-debugsource-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-debugsource-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-debugsource-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-devel-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-devel-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-devel-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-journal-remote-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-journal-remote-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-journal-remote-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-libs-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-libs-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-libs-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-udev-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-udev-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-udev-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'systemd-udev-compat-243-90.oe2003sp4.x86_64.rpm', 'product': {'name': 'systemd-udev-compat-243-90.oe2003sp4.x86_64.rpm', 'product_id': 'systemd-udev-compat-243-90.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'systemd-help-243-90.oe2003sp4.noarch.rpm', 'product': {'name': 'systemd-help-243-90.oe2003sp4.noarch.rpm', 'product_id': 'systemd-help-243-90.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'systemd-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-container-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-container-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-container-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-debuginfo-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-debuginfo-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-debuginfo-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-debugsource-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-debugsource-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-debugsource-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-devel-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-devel-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-devel-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-journal-remote-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-journal-remote-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-journal-remote-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-libs-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-libs-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-libs-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-udev-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-udev-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-udev-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-udev-compat-243-90.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-udev-compat-243-90.oe2003sp4.aarch64'}, 'product_reference': 'systemd-udev-compat-243-90.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-243-90.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-243-90.oe2003sp4.src'}, 'product_reference': 'systemd-243-90.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-container-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-container-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-container-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-debuginfo-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-debuginfo-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-debuginfo-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-debugsource-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-debugsource-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-debugsource-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-devel-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-devel-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-devel-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-journal-remote-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-journal-remote-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-journal-remote-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-libs-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-libs-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-libs-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-udev-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-udev-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-udev-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-udev-compat-243-90.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-udev-compat-243-90.oe2003sp4.x86_64'}, 'product_reference': 'systemd-udev-compat-243-90.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'systemd-help-243-90.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:systemd-help-243-90.oe2003sp4.noarch'}, 'product_reference': 'systemd-help-243-90.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40226', 'notes': [{'text': 'In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40226', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2358', 'details': 'systemd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:systemd-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-container-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-debuginfo-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-debugsource-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-devel-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-journal-remote-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-libs-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-udev-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-udev-compat-243-90.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:systemd-243-90.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:systemd-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-container-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-debuginfo-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-debugsource-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-devel-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-journal-remote-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-libs-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-udev-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-udev-compat-243-90.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:systemd-help-243-90.oe2003sp4.noarch']}}]}
500f2533e28f7df476ccf278edcb6318a60c4530f12dc1c47b4de7851590e4b9
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2359
An update for runc is now available for openEuler-22.03-LTS-SP4
High
2026-05-22 16:21:53+03:00
2026-05-22 16:21:53+03:00
['CVE-2025-65637']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'runc-1.1.3-37.oe2203sp4.x86_64.rpm', 'product_id': 'runc-1.1.3-37.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'runc-1.1.3-37.oe2203sp4.aarch64.rpm', 'product_id': 'runc-1.1.3-37.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'runc-1.1.3-37.oe2203sp4.src.rpm', 'product_id': 'runc-1.1.3-37.oe2203sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2359', 'summary': 'openEuler-SA-2026-2359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-65637&packageName=runc', 'summary': 'CVE-2025-65637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-65637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2359.json', 'summary': 'openEuler-SA-2026-2359 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'runc security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for runc is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'runc is a CLI tool for spawning and running containers according to the OCI specification.\n\nSecurity Fix(es):\n\nA denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.(CVE-2025-65637)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for runc is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'runc', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for runc is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2359', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:53+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:53+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:53+08:00', 'initial_release_date': '2026-05-22T21:21:53+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2359', 'summary': 'openEuler-SA-2026-2359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-65637&packageName=runc', 'summary': 'CVE-2025-65637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-65637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2359.json', 'summary': 'openEuler-SA-2026-2359 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'runc-1.1.3-37.oe2203sp4.x86_64.rpm', 'product': {'name': 'runc-1.1.3-37.oe2203sp4.x86_64.rpm', 'product_id': 'runc-1.1.3-37.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'runc-1.1.3-37.oe2203sp4.aarch64.rpm', 'product': {'name': 'runc-1.1.3-37.oe2203sp4.aarch64.rpm', 'product_id': 'runc-1.1.3-37.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'runc-1.1.3-37.oe2203sp4.src.rpm', 'product': {'name': 'runc-1.1.3-37.oe2203sp4.src.rpm', 'product_id': 'runc-1.1.3-37.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'runc-1.1.3-37.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:runc-1.1.3-37.oe2203sp4.x86_64'}, 'product_reference': 'runc-1.1.3-37.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'runc-1.1.3-37.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:runc-1.1.3-37.oe2203sp4.aarch64'}, 'product_reference': 'runc-1.1.3-37.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'runc-1.1.3-37.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:runc-1.1.3-37.oe2203sp4.src'}, 'product_reference': 'runc-1.1.3-37.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-65637', 'notes': [{'text': 'A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-65637', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2359', 'details': 'runc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:runc-1.1.3-37.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:runc-1.1.3-37.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:runc-1.1.3-37.oe2203sp4.src']}}]}
e40447a8599ba3c7c22138c685894ac13702c1147bf05ee509ae51f4ee44233a
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2360
An update for python-pip is now available for openEuler-24.03-LTS
Medium
2026-05-22 16:21:54+03:00
2026-05-22 16:21:54+03:00
['CVE-2026-3219']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pip-23.3.1-11.oe2403.src.rpm', 'product_id': 'python-pip-23.3.1-11.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pip-help-23.3.1-11.oe2403.noarch.rpm', 'product_id': 'python-pip-help-23.3.1-11.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pip-wheel-23.3.1-11.oe2403.noarch.rpm', 'product_id': 'python-pip-wheel-23.3.1-11.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pip-23.3.1-11.oe2403.noarch.rpm', 'product_id': 'python3-pip-23.3.1-11.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2360', 'summary': 'openEuler-SA-2026-2360', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2360.json', 'summary': 'openEuler-SA-2026-2360 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-pip security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': '%changelog * Thu Apr 9 2026 yixiangzhike &lt;yixiangzhike007@163.com&gt; - 23.3.1-10 - Fix CVE-2026-25645\n\nSecurity Fix(es):\n\npip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.(CVE-2026-3219)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'python-pip', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-pip is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2360', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:54+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:54+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:54+08:00', 'initial_release_date': '2026-05-22T21:21:54+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2360', 'summary': 'openEuler-SA-2026-2360', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2360.json', 'summary': 'openEuler-SA-2026-2360 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-pip-23.3.1-11.oe2403.src.rpm', 'product': {'name': 'python-pip-23.3.1-11.oe2403.src.rpm', 'product_id': 'python-pip-23.3.1-11.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python-pip-help-23.3.1-11.oe2403.noarch.rpm', 'product': {'name': 'python-pip-help-23.3.1-11.oe2403.noarch.rpm', 'product_id': 'python-pip-help-23.3.1-11.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python-pip-wheel-23.3.1-11.oe2403.noarch.rpm', 'product': {'name': 'python-pip-wheel-23.3.1-11.oe2403.noarch.rpm', 'product_id': 'python-pip-wheel-23.3.1-11.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pip-23.3.1-11.oe2403.noarch.rpm', 'product': {'name': 'python3-pip-23.3.1-11.oe2403.noarch.rpm', 'product_id': 'python3-pip-23.3.1-11.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-23.3.1-11.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pip-23.3.1-11.oe2403.src'}, 'product_reference': 'python-pip-23.3.1-11.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-help-23.3.1-11.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pip-help-23.3.1-11.oe2403.noarch'}, 'product_reference': 'python-pip-help-23.3.1-11.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-wheel-23.3.1-11.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pip-wheel-23.3.1-11.oe2403.noarch'}, 'product_reference': 'python-pip-wheel-23.3.1-11.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pip-23.3.1-11.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pip-23.3.1-11.oe2403.noarch'}, 'product_reference': 'python3-pip-23.3.1-11.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3219', 'notes': [{'text': 'pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3219', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2360', 'details': 'python-pip security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:python-pip-23.3.1-11.oe2403.src', 'openEuler-24.03-LTS:python-pip-help-23.3.1-11.oe2403.noarch', 'openEuler-24.03-LTS:python-pip-wheel-23.3.1-11.oe2403.noarch', 'openEuler-24.03-LTS:python3-pip-23.3.1-11.oe2403.noarch']}}]}
fcff4be56aa5ff352fb63f99fa2aa322f95732c08dcab643861cbe80b8e7ea80
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2361
An update for python-pip is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-22 16:21:54+03:00
2026-05-22 16:21:54+03:00
['CVE-2026-3219']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pip-23.3.1-11.oe2403sp3.src.rpm', 'product_id': 'python-pip-23.3.1-11.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pip-help-23.3.1-11.oe2403sp3.noarch.rpm', 'product_id': 'python-pip-help-23.3.1-11.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch.rpm', 'product_id': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pip-23.3.1-11.oe2403sp3.noarch.rpm', 'product_id': 'python3-pip-23.3.1-11.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2361', 'summary': 'openEuler-SA-2026-2361', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2361.json', 'summary': 'openEuler-SA-2026-2361 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-pip security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': '%changelog * Thu Apr 9 2026 yixiangzhike &lt;yixiangzhike007@163.com&gt; - 23.3.1-10 - Fix CVE-2026-25645\n\nSecurity Fix(es):\n\npip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.(CVE-2026-3219)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'python-pip', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-pip is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2361', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:54+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:54+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:54+08:00', 'initial_release_date': '2026-05-22T21:21:54+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2361', 'summary': 'openEuler-SA-2026-2361', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2361.json', 'summary': 'openEuler-SA-2026-2361 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-pip-23.3.1-11.oe2403sp3.src.rpm', 'product': {'name': 'python-pip-23.3.1-11.oe2403sp3.src.rpm', 'product_id': 'python-pip-23.3.1-11.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python-pip-help-23.3.1-11.oe2403sp3.noarch.rpm', 'product': {'name': 'python-pip-help-23.3.1-11.oe2403sp3.noarch.rpm', 'product_id': 'python-pip-help-23.3.1-11.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch.rpm', 'product': {'name': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch.rpm', 'product_id': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pip-23.3.1-11.oe2403sp3.noarch.rpm', 'product': {'name': 'python3-pip-23.3.1-11.oe2403sp3.noarch.rpm', 'product_id': 'python3-pip-23.3.1-11.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-23.3.1-11.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pip-23.3.1-11.oe2403sp3.src'}, 'product_reference': 'python-pip-23.3.1-11.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-help-23.3.1-11.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pip-help-23.3.1-11.oe2403sp3.noarch'}, 'product_reference': 'python-pip-help-23.3.1-11.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pip-wheel-23.3.1-11.oe2403sp3.noarch'}, 'product_reference': 'python-pip-wheel-23.3.1-11.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pip-23.3.1-11.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pip-23.3.1-11.oe2403sp3.noarch'}, 'product_reference': 'python3-pip-23.3.1-11.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3219', 'notes': [{'text': 'pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3219', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2361', 'details': 'python-pip security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:python-pip-23.3.1-11.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:python-pip-help-23.3.1-11.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:python-pip-wheel-23.3.1-11.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:python3-pip-23.3.1-11.oe2403sp3.noarch']}}]}
9f7911c38782e8b1c33e90c4c3e16796c6b4d7677a460c02bc9c04c608a3c4b0
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2362
An update for python-pip is now available for openEuler-20.03-LTS-SP4
Medium
2026-05-22 16:21:54+03:00
2026-05-22 16:21:54+03:00
['CVE-2026-3219']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python-pip-20.2.2-17.oe2003sp4.src.rpm', 'product_id': 'python-pip-20.2.2-17.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python-pip-help-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python-pip-help-20.2.2-17.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python2-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python2-pip-20.2.2-17.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python3-pip-20.2.2-17.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2362', 'summary': 'openEuler-SA-2026-2362', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2362.json', 'summary': 'openEuler-SA-2026-2362 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-pip security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': '%changelog * Thu Apr 9 2026 yixiangzhike &lt;yixiangzhike007@163.com&gt; - 23.3.1-10 - Fix CVE-2026-25645\n\nSecurity Fix(es):\n\npip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.(CVE-2026-3219)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'python-pip', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-pip is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2362', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:54+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:54+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:54+08:00', 'initial_release_date': '2026-05-22T21:21:54+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2362', 'summary': 'openEuler-SA-2026-2362', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2362.json', 'summary': 'openEuler-SA-2026-2362 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-pip-20.2.2-17.oe2003sp4.src.rpm', 'product': {'name': 'python-pip-20.2.2-17.oe2003sp4.src.rpm', 'product_id': 'python-pip-20.2.2-17.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python-pip-help-20.2.2-17.oe2003sp4.noarch.rpm', 'product': {'name': 'python-pip-help-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python-pip-help-20.2.2-17.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch.rpm', 'product': {'name': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python2-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product': {'name': 'python2-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python2-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product': {'name': 'python3-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product_id': 'python3-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-20.2.2-17.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python-pip-20.2.2-17.oe2003sp4.src'}, 'product_reference': 'python-pip-20.2.2-17.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-help-20.2.2-17.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python-pip-help-20.2.2-17.oe2003sp4.noarch'}, 'product_reference': 'python-pip-help-20.2.2-17.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python-pip-wheel-20.2.2-17.oe2003sp4.noarch'}, 'product_reference': 'python-pip-wheel-20.2.2-17.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python2-pip-20.2.2-17.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python2-pip-20.2.2-17.oe2003sp4.noarch'}, 'product_reference': 'python2-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pip-20.2.2-17.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-pip-20.2.2-17.oe2003sp4.noarch'}, 'product_reference': 'python3-pip-20.2.2-17.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3219', 'notes': [{'text': 'pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3219', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2362', 'details': 'python-pip security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:python-pip-20.2.2-17.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:python-pip-help-20.2.2-17.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:python-pip-wheel-20.2.2-17.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:python2-pip-20.2.2-17.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:python3-pip-20.2.2-17.oe2003sp4.noarch']}}]}
4e939a786832ad20c6d8486260fd695a5ca1f8fe7cbef71aa9a0ebfb23ad5da9
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2363
An update for python-pip is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-22 16:21:54+03:00
2026-05-22 16:21:54+03:00
['CVE-2026-3219']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python-pip-21.3.1-16.oe2203sp4.src.rpm', 'product_id': 'python-pip-21.3.1-16.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python-pip-help-21.3.1-16.oe2203sp4.noarch.rpm', 'product_id': 'python-pip-help-21.3.1-16.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch.rpm', 'product_id': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-pip-21.3.1-16.oe2203sp4.noarch.rpm', 'product_id': 'python3-pip-21.3.1-16.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2363', 'summary': 'openEuler-SA-2026-2363', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2363.json', 'summary': 'openEuler-SA-2026-2363 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-pip security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': '%changelog * Thu Apr 9 2026 yixiangzhike &lt;yixiangzhike007@163.com&gt; - 23.3.1-10 - Fix CVE-2026-25645\n\nSecurity Fix(es):\n\npip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.(CVE-2026-3219)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-pip is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'python-pip', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-pip is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2363', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:54+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:54+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:54+08:00', 'initial_release_date': '2026-05-22T21:21:54+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2363', 'summary': 'openEuler-SA-2026-2363', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3219&packageName=python-pip', 'summary': 'CVE-2026-3219', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2363.json', 'summary': 'openEuler-SA-2026-2363 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-pip-21.3.1-16.oe2203sp4.src.rpm', 'product': {'name': 'python-pip-21.3.1-16.oe2203sp4.src.rpm', 'product_id': 'python-pip-21.3.1-16.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python-pip-help-21.3.1-16.oe2203sp4.noarch.rpm', 'product': {'name': 'python-pip-help-21.3.1-16.oe2203sp4.noarch.rpm', 'product_id': 'python-pip-help-21.3.1-16.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch.rpm', 'product': {'name': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch.rpm', 'product_id': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-pip-21.3.1-16.oe2203sp4.noarch.rpm', 'product': {'name': 'python3-pip-21.3.1-16.oe2203sp4.noarch.rpm', 'product_id': 'python3-pip-21.3.1-16.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-21.3.1-16.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python-pip-21.3.1-16.oe2203sp4.src'}, 'product_reference': 'python-pip-21.3.1-16.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-help-21.3.1-16.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-16.oe2203sp4.noarch'}, 'product_reference': 'python-pip-help-21.3.1-16.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-16.oe2203sp4.noarch'}, 'product_reference': 'python-pip-wheel-21.3.1-16.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pip-21.3.1-16.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-pip-21.3.1-16.oe2203sp4.noarch'}, 'product_reference': 'python3-pip-21.3.1-16.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3219', 'notes': [{'text': 'pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3219', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2363', 'details': 'python-pip security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:python-pip-21.3.1-16.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-16.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-16.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:python3-pip-21.3.1-16.oe2203sp4.noarch']}}]}
c1100c2fc78e6bf396fbc421f10f1de4de67f7cbc432fe2aa0b574991b7dd61b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2364
An update for OpenEXR is now available for openEuler-22.03-LTS-SP4
Critical
2026-05-22 16:21:55+03:00
2026-05-22 16:21:55+03:00
['CVE-2026-41142', 'CVE-2026-42216', 'CVE-2026-42217']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-3.1.5-7.oe2203sp4.src.rpm', 'product_id': 'OpenEXR-3.1.5-7.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2364', 'summary': 'openEuler-SA-2026-2364', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41142&packageName=OpenEXR', 'summary': 'CVE-2026-41142', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42216&packageName=OpenEXR', 'summary': 'CVE-2026-42216', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42217&packageName=OpenEXR', 'summary': 'CVE-2026-42217', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41142', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42216', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2364.json', 'summary': 'openEuler-SA-2026-2364 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'OpenEXR security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for OpenEXR is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp; Magic for use in computer imaging applications.\n\nSecurity Fix(es):\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-41142)\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42216)\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42217)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for OpenEXR is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'OpenEXR', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for OpenEXR is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2364', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:55+08:00', 'initial_release_date': '2026-05-22T21:21:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2364', 'summary': 'openEuler-SA-2026-2364', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41142&packageName=OpenEXR', 'summary': 'CVE-2026-41142', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42216&packageName=OpenEXR', 'summary': 'CVE-2026-42216', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42217&packageName=OpenEXR', 'summary': 'CVE-2026-42217', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41142', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42216', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2364.json', 'summary': 'openEuler-SA-2026-2364 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64.rpm', 'product': {'name': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64.rpm', 'product': {'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64.rpm', 'product': {'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64.rpm', 'product': {'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64.rpm', 'product': {'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_id': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'OpenEXR-3.1.5-7.oe2203sp4.src.rpm', 'product': {'name': 'OpenEXR-3.1.5-7.oe2203sp4.src.rpm', 'product_id': 'OpenEXR-3.1.5-7.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64.rpm', 'product': {'name': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64.rpm', 'product': {'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64.rpm', 'product': {'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64.rpm', 'product': {'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64.rpm', 'product': {'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_id': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-3.1.5-7.oe2203sp4.aarch64'}, 'product_reference': 'OpenEXR-3.1.5-7.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64'}, 'product_reference': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64'}, 'product_reference': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64'}, 'product_reference': 'OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64'}, 'product_reference': 'OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.5-7.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-3.1.5-7.oe2203sp4.src'}, 'product_reference': 'OpenEXR-3.1.5-7.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-3.1.5-7.oe2203sp4.x86_64'}, 'product_reference': 'OpenEXR-3.1.5-7.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64'}, 'product_reference': 'OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64'}, 'product_reference': 'OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64'}, 'product_reference': 'OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64'}, 'product_reference': 'OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41142', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41142', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2364', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:OpenEXR-3.1.5-7.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:OpenEXR-debuginfo-3.1.5-7.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:OpenEXR-debugsource-3.1.5-7.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:OpenEXR-devel-3.1.5-7.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:OpenEXR-libs-3.1.5-7.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:OpenEXR-3.1.5-7.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:OpenEXR-3.1.5-7.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:OpenEXR-debuginfo-3.1.5-7.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:OpenEXR-debugsource-3.1.5-7.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:OpenEXR-devel-3.1.5-7.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:OpenEXR-libs-3.1.5-7.oe2203sp4.x86_64']}}, {'cve': 'CVE-2026-42216', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42216', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2364', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42217', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42217', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2364', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
38a098d92938d1b205a96c3ef0483c26a1157ad9c44390db233ae8474eef01de
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2025-1037
An update for kernel is now available for openEuler-22.03-LTS-SP4
High
2025-01-10 16:10:50+03:00
2025-01-10 16:10:50+03:00
['CVE-2022-49034', 'CVE-2024-47730', 'CVE-2024-49907', 'CVE-2024-50001', 'CVE-2024-50188', 'CVE-2024-50233', 'CVE-2024-50264', 'CVE-2024-53146', 'CVE-2024-53147', 'CVE-2024-53155', 'CVE-2024-53158', 'CVE-2024-53161', 'CVE-2024-53165', 'CVE-2024-53173', 'CVE-2024-53185', 'CVE-2024-53187', 'CVE-2024-53194', 'CVE-2024-53197', 'CVE-2024-53217', 'CVE-2024-53218', 'CVE-2024-53219', 'CVE-2024-53221', 'CVE-2024-53224', 'CVE-2024-53227', 'CVE-2024-56538', 'CVE-2024-56548', 'CVE-2024-56562', 'CVE-2024-56569', 'CVE-2024-56570', 'CVE-2024-56572', 'CVE-2024-56581', 'CVE-2024-56583', 'CVE-2024-56584', 'CVE-2024-56586', 'CVE-2024-56594', 'CVE-2024-56596', 'CVE-2024-56598', 'CVE-2024-56604', 'CVE-2024-56605', 'CVE-2024-56608', 'CVE-2024-56615', 'CVE-2024-56619', 'CVE-2024-56627', 'CVE-2024-56629', 'CVE-2024-56672', 'CVE-2024-56681', 'CVE-2024-56686', 'CVE-2024-56691', 'CVE-2024-56692', 'CVE-2024-56700', 'CVE-2024-56709', 'CVE-2024-56739', 'CVE-2024-56741', 'CVE-2024-56747', 'CVE-2024-56748', 'CVE-2024-56756', 'CVE-2024-56763']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src.rpm', 'product_id': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'summary': 'openEuler-SA-2025-1037', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2022-49034&packageName=kernel', 'summary': 'CVE-2022-49034', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-47730&packageName=kernel', 'summary': 'CVE-2024-47730', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-49907&packageName=kernel', 'summary': 'CVE-2024-49907', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50001&packageName=kernel', 'summary': 'CVE-2024-50001', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50188&packageName=kernel', 'summary': 'CVE-2024-50188', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50233&packageName=kernel', 'summary': 'CVE-2024-50233', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50264&packageName=kernel', 'summary': 'CVE-2024-50264', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53146&packageName=kernel', 'summary': 'CVE-2024-53146', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53147&packageName=kernel', 'summary': 'CVE-2024-53147', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53155&packageName=kernel', 'summary': 'CVE-2024-53155', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53158&packageName=kernel', 'summary': 'CVE-2024-53158', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53161&packageName=kernel', 'summary': 'CVE-2024-53161', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53165&packageName=kernel', 'summary': 'CVE-2024-53165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53173&packageName=kernel', 'summary': 'CVE-2024-53173', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53185&packageName=kernel', 'summary': 'CVE-2024-53185', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53187&packageName=kernel', 'summary': 'CVE-2024-53187', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53194&packageName=kernel', 'summary': 'CVE-2024-53194', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53197&packageName=kernel', 'summary': 'CVE-2024-53197', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53217&packageName=kernel', 'summary': 'CVE-2024-53217', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53218&packageName=kernel', 'summary': 'CVE-2024-53218', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53219&packageName=kernel', 'summary': 'CVE-2024-53219', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53221&packageName=kernel', 'summary': 'CVE-2024-53221', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53224&packageName=kernel', 'summary': 'CVE-2024-53224', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53227&packageName=kernel', 'summary': 'CVE-2024-53227', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56538&packageName=kernel', 'summary': 'CVE-2024-56538', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56548&packageName=kernel', 'summary': 'CVE-2024-56548', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56562&packageName=kernel', 'summary': 'CVE-2024-56562', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56569&packageName=kernel', 'summary': 'CVE-2024-56569', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56570&packageName=kernel', 'summary': 'CVE-2024-56570', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56572&packageName=kernel', 'summary': 'CVE-2024-56572', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56581&packageName=kernel', 'summary': 'CVE-2024-56581', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56583&packageName=kernel', 'summary': 'CVE-2024-56583', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56584&packageName=kernel', 'summary': 'CVE-2024-56584', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56586&packageName=kernel', 'summary': 'CVE-2024-56586', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56594&packageName=kernel', 'summary': 'CVE-2024-56594', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56596&packageName=kernel', 'summary': 'CVE-2024-56596', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56598&packageName=kernel', 'summary': 'CVE-2024-56598', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56604&packageName=kernel', 'summary': 'CVE-2024-56604', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56605&packageName=kernel', 'summary': 'CVE-2024-56605', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56608&packageName=kernel', 'summary': 'CVE-2024-56608', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56615&packageName=kernel', 'summary': 'CVE-2024-56615', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56619&packageName=kernel', 'summary': 'CVE-2024-56619', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56627&packageName=kernel', 'summary': 'CVE-2024-56627', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56629&packageName=kernel', 'summary': 'CVE-2024-56629', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56672&packageName=kernel', 'summary': 'CVE-2024-56672', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56681&packageName=kernel', 'summary': 'CVE-2024-56681', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56686&packageName=kernel', 'summary': 'CVE-2024-56686', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56691&packageName=kernel', 'summary': 'CVE-2024-56691', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56692&packageName=kernel', 'summary': 'CVE-2024-56692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56700&packageName=kernel', 'summary': 'CVE-2024-56700', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56709&packageName=kernel', 'summary': 'CVE-2024-56709', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56739&packageName=kernel', 'summary': 'CVE-2024-56739', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56741&packageName=kernel', 'summary': 'CVE-2024-56741', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56747&packageName=kernel', 'summary': 'CVE-2024-56747', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56748&packageName=kernel', 'summary': 'CVE-2024-56748', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56756&packageName=kernel', 'summary': 'CVE-2024-56756', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56763&packageName=kernel', 'summary': 'CVE-2024-56763', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2022-49034', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-47730', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-49907', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50001', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50188', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50233', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50264', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53146', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53147', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53155', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53158', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53161', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53173', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53185', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53187', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53194', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53197', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53218', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53221', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53224', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53227', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56538', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56548', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56562', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56569', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56570', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56572', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56581', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56583', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56584', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56586', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56594', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56596', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56598', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56605', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56608', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56615', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56619', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56627', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56629', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56672', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56681', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56686', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56691', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56700', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56709', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56739', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56741', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56747', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56748', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56756', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56763', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2025/csaf-openeuler-sa-2025-1037.json', 'summary': 'openEuler-SA-2025-1037 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'kernel security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'The Linux Kernel, the operating system core itself.\n\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning similar as below when showing /proc/cpuinfo. Fix this by using nr_cpu_ids (the runtime limit) instead of NR_CPUS to iterate CPUs. [ 3.052463] ------------[ cut here ]------------ [ 3.059679] WARNING: CPU: 3 PID: 1 at include/linux/cpumask.h:108 show_cpuinfo+0x5e8/0x5f0 [ 3.070072] Modules linked in: efivarfs autofs4 [ 3.076257] CPU: 0 PID: 1 Comm: systemd Not tainted 5.19-rc5+ #1052 [ 3.099465] Stack : 9000000100157b08 9000000000f18530 9000000000cf846c 9000000100154000 [ 3.109127] 9000000100157a50 0000000000000000 9000000100157a58 9000000000ef7430 [ 3.118774] 90000001001578e8 0000000000000040 0000000000000020 ffffffffffffffff [ 3.128412] 0000000000aaaaaa 1ab25f00eec96a37 900000010021de80 900000000101c890 [ 3.138056] 0000000000000000 0000000000000000 0000000000000000 0000000000aaaaaa [ 3.147711] ffff8000339dc220 0000000000000001 0000000006ab4000 0000000000000000 [ 3.157364] 900000000101c998 0000000000000004 9000000000ef7430 0000000000000000 [ 3.167012] 0000000000000009 000000000000006c 0000000000000000 0000000000000000 [ 3.176641] 9000000000d3de08 9000000001639390 90000000002086d8 00007ffff0080286 [ 3.186260] 00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c [ 3.195868] ... [ 3.199917] Call Trace: [ 3.203941] [<90000000002086d8>] show_stack+0x38/0x14c [ 3.210666] [<9000000000cf846c>] dump_stack_lvl+0x60/0x88 [ 3.217625] [<900000000023d268>] __warn+0xd0/0x100 [ 3.223958] [<9000000000cf3c90>] warn_slowpath_fmt+0x7c/0xcc [ 3.231150] [<9000000000210220>] show_cpuinfo+0x5e8/0x5f0 [ 3.238080] [<90000000004f578c>] seq_read_iter+0x354/0x4b4 [ 3.245098] [<90000000004c2e90>] new_sync_read+0x17c/0x1c4 [ 3.252114] [<90000000004c5174>] vfs_read+0x138/0x1d0 [ 3.258694] [<90000000004c55f8>] ksys_read+0x70/0x100 [ 3.265265] [<9000000000cfde9c>] do_syscall+0x7c/0x94 [ 3.271820] [<9000000000202fe4>] handle_syscall+0xc4/0x160 [ 3.281824] ---[ end trace 8b484262b4b8c24c ]---(CVE-2022-49034)\n\nIn the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - inject error before stopping queue The master ooo cannot be completely closed when the accelerator core reports memory error. Therefore, the driver needs to inject the qm error to close the master ooo. Currently, the qm error is injected after stopping queue, memory may be released immediately after stopping queue, causing the device to access the released memory. Therefore, error is injected to close master ooo before stopping queue to ensure that the device does not access the released memory.(CVE-2024-47730)\n\nIn the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointers before using dc->clk_mgr [WHY & HOW] dc->clk_mgr is null checked previously in the same function, indicating it might be null. Passing "dc" to "dc->hwss.apply_idle_power_optimizations", which dereferences null "dc->clk_mgr". (The function pointer resolves to "dcn35_apply_idle_power_optimizations".) This fixes 1 FORWARD_NULL issue reported by Coverity.(CVE-2024-49907)\n\nIn the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix error path in multi-packet WQE transmit Remove the erroneous unmap in case no DMA mapping was established The multi-packet WQE transmit code attempts to obtain a DMA mapping for the skb. This could fail, e.g. under memory pressure, when the IOMMU driver just can\'t allocate more memory for page tables. While the code tries to handle this in the path below the err_unmap label it erroneously unmaps one entry from the sq\'s FIFO list of active mappings. Since the current map attempt failed this unmap is removing some random DMA mapping that might still be required. If the PCI function now presents that IOVA, the IOMMU may assumes a rogue DMA access and e.g. on s390 puts the PCI function in error state. The erroneous behavior was seen in a stress-test environment that created memory pressure.(CVE-2024-50001)\n\nIn the Linux kernel, the following vulnerability has been resolved: net: phy: dp83869: fix memory corruption when enabling fiber When configuring the fiber port, the DP83869 PHY driver incorrectly calls linkmode_set_bit() with a bit mask (1 << 10) rather than a bit number (10). This corrupts some other memory location -- in case of arm64 the priv pointer in the same structure. Since the advertising flags are updated from supported at the end of the function the incorrect line isn\'t needed at all and can be removed.(CVE-2024-50188)\n\nIn the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9832: fix division by zero in ad9832_calc_freqreg() In the ad9832_write_frequency() function, clk_get_rate() might return 0. This can lead to a division by zero when calling ad9832_calc_freqreg(). The check if (fout > (clk_get_rate(st->mclk) / 2)) does not protect against the case when fout is 0. The ad9832_write_frequency() function is called from ad9832_write(), and fout is derived from a text buffer, which can contain any value.(CVE-2024-50233)\n\nIn the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans During loopback communication, a dangling pointer can be created in vsk->trans, potentially leading to a Use-After-Free condition. This issue is resolved by initializing vsk->trans to NULL.(CVE-2024-50264)\n\nIn the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so that decode_cb_compound4res() does not have to perform arithmetic on the unsafe length value.(CVE-2024-53146)\n\nIn the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is greater than or equal to the cluster size, if start_clu becomes an EOF cluster(an invalid cluster) due to file system corruption, then the directory entry where ei->hint_femp.eidx hint is outside the directory, resulting in an out-of-bounds access, which may cause further file system corruption. This commit adds a check for start_clu, if it is an invalid cluster, the file or directory will be treated as empty.(CVE-2024-53147)\n\nIn the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_iter() Syzbot has reported the following KMSAN splat: BUG: KMSAN: uninit-value in ocfs2_file_read_iter+0x9a4/0xf80 ocfs2_file_read_iter+0x9a4/0xf80 __io_read+0x8d4/0x20f0 io_read+0x3e/0xf0 io_issue_sqe+0x42b/0x22c0 io_wq_submit_work+0xaf9/0xdc0 io_worker_handle_work+0xd13/0x2110 io_wq_worker+0x447/0x1410 ret_from_fork+0x6f/0x90 ret_from_fork_asm+0x1a/0x30 Uninit was created at: __alloc_pages_noprof+0x9a7/0xe00 alloc_pages_mpol_noprof+0x299/0x990 alloc_pages_noprof+0x1bf/0x1e0 allocate_slab+0x33a/0x1250 ___slab_alloc+0x12ef/0x35e0 kmem_cache_alloc_bulk_noprof+0x486/0x1330 __io_alloc_req_refill+0x84/0x560 io_submit_sqes+0x172f/0x2f30 __se_sys_io_uring_enter+0x406/0x41c0 __x64_sys_io_uring_enter+0x11f/0x1a0 x64_sys_call+0x2b54/0x3ba0 do_syscall_64+0xcd/0x1e0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Since an instance of \'struct kiocb\' may be passed from the block layer with \'private\' field uninitialized, introduce \'ocfs2_iocb_init_rw_locked()\' and use it from where \'ocfs2_dio_end_io()\' might take care, i.e. in \'ocfs2_file_read_iter()\' and \'ocfs2_file_write_iter()\'.(CVE-2024-53155)\n\nIn the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() This loop is supposed to break if the frequency returned from clk_round_rate() is the same as on the previous iteration. However, that check doesn\'t make sense on the first iteration through the loop. It leads to reading before the start of these->clk_perf_tbl[] array.(CVE-2024-53158)\n\nIn the Linux kernel, the following vulnerability has been resolved: EDAC/bluefield: Fix potential integer overflow The 64-bit argument for the "get DIMM info" SMC call consists of mem_ctrl_idx left-shifted 16 bits and OR-ed with DIMM index. With mem_ctrl_idx defined as 32-bits wide the left-shift operation truncates the upper 16 bits of information during the calculation of the SMC argument. The mem_ctrl_idx stack variable must be defined as 64-bits wide to prevent any potential integer overflow, i.e. loss of data from upper 16 bits.(CVE-2024-53161)\n\nIn the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_controller() In the error handling for this function, d is freed without ever removing it from intc_list which would lead to a use after free. To fix this, let\'s only add it to the list after everything has succeeded.(CVE-2024-53165)\n\nIn the Linux kernel, the following vulnerability has been resolved: NFSv4.0: Fix a use-after-free problem in the asynchronous open() Yang Erkun reports that when two threads are opening files at the same time, and are forced to abort before a reply is seen, then the call to nfs_release_seqid() in nfs4_opendata_free() can result in a use-after-free of the pointer to the defunct rpc task of the other thread. The fix is to ensure that if the RPC call is aborted before the call to nfs_wait_on_sequence() is complete, then we must call nfs_release_seqid() in nfs4_open_release() before the rpc_task is freed.(CVE-2024-53173)\n\nIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix NULL ptr deref in crypto_aead_setkey() Neither SMB3.0 or SMB3.02 supports encryption negotiate context, so when SMB2_GLOBAL_CAP_ENCRYPTION flag is set in the negotiate response, the client uses AES-128-CCM as the default cipher. See MS-SMB2 3.3.5.4. Commit b0abcd65ec54 ("smb: client: fix UAF in async decryption") added a @server->cipher_type check to conditionally call smb3_crypto_aead_allocate(), but that check would always be false as @server->cipher_type is unset for SMB3.02. Fix the following KASAN splat by setting @server->cipher_type for SMB3.02 as well. mount.cifs //srv/share /mnt -o vers=3.02,seal,... BUG: KASAN: null-ptr-deref in crypto_aead_setkey+0x2c/0x130 Read of size 8 at addr 0000000000000020 by task mount.cifs/1095 CPU: 1 UID: 0 PID: 1095 Comm: mount.cifs Not tainted 6.12.0 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x5d/0x80 ? crypto_aead_setkey+0x2c/0x130 kasan_report+0xda/0x110 ? crypto_aead_setkey+0x2c/0x130 crypto_aead_setkey+0x2c/0x130 crypt_message+0x258/0xec0 [cifs] ? __asan_memset+0x23/0x50 ? __pfx_crypt_message+0x10/0x10 [cifs] ? mark_lock+0xb0/0x6a0 ? hlock_class+0x32/0xb0 ? mark_lock+0xb0/0x6a0 smb3_init_transform_rq+0x352/0x3f0 [cifs] ? lock_acquire.part.0+0xf4/0x2a0 smb_send_rqst+0x144/0x230 [cifs] ? __pfx_smb_send_rqst+0x10/0x10 [cifs] ? hlock_class+0x32/0xb0 ? smb2_setup_request+0x225/0x3a0 [cifs] ? __pfx_cifs_compound_last_callback+0x10/0x10 [cifs] compound_send_recv+0x59b/0x1140 [cifs] ? __pfx_compound_send_recv+0x10/0x10 [cifs] ? __create_object+0x5e/0x90 ? hlock_class+0x32/0xb0 ? do_raw_spin_unlock+0x9a/0xf0 cifs_send_recv+0x23/0x30 [cifs] SMB2_tcon+0x3ec/0xb30 [cifs] ? __pfx_SMB2_tcon+0x10/0x10 [cifs] ? lock_acquire.part.0+0xf4/0x2a0 ? __pfx_lock_release+0x10/0x10 ? do_raw_spin_trylock+0xc6/0x120 ? lock_acquire+0x3f/0x90 ? _get_xid+0x16/0xd0 [cifs] ? __pfx_SMB2_tcon+0x10/0x10 [cifs] ? cifs_get_smb_ses+0xcdd/0x10a0 [cifs] cifs_get_smb_ses+0xcdd/0x10a0 [cifs] ? __pfx_cifs_get_smb_ses+0x10/0x10 [cifs] ? cifs_get_tcp_session+0xaa0/0xca0 [cifs] cifs_mount_get_session+0x8a/0x210 [cifs] dfs_mount_share+0x1b0/0x11d0 [cifs] ? __pfx___lock_acquire+0x10/0x10 ? __pfx_dfs_mount_share+0x10/0x10 [cifs] ? lock_acquire.part.0+0xf4/0x2a0 ? find_held_lock+0x8a/0xa0 ? hlock_class+0x32/0xb0 ? lock_release+0x203/0x5d0 cifs_mount+0xb3/0x3d0 [cifs] ? do_raw_spin_trylock+0xc6/0x120 ? __pfx_cifs_mount+0x10/0x10 [cifs] ? lock_acquire+0x3f/0x90 ? find_nls+0x16/0xa0 ? smb3_update_mnt_flags+0x372/0x3b0 [cifs] cifs_smb3_do_mount+0x1e2/0xc80 [cifs] ? __pfx_vfs_parse_fs_string+0x10/0x10 ? __pfx_cifs_smb3_do_mount+0x10/0x10 [cifs] smb3_get_tree+0x1bf/0x330 [cifs] vfs_get_tree+0x4a/0x160 path_mount+0x3c1/0xfb0 ? kasan_quarantine_put+0xc7/0x1d0 ? __pfx_path_mount+0x10/0x10 ? kmem_cache_free+0x118/0x3e0 ? user_path_at+0x74/0xa0 __x64_sys_mount+0x1a6/0x1e0 ? __pfx___x64_sys_mount+0x10/0x10 ? mark_held_locks+0x1a/0x90 do_syscall_64+0xbb/0x1d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f(CVE-2024-53185)\n\nIn the Linux kernel, the following vulnerability has been resolved: io_uring: check for overflows in io_pin_pages WARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144 CPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0 Call Trace: <TASK> __io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183 io_rings_map io_uring/io_uring.c:2611 [inline] io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470 io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692 io_uring_setup io_uring/io_uring.c:3781 [inline] ... </TASK> io_pin_pages()\'s uaddr parameter came directly from the user and can be garbage. Don\'t just add size to it as it can overflow.(CVE-2024-53187)\n\nIn the Linux kernel, the following vulnerability has been resolved: PCI: Fix use-after-free of slot->bus on hot remove Dennis reports a boot crash on recent Lenovo laptops with a USB4 dock. Since commit 0fc70886569c ("thunderbolt: Reset USB4 v2 host router") and commit 59a54c5f3dbd ("thunderbolt: Reset topology created by the boot firmware"), USB4 v2 and v1 Host Routers are reset on probe of the thunderbolt driver. The reset clears the Presence Detect State and Data Link Layer Link Active bits at the USB4 Host Router\'s Root Port and thus causes hot removal of the dock. The crash occurs when pciehp is unbound from one of the dock\'s Downstream Ports: pciehp creates a pci_slot on bind and destroys it on unbind. The pci_slot contains a pointer to the pci_bus below the Downstream Port, but a reference on that pci_bus is never acquired. The pci_bus is destroyed before the pci_slot, so a use-after-free ensues when pci_slot_release() accesses slot->bus. In principle this should not happen because pci_stop_bus_device() unbinds pciehp (and therefore destroys the pci_slot) before the pci_bus is destroyed by pci_remove_bus_device(). However the stacktrace provided by Dennis shows that pciehp is unbound from pci_remove_bus_device() instead of pci_stop_bus_device(). To understand the significance of this, one needs to know that the PCI core uses a two step process to remove a portion of the hierarchy: It first unbinds all drivers in the sub-hierarchy in pci_stop_bus_device() and then actually removes the devices in pci_remove_bus_device(). There is no precaution to prevent driver binding in-between pci_stop_bus_device() and pci_remove_bus_device(). In Dennis\' case, it seems removal of the hierarchy by pciehp races with driver binding by pci_bus_add_devices(). pciehp is bound to the Downstream Port after pci_stop_bus_device() has run, so it is unbound by pci_remove_bus_device() instead of pci_stop_bus_device(). Because the pci_bus has already been destroyed at that point, accesses to it result in a use-after-free. One might conclude that driver binding needs to be prevented after pci_stop_bus_device() has run. However it seems risky that pci_slot points to pci_bus without holding a reference. Solely relying on correct ordering of driver unbind versus pci_bus destruction is certainly not defensive programming. If pci_slot has a need to access data in pci_bus, it ought to acquire a reference. Amend pci_create_slot() accordingly. Dennis reports that the crash is not reproducible with this change. Abridged stacktrace: pcieport 0000:00:07.0: PME: Signaling with IRQ 156 pcieport 0000:00:07.0: pciehp: Slot #12 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ IbPresDis- LLActRep+ pci_bus 0000:20: dev 00, created physical slot 12 pcieport 0000:00:07.0: pciehp: Slot(12): Card not present ... pcieport 0000:21:02.0: pciehp: pcie_disable_notification: SLOTCTRL d8 write cmd 0 Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] PREEMPT SMP NOPTI CPU: 13 UID: 0 PID: 134 Comm: irq/156-pciehp Not tainted 6.11.0-devel+ #1 RIP: 0010:dev_driver_string+0x12/0x40 pci_destroy_slot pciehp_remove pcie_port_remove_service device_release_driver_internal bus_remove_device device_del device_unregister remove_iter device_for_each_child pcie_portdrv_remove pci_device_remove device_release_driver_internal bus_remove_device device_del pci_remove_bus_device (recursive invocation) pci_remove_bus_device pciehp_unconfigure_device pciehp_disable_slot pciehp_handle_presence_or_link_change pciehp_ist(CVE-2024-53194)\n\nIn the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration.(CVE-2024-53197)\n\nIn the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent NULL dereference in nfsd4_process_cb_update() @ses is initialized to NULL. If __nfsd4_find_backchannel() finds no available backchannel session, setup_callback_client() will try to dereference @ses and segfault.(CVE-2024-53217)\n\nIn the Linux kernel, the following vulnerability has been resolved: f2fs: fix race in concurrent f2fs_stop_gc_thread In my test case, concurrent calls to f2fs shutdown report the following stack trace: Oops: general protection fault, probably for non-canonical address 0xc6cfff63bb5513fc: 0000 [#1] PREEMPT SMP PTI CPU: 0 UID: 0 PID: 678 Comm: f2fs_rep_shutdo Not tainted 6.12.0-rc5-next-20241029-g6fb2fa9805c5-dirty #85 Call Trace: <TASK> ? show_regs+0x8b/0xa0 ? __die_body+0x26/0xa0 ? die_addr+0x54/0x90 ? exc_general_protection+0x24b/0x5c0 ? asm_exc_general_protection+0x26/0x30 ? kthread_stop+0x46/0x390 f2fs_stop_gc_thread+0x6c/0x110 f2fs_do_shutdown+0x309/0x3a0 f2fs_ioc_shutdown+0x150/0x1c0 __f2fs_ioctl+0xffd/0x2ac0 f2fs_ioctl+0x76/0xe0 vfs_ioctl+0x23/0x60 __x64_sys_ioctl+0xce/0xf0 x64_sys_call+0x2b1b/0x4540 do_syscall_64+0xa7/0x240 entry_SYSCALL_64_after_hwframe+0x76/0x7e The root cause is a race condition in f2fs_stop_gc_thread() called from different f2fs shutdown paths: [CPU0] [CPU1] ---------------------- ----------------------- f2fs_stop_gc_thread f2fs_stop_gc_thread gc_th = sbi->gc_thread gc_th = sbi->gc_thread kfree(gc_th) sbi->gc_thread = NULL < gc_th != NULL > kthread_stop(gc_th->f2fs_gc_task) //UAF The commit c7f114d864ac ("f2fs: fix to avoid use-after-free in f2fs_stop_gc_thread()") attempted to fix this issue by using a read semaphore to prevent races between shutdown and remount threads, but it fails to prevent all race conditions. Fix it by converting to write lock of s_umount in f2fs_do_shutdown().(CVE-2024-53218)\n\nIn the Linux kernel, the following vulnerability has been resolved: virtiofs: use pages instead of pointer for kernel direct IO When trying to insert a 10MB kernel module kept in a virtio-fs with cache disabled, the following warning was reported: ------------[ cut here ]------------ WARNING: CPU: 1 PID: 404 at mm/page_alloc.c:4551 ...... Modules linked in: CPU: 1 PID: 404 Comm: insmod Not tainted 6.9.0-rc5+ #123 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ...... RIP: 0010:__alloc_pages+0x2bf/0x380 ...... Call Trace: <TASK> ? __warn+0x8e/0x150 ? __alloc_pages+0x2bf/0x380 __kmalloc_large_node+0x86/0x160 __kmalloc+0x33c/0x480 virtio_fs_enqueue_req+0x240/0x6d0 virtio_fs_wake_pending_and_unlock+0x7f/0x190 queue_request_and_unlock+0x55/0x60 fuse_simple_request+0x152/0x2b0 fuse_direct_io+0x5d2/0x8c0 fuse_file_read_iter+0x121/0x160 __kernel_read+0x151/0x2d0 kernel_read+0x45/0x50 kernel_read_file+0x1a9/0x2a0 init_module_from_file+0x6a/0xe0 idempotent_init_module+0x175/0x230 __x64_sys_finit_module+0x5d/0xb0 x64_sys_call+0x1c3/0x9e0 do_syscall_64+0x3d/0xc0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 ...... </TASK> ---[ end trace 0000000000000000 ]--- The warning is triggered as follows: 1) syscall finit_module() handles the module insertion and it invokes kernel_read_file() to read the content of the module first. 2) kernel_read_file() allocates a 10MB buffer by using vmalloc() and passes it to kernel_read(). kernel_read() constructs a kvec iter by using iov_iter_kvec() and passes it to fuse_file_read_iter(). 3) virtio-fs disables the cache, so fuse_file_read_iter() invokes fuse_direct_io(). As for now, the maximal read size for kvec iter is only limited by fc->max_read. For virtio-fs, max_read is UINT_MAX, so fuse_direct_io() doesn\'t split the 10MB buffer. It saves the address and the size of the 10MB-sized buffer in out_args[0] of a fuse request and passes the fuse request to virtio_fs_wake_pending_and_unlock(). 4) virtio_fs_wake_pending_and_unlock() uses virtio_fs_enqueue_req() to queue the request. Because virtiofs need DMA-able address, so virtio_fs_enqueue_req() uses kmalloc() to allocate a bounce buffer for all fuse args, copies these args into the bounce buffer and passed the physical address of the bounce buffer to virtiofsd. The total length of these fuse args for the passed fuse request is about 10MB, so copy_args_to_argbuf() invokes kmalloc() with a 10MB size parameter and it triggers the warning in __alloc_pages(): if (WARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp)) return NULL; 5) virtio_fs_enqueue_req() will retry the memory allocation in a kworker, but it won\'t help, because kmalloc() will always return NULL due to the abnormal size and finit_module() will hang forever. A feasible solution is to limit the value of max_read for virtio-fs, so the length passed to kmalloc() will be limited. However it will affect the maximal read size for normal read. And for virtio-fs write initiated from kernel, it has the similar problem but now there is no way to limit fc->max_write in kernel. So instead of limiting both the values of max_read and max_write in kernel, introducing use_pages_for_kvec_io in fuse_conn and setting it as true in virtiofs. When use_pages_for_kvec_io is enabled, fuse will use pages instead of pointer to pass the KVEC_IO data. After switching to pages for KVEC_IO data, these pages will be used for DMA through virtio-fs. If these pages are backed by vmalloc(), {flush|invalidate}_kernel_vmap_range() are necessary to flush or invalidate the cache before the DMA operation. So add two new fields in fuse_args_pages to record the base address of vmalloc area and the condition indicating whether invalidation is needed. Perform the flush in fuse_get_user_pages() for write operations and the invalidation in fuse_release_user_pages() for read operations. It may seem necessary to introduce another fie ---truncated---(CVE-2024-53219)\n\nIn the Linux kernel, the following vulnerability has been resolved: f2fs: fix null-ptr-deref in f2fs_submit_page_bio() There\'s issue as follows when concurrently installing the f2fs.ko module and mounting the f2fs file system: KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027] RIP: 0010:__bio_alloc+0x2fb/0x6c0 [f2fs] Call Trace: <TASK> f2fs_submit_page_bio+0x126/0x8b0 [f2fs] __get_meta_page+0x1d4/0x920 [f2fs] get_checkpoint_version.constprop.0+0x2b/0x3c0 [f2fs] validate_checkpoint+0xac/0x290 [f2fs] f2fs_get_valid_checkpoint+0x207/0x950 [f2fs] f2fs_fill_super+0x1007/0x39b0 [f2fs] mount_bdev+0x183/0x250 legacy_get_tree+0xf4/0x1e0 vfs_get_tree+0x88/0x340 do_new_mount+0x283/0x5e0 path_mount+0x2b2/0x15b0 __x64_sys_mount+0x1fe/0x270 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e Above issue happens as the biset of the f2fs file system is not initialized before register "f2fs_fs_type". To address above issue just register "f2fs_fs_type" at the last in init_f2fs_fs(). Ensure that all f2fs file system resources are initialized.(CVE-2024-53221)\n\nIn the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Move events notifier registration to be after device registration Move pkey change work initialization and cleanup from device resources stage to notifier stage, since this is the stage which handles this work events. Fix a race between the device deregistration and pkey change work by moving MLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to ensure that the notifier is deregistered before the device during cleanup. Which ensures there are no works that are being executed after the device has already unregistered which can cause the panic below. BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1 Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023 Workqueue: events pkey_change_handler [mlx5_ib] RIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib] Code: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 <4c> 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40 RSP: 0018:ffffbcc54068be20 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36 RDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128 RBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001 R10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000 R13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905 FS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: mlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib] process_one_work+0x1e8/0x3c0 worker_thread+0x50/0x3b0 ? rescuer_thread+0x380/0x380 kthread+0x149/0x170 ? set_kthread_struct+0x50/0x50 ret_from_fork+0x22/0x30 Modules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core] CR2: 0000000000000000 ---[ end trace f6f8be4eae12f7bc ]---(CVE-2024-53224)\n\nIn the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Fix use-after-free in bfad_im_module_exit() BUG: KASAN: slab-use-after-free in __lock_acquire+0x2aca/0x3a20 Read of size 8 at addr ffff8881082d80c8 by task modprobe/25303 Call Trace: <TASK> dump_stack_lvl+0x95/0xe0 print_report+0xcb/0x620 kasan_report+0xbd/0xf0 __lock_acquire+0x2aca/0x3a20 lock_acquire+0x19b/0x520 _raw_spin_lock+0x2b/0x40 attribute_container_unregister+0x30/0x160 fc_release_transport+0x19/0x90 [scsi_transport_fc] bfad_im_module_exit+0x23/0x60 [bfa] bfad_init+0xdb/0xff0 [bfa] do_one_initcall+0xdc/0x550 do_init_module+0x22d/0x6b0 load_module+0x4e96/0x5ff0 init_module_from_file+0xcd/0x130 idempotent_init_module+0x330/0x620 __x64_sys_finit_module+0xb3/0x110 do_syscall_64+0xc1/0x1d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f </TASK> Allocated by task 25303: kasan_save_stack+0x24/0x50 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x7f/0x90 fc_attach_transport+0x4f/0x4740 [scsi_transport_fc] bfad_im_module_init+0x17/0x80 [bfa] bfad_init+0x23/0xff0 [bfa] do_one_initcall+0xdc/0x550 do_init_module+0x22d/0x6b0 load_module+0x4e96/0x5ff0 init_module_from_file+0xcd/0x130 idempotent_init_module+0x330/0x620 __x64_sys_finit_module+0xb3/0x110 do_syscall_64+0xc1/0x1d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 25303: kasan_save_stack+0x24/0x50 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x38/0x50 kfree+0x212/0x480 bfad_im_module_init+0x7e/0x80 [bfa] bfad_init+0x23/0xff0 [bfa] do_one_initcall+0xdc/0x550 do_init_module+0x22d/0x6b0 load_module+0x4e96/0x5ff0 init_module_from_file+0xcd/0x130 idempotent_init_module+0x330/0x620 __x64_sys_finit_module+0xb3/0x110 do_syscall_64+0xc1/0x1d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Above issue happens as follows: bfad_init error = bfad_im_module_init() fc_release_transport(bfad_im_scsi_transport_template); if (error) goto ext; ext: bfad_im_module_exit(); fc_release_transport(bfad_im_scsi_transport_template); --> Trigger double release Don\'t call bfad_im_module_exit() if bfad_im_module_init() failed.(CVE-2024-53227)\n\nIn the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_kms: Unplug DRM device before removal Prevent userspace accesses to the DRM device from causing use-after-frees by unplugging the device before we remove it. This causes any further userspace accesses to result in an error without further calls into this driver\'s internals.(CVE-2024-56538)\n\nIn the Linux kernel, the following vulnerability has been resolved: hfsplus: don\'t query the device logical block size multiple times Devices block sizes may change. One of these cases is a loop device by using ioctl LOOP_SET_BLOCK_SIZE. While this may cause other issues like IO being rejected, in the case of hfsplus, it will allocate a block by using that size and potentially write out-of-bounds when hfsplus_read_wrapper calls hfsplus_submit_bio and the latter function reads a different io_size. Using a new min_io_size initally set to sb_min_blocksize works for the purposes of the original fix, since it will be set to the max between HFSPLUS_SECTOR_SIZE and the first seen logical block size. We still use the max between HFSPLUS_SECTOR_SIZE and min_io_size in case the latter is not initialized. Tested by mounting an hfsplus filesystem with loop block sizes 512, 1024 and 4096. The produced KASAN report before the fix looks like this: [ 419.944641] ================================================================== [ 419.945655] BUG: KASAN: slab-use-after-free in hfsplus_read_wrapper+0x659/0xa0a [ 419.946703] Read of size 2 at addr ffff88800721fc00 by task repro/10678 [ 419.947612] [ 419.947846] CPU: 0 UID: 0 PID: 10678 Comm: repro Not tainted 6.12.0-rc5-00008-gdf56e0f2f3ca #84 [ 419.949007] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 [ 419.950035] Call Trace: [ 419.950384] <TASK> [ 419.950676] dump_stack_lvl+0x57/0x78 [ 419.951212] ? hfsplus_read_wrapper+0x659/0xa0a [ 419.951830] print_report+0x14c/0x49e [ 419.952361] ? __virt_addr_valid+0x267/0x278 [ 419.952979] ? kmem_cache_debug_flags+0xc/0x1d [ 419.953561] ? hfsplus_read_wrapper+0x659/0xa0a [ 419.954231] kasan_report+0x89/0xb0 [ 419.954748] ? hfsplus_read_wrapper+0x659/0xa0a [ 419.955367] hfsplus_read_wrapper+0x659/0xa0a [ 419.955948] ? __pfx_hfsplus_read_wrapper+0x10/0x10 [ 419.956618] ? do_raw_spin_unlock+0x59/0x1a9 [ 419.957214] ? _raw_spin_unlock+0x1a/0x2e [ 419.957772] hfsplus_fill_super+0x348/0x1590 [ 419.958355] ? hlock_class+0x4c/0x109 [ 419.958867] ? __pfx_hfsplus_fill_super+0x10/0x10 [ 419.959499] ? __pfx_string+0x10/0x10 [ 419.960006] ? lock_acquire+0x3e2/0x454 [ 419.960532] ? bdev_name.constprop.0+0xce/0x243 [ 419.961129] ? __pfx_bdev_name.constprop.0+0x10/0x10 [ 419.961799] ? pointer+0x3f0/0x62f [ 419.962277] ? __pfx_pointer+0x10/0x10 [ 419.962761] ? vsnprintf+0x6c4/0xfba [ 419.963178] ? __pfx_vsnprintf+0x10/0x10 [ 419.963621] ? setup_bdev_super+0x376/0x3b3 [ 419.964029] ? snprintf+0x9d/0xd2 [ 419.964344] ? __pfx_snprintf+0x10/0x10 [ 419.964675] ? lock_acquired+0x45c/0x5e9 [ 419.965016] ? set_blocksize+0x139/0x1c1 [ 419.965381] ? sb_set_blocksize+0x6d/0xae [ 419.965742] ? __pfx_hfsplus_fill_super+0x10/0x10 [ 419.966179] mount_bdev+0x12f/0x1bf [ 419.966512] ? __pfx_mount_bdev+0x10/0x10 [ 419.966886] ? vfs_parse_fs_string+0xce/0x111 [ 419.967293] ? __pfx_vfs_parse_fs_string+0x10/0x10 [ 419.967702] ? __pfx_hfsplus_mount+0x10/0x10 [ 419.968073] legacy_get_tree+0x104/0x178 [ 419.968414] vfs_get_tree+0x86/0x296 [ 419.968751] path_mount+0xba3/0xd0b [ 419.969157] ? __pfx_path_mount+0x10/0x10 [ 419.969594] ? kmem_cache_free+0x1e2/0x260 [ 419.970311] do_mount+0x99/0xe0 [ 419.970630] ? __pfx_do_mount+0x10/0x10 [ 419.971008] __do_sys_mount+0x199/0x1c9 [ 419.971397] do_syscall_64+0xd0/0x135 [ 419.971761] entry_SYSCALL_64_after_hwframe+0x76/0x7e [ 419.972233] RIP: 0033:0x7c3cb812972e [ 419.972564] Code: 48 8b 0d f5 46 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c2 46 0d 00 f7 d8 64 89 01 48 [ 419.974371] RSP: 002b:00007ffe30632548 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5 [ 419.975048] RAX: ffffffffffffffda RBX: 00007ffe306328d8 RCX: 00007c3cb812972e [ 419.975701] RDX: 0000000020000000 RSI: 0000000020000c80 RDI: ---truncated---(CVE-2024-56548)\n\nIn the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() if (dev->boardinfo && dev->boardinfo->init_dyn_addr) ^^^ here check "init_dyn_addr" i3c_bus_set_addr_slot_status(&master->bus, dev->info.dyn_addr, ...) ^^^^ free "dyn_addr" Fix copy/paste error "dyn_addr" by replacing it with "init_dyn_addr".(CVE-2024-56562)\n\nIn the Linux kernel, the following vulnerability has been resolved: ftrace: Fix regression with module command in stack_trace_filter When executing the following command: # echo "write*:mod:ext3" > /sys/kernel/tracing/stack_trace_filter The current mod command causes a null pointer dereference. While commit 0f17976568b3f ("ftrace: Fix regression with module command in stack_trace_filter") has addressed part of the issue, it left a corner case unhandled, which still results in a kernel crash.(CVE-2024-56569)\n\nIn the Linux kernel, the following vulnerability has been resolved: ovl: Filter invalid inodes with missing lookup function Add a check to the ovl_dentry_weird() function to prevent the processing of directory inodes that lack the lookup function. This is important because such inodes can cause errors in overlayfs when passed to the lowerstack.(CVE-2024-56570)\n\nIn the Linux kernel, the following vulnerability has been resolved: media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal() The buffer in the loop should be released under the exception path, otherwise there may be a memory leak here. To mitigate this, free the buffer when allegro_alloc_buffer fails.(CVE-2024-56572)\n\nIn the Linux kernel, the following vulnerability has been resolved: btrfs: ref-verify: fix use-after-free after invalid ref action At btrfs_ref_tree_mod() after we successfully inserted the new ref entry (local variable \'ref\') into the respective block entry\'s rbtree (local variable \'be\'), if we find an unexpected action of BTRFS_DROP_DELAYED_REF, we error out and free the ref entry without removing it from the block entry\'s rbtree. Then in the error path of btrfs_ref_tree_mod() we call btrfs_free_ref_cache(), which iterates over all block entries and then calls free_block_entry() for each one, and there we will trigger a use-after-free when we are called against the block entry to which we added the freed ref entry to its rbtree, since the rbtree still points to the block entry, as we didn\'t remove it from the rbtree before freeing it in the error path at btrfs_ref_tree_mod(). Fix this by removing the new ref entry from the rbtree before freeing it. Syzbot report this with the following stack traces: BTRFS error (device loop0 state EA): Ref action 2, root 5, ref_root 0, parent 8564736, owner 0, offset 0, num_refs 18446744073709551615 __btrfs_mod_ref+0x7dd/0xac0 fs/btrfs/extent-tree.c:2523 update_ref_for_cow+0x9cd/0x11f0 fs/btrfs/ctree.c:512 btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594 btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754 btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116 btrfs_insert_empty_items+0x9c/0x1a0 fs/btrfs/ctree.c:4314 btrfs_insert_empty_item fs/btrfs/ctree.h:669 [inline] btrfs_insert_orphan_item+0x1f1/0x320 fs/btrfs/orphan.c:23 btrfs_orphan_add+0x6d/0x1a0 fs/btrfs/inode.c:3482 btrfs_unlink+0x267/0x350 fs/btrfs/inode.c:4293 vfs_unlink+0x365/0x650 fs/namei.c:4469 do_unlinkat+0x4ae/0x830 fs/namei.c:4533 __do_sys_unlinkat fs/namei.c:4576 [inline] __se_sys_unlinkat fs/namei.c:4569 [inline] __x64_sys_unlinkat+0xcc/0xf0 fs/namei.c:4569 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f BTRFS error (device loop0 state EA): Ref action 1, root 5, ref_root 5, parent 0, owner 260, offset 0, num_refs 1 __btrfs_mod_ref+0x76b/0xac0 fs/btrfs/extent-tree.c:2521 update_ref_for_cow+0x96a/0x11f0 btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594 btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754 btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116 btrfs_lookup_inode+0xdc/0x480 fs/btrfs/inode-item.c:411 __btrfs_update_delayed_inode+0x1e7/0xb90 fs/btrfs/delayed-inode.c:1030 btrfs_update_delayed_inode fs/btrfs/delayed-inode.c:1114 [inline] __btrfs_commit_inode_delayed_items+0x2318/0x24a0 fs/btrfs/delayed-inode.c:1137 __btrfs_run_delayed_items+0x213/0x490 fs/btrfs/delayed-inode.c:1171 btrfs_commit_transaction+0x8a8/0x3740 fs/btrfs/transaction.c:2313 prepare_to_relocate+0x3c4/0x4c0 fs/btrfs/relocation.c:3586 relocate_block_group+0x16c/0xd40 fs/btrfs/relocation.c:3611 btrfs_relocate_block_group+0x77d/0xd90 fs/btrfs/relocation.c:4081 btrfs_relocate_chunk+0x12c/0x3b0 fs/btrfs/volumes.c:3377 __btrfs_balance+0x1b0f/0x26b0 fs/btrfs/volumes.c:4161 btrfs_balance+0xbdc/0x10c0 fs/btrfs/volumes.c:4538 BTRFS error (device loop0 state EA): Ref action 2, root 5, ref_root 0, parent 8564736, owner 0, offset 0, num_refs 18446744073709551615 __btrfs_mod_ref+0x7dd/0xac0 fs/btrfs/extent-tree.c:2523 update_ref_for_cow+0x9cd/0x11f0 fs/btrfs/ctree.c:512 btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594 btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754 btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116 btrfs_lookup_inode+0xdc/0x480 fs/btrfs/inode-item.c:411 __btrfs_update_delayed_inode+0x1e7/0xb90 fs/btrfs/delayed-inode.c:1030 btrfs_update_delayed_i ---truncated---(CVE-2024-56581)\n\nIn the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix warning in migrate_enable for boosted tasks When running the following command: while true; do stress-ng --cyclic 30 --timeout 30s --minimize --quiet done a warning is eventually triggered: WARNING: CPU: 43 PID: 2848 at kernel/sched/deadline.c:794 setup_new_dl_entity+0x13e/0x180 ... Call Trace: <TASK> ? show_trace_log_lvl+0x1c4/0x2df ? enqueue_dl_entity+0x631/0x6e0 ? setup_new_dl_entity+0x13e/0x180 ? __warn+0x7e/0xd0 ? report_bug+0x11a/0x1a0 ? handle_bug+0x3c/0x70 ? exc_invalid_op+0x14/0x70 ? asm_exc_invalid_op+0x16/0x20 enqueue_dl_entity+0x631/0x6e0 enqueue_task_dl+0x7d/0x120 __do_set_cpus_allowed+0xe3/0x280 __set_cpus_allowed_ptr_locked+0x140/0x1d0 __set_cpus_allowed_ptr+0x54/0xa0 migrate_enable+0x7e/0x150 rt_spin_unlock+0x1c/0x90 group_send_sig_info+0xf7/0x1a0 ? kill_pid_info+0x1f/0x1d0 kill_pid_info+0x78/0x1d0 kill_proc_info+0x5b/0x110 __x64_sys_kill+0x93/0xc0 do_syscall_64+0x5c/0xf0 entry_SYSCALL_64_after_hwframe+0x6e/0x76 RIP: 0033:0x7f0dab31f92b This warning occurs because set_cpus_allowed dequeues and enqueues tasks with the ENQUEUE_RESTORE flag set. If the task is boosted, the warning is triggered. A boosted task already had its parameters set by rt_mutex_setprio, and a new call to setup_new_dl_entity is unnecessary, hence the WARN_ON call. Check if we are requeueing a boosted task and avoid calling setup_new_dl_entity if that\'s the case.(CVE-2024-56583)\n\nIn the Linux kernel, the following vulnerability has been resolved: io_uring/tctx: work around xa_store() allocation error issue syzbot triggered the following WARN_ON: WARNING: CPU: 0 PID: 16 at io_uring/tctx.c:51 __io_uring_free+0xfa/0x140 io_uring/tctx.c:51 which is the WARN_ON_ONCE(!xa_empty(&tctx->xa)); sanity check in __io_uring_free() when a io_uring_task is going through its final put. The syzbot test case includes injecting memory allocation failures, and it very much looks like xa_store() can fail one of its memory allocations and end up with ->head being non-NULL even though no entries exist in the xarray. Until this issue gets sorted out, work around it by attempting to iterate entries in our xarray, and WARN_ON_ONCE() if one is found.(CVE-2024-56584)\n\nIn the Linux kernel, the following vulnerability has been resolved: f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode. creating a large files during checkpoint disable until it runs out of space and then delete it, then remount to enable checkpoint again, and then unmount the filesystem triggers the f2fs_bug_on as below: ------------[ cut here ]------------ kernel BUG at fs/f2fs/inode.c:896! CPU: 2 UID: 0 PID: 1286 Comm: umount Not tainted 6.11.0-rc7-dirty #360 Oops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI RIP: 0010:f2fs_evict_inode+0x58c/0x610 Call Trace: __die_body+0x15/0x60 die+0x33/0x50 do_trap+0x10a/0x120 f2fs_evict_inode+0x58c/0x610 do_error_trap+0x60/0x80 f2fs_evict_inode+0x58c/0x610 exc_invalid_op+0x53/0x60 f2fs_evict_inode+0x58c/0x610 asm_exc_invalid_op+0x16/0x20 f2fs_evict_inode+0x58c/0x610 evict+0x101/0x260 dispose_list+0x30/0x50 evict_inodes+0x140/0x190 generic_shutdown_super+0x2f/0x150 kill_block_super+0x11/0x40 kill_f2fs_super+0x7d/0x140 deactivate_locked_super+0x2a/0x70 cleanup_mnt+0xb3/0x140 task_work_run+0x61/0x90 The root cause is: creating large files during disable checkpoint period results in not enough free segments, so when writing back root inode will failed in f2fs_enable_checkpoint. When umount the file system after enabling checkpoint, the root inode is dirty in f2fs_evict_inode function, which triggers BUG_ON. The steps to reproduce are as follows: dd if=/dev/zero of=f2fs.img bs=1M count=55 mount f2fs.img f2fs_dir -o checkpoint=disable:10% dd if=/dev/zero of=big bs=1M count=50 sync rm big mount -o remount,checkpoint=enable f2fs_dir umount f2fs_dir Let\'s redirty inode when there is not free segments during checkpoint is disable.(CVE-2024-56586)\n\nIn the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: set the right AMDGPU sg segment limitation The driver needs to set the correct max_segment_size; otherwise debug_dma_map_sg() will complain about the over-mapping of the AMDGPU sg length as following: WARNING: CPU: 6 PID: 1964 at kernel/dma/debug.c:1178 debug_dma_map_sg+0x2dc/0x370 [ 364.049444] Modules linked in: veth amdgpu(OE) amdxcp drm_exec gpu_sched drm_buddy drm_ttm_helper ttm(OE) drm_suballoc_helper drm_display_helper drm_kms_helper i2c_algo_bit rpcsec_gss_krb5 auth_rpcgss nfsv4 nfs lockd grace netfs xt_conntrack xt_MASQUERADE nf_conntrack_netlink xfrm_user xfrm_algo iptable_nat xt_addrtype iptable_filter br_netfilter nvme_fabrics overlay nfnetlink_cttimeout nfnetlink openvswitch nsh nf_conncount nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c bridge stp llc amd_atl intel_rapl_msr intel_rapl_common sunrpc sch_fq_codel snd_hda_codec_realtek snd_hda_codec_generic snd_hda_scodec_component snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg edac_mce_amd binfmt_misc snd_hda_codec snd_pci_acp6x snd_hda_core snd_acp_config snd_hwdep snd_soc_acpi kvm_amd snd_pcm kvm snd_seq_midi snd_seq_midi_event crct10dif_pclmul ghash_clmulni_intel sha512_ssse3 snd_rawmidi sha256_ssse3 sha1_ssse3 aesni_intel snd_seq nls_iso8859_1 crypto_simd snd_seq_device cryptd snd_timer rapl input_leds snd [ 364.049532] ipmi_devintf wmi_bmof ccp serio_raw k10temp sp5100_tco soundcore ipmi_msghandler cm32181 industrialio mac_hid msr parport_pc ppdev lp parport drm efi_pstore ip_tables x_tables pci_stub crc32_pclmul nvme ahci libahci i2c_piix4 r8169 nvme_core i2c_designware_pci realtek i2c_ccgx_ucsi video wmi hid_generic cdc_ether usbnet usbhid hid r8152 mii [ 364.049576] CPU: 6 PID: 1964 Comm: rocminfo Tainted: G OE 6.10.0-custom #492 [ 364.049579] Hardware name: AMD Majolica-RN/Majolica-RN, BIOS RMJ1009A 06/13/2021 [ 364.049582] RIP: 0010:debug_dma_map_sg+0x2dc/0x370 [ 364.049585] Code: 89 4d b8 e8 36 b1 86 00 8b 4d b8 48 8b 55 b0 44 8b 45 a8 4c 8b 4d a0 48 89 c6 48 c7 c7 00 4b 74 bc 4c 89 4d b8 e8 b4 73 f3 ff <0f> 0b 4c 8b 4d b8 8b 15 c8 2c b8 01 85 d2 0f 85 ee fd ff ff 8b 05 [ 364.049588] RSP: 0018:ffff9ca600b57ac0 EFLAGS: 00010286 [ 364.049590] RAX: 0000000000000000 RBX: ffff88b7c132b0c8 RCX: 0000000000000027 [ 364.049592] RDX: ffff88bb0f521688 RSI: 0000000000000001 RDI: ffff88bb0f521680 [ 364.049594] RBP: ffff9ca600b57b20 R08: 000000000000006f R09: ffff9ca600b57930 [ 364.049596] R10: ffff9ca600b57928 R11: ffffffffbcb46328 R12: 0000000000000000 [ 364.049597] R13: 0000000000000001 R14: ffff88b7c19c0700 R15: ffff88b7c9059800 [ 364.049599] FS: 00007fb2d3516e80(0000) GS:ffff88bb0f500000(0000) knlGS:0000000000000000 [ 364.049601] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 364.049603] CR2: 000055610bd03598 CR3: 00000001049f6000 CR4: 0000000000350ef0 [ 364.049605] Call Trace: [ 364.049607] <TASK> [ 364.049609] ? show_regs+0x6d/0x80 [ 364.049614] ? __warn+0x8c/0x140 [ 364.049618] ? debug_dma_map_sg+0x2dc/0x370 [ 364.049621] ? report_bug+0x193/0x1a0 [ 364.049627] ? handle_bug+0x46/0x80 [ 364.049631] ? exc_invalid_op+0x1d/0x80 [ 364.049635] ? asm_exc_invalid_op+0x1f/0x30 [ 364.049642] ? debug_dma_map_sg+0x2dc/0x370 [ 364.049647] __dma_map_sg_attrs+0x90/0xe0 [ 364.049651] dma_map_sgtable+0x25/0x40 [ 364.049654] amdgpu_bo_move+0x59a/0x850 [amdgpu] [ 364.049935] ? srso_return_thunk+0x5/0x5f [ 364.049939] ? amdgpu_ttm_tt_populate+0x5d/0xc0 [amdgpu] [ 364.050095] ttm_bo_handle_move_mem+0xc3/0x180 [ttm] [ 364.050103] ttm_bo_validate+0xc1/0x160 [ttm] [ 364.050108] ? amdgpu_ttm_tt_get_user_pages+0xe5/0x1b0 [amdgpu] [ 364.050263] amdgpu_amdkfd_gpuvm_alloc_memory_of_gpu+0xa12/0xc90 [amdgpu] [ 364.050473] kfd_ioctl_alloc_memory_of_gpu+0x16b/0x3b0 [amdgpu] [ 364.050680] kfd_ioctl+0x3c2/0x530 [amdgpu] [ 364.050866] ? __pfx_kfd_ioctl_alloc_memory_of_gpu+0x10/0x10 [amdgpu] [ 364.05105 ---truncated---(CVE-2024-56594)\n\nIn the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in jfs_readdir The stbl might contain some invalid values. Added a check to return error code in that case.(CVE-2024-56596)\n\nIn the Linux kernel, the following vulnerability has been resolved: jfs: array-index-out-of-bounds fix in dtReadFirst The value of stbl can be sometimes out of bounds due to a bad filesystem. Added a check with appopriate return of error code in that case.(CVE-2024-56598)\n\nIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc() bt_sock_alloc() attaches allocated sk object to the provided sock object. If rfcomm_dlc_alloc() fails, we release the sk object, but leave the dangling pointer in the sock object, which may cause use-after-free. Fix this by swapping calls to bt_sock_alloc() and rfcomm_dlc_alloc().(CVE-2024-56604)\n\nIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() bt_sock_alloc() allocates the sk object and attaches it to the provided sock object. On error l2cap_sock_alloc() frees the sk object, but the dangling pointer is still attached to the sock object, which may create use-after-free in other code.(CVE-2024-56605)\n\nIn the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds access in \'dcn21_link_encoder_create\' An issue was identified in the dcn21_link_encoder_create function where an out-of-bounds access could occur when the hpd_source index was used to reference the link_enc_hpd_regs array. This array has a fixed size and the index was not being checked against the array\'s bounds before accessing it. This fix adds a conditional check to ensure that the hpd_source index is within the valid range of the link_enc_hpd_regs array. If the index is out of bounds, the function now returns NULL to prevent undefined behavior. References: [ 65.920507] ------------[ cut here ]------------ [ 65.920510] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn21/dcn21_resource.c:1312:29 [ 65.920519] index 7 is out of range for type \'dcn10_link_enc_hpd_registers [5]\' [ 65.920523] CPU: 3 PID: 1178 Comm: modprobe Tainted: G OE 6.8.0-cleanershaderfeatureresetasdntipmi200nv2132 #13 [ 65.920525] Hardware name: AMD Majolica-RN/Majolica-RN, BIOS WMJ0429N_Weekly_20_04_2 04/29/2020 [ 65.920527] Call Trace: [ 65.920529] <TASK> [ 65.920532] dump_stack_lvl+0x48/0x70 [ 65.920541] dump_stack+0x10/0x20 [ 65.920543] __ubsan_handle_out_of_bounds+0xa2/0xe0 [ 65.920549] dcn21_link_encoder_create+0xd9/0x140 [amdgpu] [ 65.921009] link_create+0x6d3/0xed0 [amdgpu] [ 65.921355] create_links+0x18a/0x4e0 [amdgpu] [ 65.921679] dc_create+0x360/0x720 [amdgpu] [ 65.921999] ? dmi_matches+0xa0/0x220 [ 65.922004] amdgpu_dm_init+0x2b6/0x2c90 [amdgpu] [ 65.922342] ? console_unlock+0x77/0x120 [ 65.922348] ? dev_printk_emit+0x86/0xb0 [ 65.922354] dm_hw_init+0x15/0x40 [amdgpu] [ 65.922686] amdgpu_device_init+0x26a8/0x33a0 [amdgpu] [ 65.922921] amdgpu_driver_load_kms+0x1b/0xa0 [amdgpu] [ 65.923087] amdgpu_pci_probe+0x1b7/0x630 [amdgpu] [ 65.923087] local_pci_probe+0x4b/0xb0 [ 65.923087] pci_device_probe+0xc8/0x280 [ 65.923087] really_probe+0x187/0x300 [ 65.923087] __driver_probe_device+0x85/0x130 [ 65.923087] driver_probe_device+0x24/0x110 [ 65.923087] __driver_attach+0xac/0x1d0 [ 65.923087] ? __pfx___driver_attach+0x10/0x10 [ 65.923087] bus_for_each_dev+0x7d/0xd0 [ 65.923087] driver_attach+0x1e/0x30 [ 65.923087] bus_add_driver+0xf2/0x200 [ 65.923087] driver_register+0x64/0x130 [ 65.923087] ? __pfx_amdgpu_init+0x10/0x10 [amdgpu] [ 65.923087] __pci_register_driver+0x61/0x70 [ 65.923087] amdgpu_init+0x7d/0xff0 [amdgpu] [ 65.923087] do_one_initcall+0x49/0x310 [ 65.923087] ? kmalloc_trace+0x136/0x360 [ 65.923087] do_init_module+0x6a/0x270 [ 65.923087] load_module+0x1fce/0x23a0 [ 65.923087] init_module_from_file+0x9c/0xe0 [ 65.923087] ? init_module_from_file+0x9c/0xe0 [ 65.923087] idempotent_init_module+0x179/0x230 [ 65.923087] __x64_sys_finit_module+0x5d/0xa0 [ 65.923087] do_syscall_64+0x76/0x120 [ 65.923087] entry_SYSCALL_64_after_hwframe+0x6e/0x76 [ 65.923087] RIP: 0033:0x7f2d80f1e88d [ 65.923087] Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 b5 0f 00 f7 d8 64 89 01 48 [ 65.923087] RSP: 002b:00007ffc7bc1aa78 EFLAGS: 00000246 ORIG_RAX: 0000000000000139 [ 65.923087] RAX: ffffffffffffffda RBX: 0000564c9c1db130 RCX: 00007f2d80f1e88d [ 65.923087] RDX: 0000000000000000 RSI: 0000564c9c1e5480 RDI: 000000000000000f [ 65.923087] RBP: 0000000000040000 R08: 0000000000000000 R09: 0000000000000002 [ 65.923087] R10: 000000000000000f R11: 0000000000000246 R12: 0000564c9c1e5480 [ 65.923087] R13: 0000564c9c1db260 R14: 0000000000000000 R15: 0000564c9c1e54b0 [ 65.923087] </TASK> [ 65.923927] ---[ end trace ]---(CVE-2024-56608)\n\nIn the Linux kernel, the following vulnerability has been resolved: bpf: fix OOB devmap writes when deleting elements Jordy reported issue against XSKMAP which also applies to DEVMAP - the index used for accessing map entry, due to being a signed integer, causes the OOB writes. Fix is simple as changing the type from int to u32, however, when compared to XSKMAP case, one more thing needs to be addressed. When map is released from system via dev_map_free(), we iterate through all of the entries and an iterator variable is also an int, which implies OOB accesses. Again, change it to be u32. Example splat below: [ 160.724676] BUG: unable to handle page fault for address: ffffc8fc2c001000 [ 160.731662] #PF: supervisor read access in kernel mode [ 160.736876] #PF: error_code(0x0000) - not-present page [ 160.742095] PGD 0 P4D 0 [ 160.744678] Oops: Oops: 0000 [#1] PREEMPT SMP [ 160.749106] CPU: 1 UID: 0 PID: 520 Comm: kworker/u145:12 Not tainted 6.12.0-rc1+ #487 [ 160.757050] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019 [ 160.767642] Workqueue: events_unbound bpf_map_free_deferred [ 160.773308] RIP: 0010:dev_map_free+0x77/0x170 [ 160.777735] Code: 00 e8 fd 91 ed ff e8 b8 73 ed ff 41 83 7d 18 19 74 6e 41 8b 45 24 49 8b bd f8 00 00 00 31 db 85 c0 74 48 48 63 c3 48 8d 04 c7 <48> 8b 28 48 85 ed 74 30 48 8b 7d 18 48 85 ff 74 05 e8 b3 52 fa ff [ 160.796777] RSP: 0018:ffffc9000ee1fe38 EFLAGS: 00010202 [ 160.802086] RAX: ffffc8fc2c001000 RBX: 0000000080000000 RCX: 0000000000000024 [ 160.809331] RDX: 0000000000000000 RSI: 0000000000000024 RDI: ffffc9002c001000 [ 160.816576] RBP: 0000000000000000 R08: 0000000000000023 R09: 0000000000000001 [ 160.823823] R10: 0000000000000001 R11: 00000000000ee6b2 R12: dead000000000122 [ 160.831066] R13: ffff88810c928e00 R14: ffff8881002df405 R15: 0000000000000000 [ 160.838310] FS: 0000000000000000(0000) GS:ffff8897e0c40000(0000) knlGS:0000000000000000 [ 160.846528] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 160.852357] CR2: ffffc8fc2c001000 CR3: 0000000005c32006 CR4: 00000000007726f0 [ 160.859604] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 160.866847] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 160.874092] PKRU: 55555554 [ 160.876847] Call Trace: [ 160.879338] <TASK> [ 160.881477] ? __die+0x20/0x60 [ 160.884586] ? page_fault_oops+0x15a/0x450 [ 160.888746] ? search_extable+0x22/0x30 [ 160.892647] ? search_bpf_extables+0x5f/0x80 [ 160.896988] ? exc_page_fault+0xa9/0x140 [ 160.900973] ? asm_exc_page_fault+0x22/0x30 [ 160.905232] ? dev_map_free+0x77/0x170 [ 160.909043] ? dev_map_free+0x58/0x170 [ 160.912857] bpf_map_free_deferred+0x51/0x90 [ 160.917196] process_one_work+0x142/0x370 [ 160.921272] worker_thread+0x29e/0x3b0 [ 160.925082] ? rescuer_thread+0x4b0/0x4b0 [ 160.929157] kthread+0xd4/0x110 [ 160.932355] ? kthread_park+0x80/0x80 [ 160.936079] ret_from_fork+0x2d/0x50 [ 160.943396] ? kthread_park+0x80/0x80 [ 160.950803] ret_from_fork_asm+0x11/0x20 [ 160.958482] </TASK>(CVE-2024-56615)\n\nIn the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry() Syzbot reported that when searching for records in a directory where the inode\'s i_size is corrupted and has a large value, memory access outside the folio/page range may occur, or a use-after-free bug may be detected if KASAN is enabled. This is because nilfs_last_byte(), which is called by nilfs_find_entry() and others to calculate the number of valid bytes of directory data in a page from i_size and the page index, loses the upper 32 bits of the 64-bit size information due to an inappropriate type of local variable to which the i_size value is assigned. This caused a large byte offset value due to underflow in the end address calculation in the calling nilfs_find_entry(), resulting in memory access that exceeds the folio/page size. Fix this issue by changing the type of the local variable causing the bit loss from "unsigned int" to "u64". The return value of nilfs_last_byte() is also of type "unsigned int", but it is truncated so as not to exceed PAGE_SIZE and no bit loss occurs, so no change is required.(CVE-2024-56619)\n\nIn the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf. Note that this issue is coming when setting \'vfs objects = streams_xattr parameter\' in ksmbd.conf.(CVE-2024-56627)\n\nIn the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix when get product name maybe null pointer Due to incorrect dev->product reporting by certain devices, null pointer dereferences occur when dev->product is empty, leading to potential system crashes. This issue was found on EXCELSIOR DL37-D05 device with Loongson-LS3A6000-7A2000-DL37 motherboard. Kernel logs: [ 56.470885] usb 4-3: new full-speed USB device number 4 using ohci-pci [ 56.671638] usb 4-3: string descriptor 0 read error: -22 [ 56.671644] usb 4-3: New USB device found, idVendor=056a, idProduct=0374, bcdDevice= 1.07 [ 56.671647] usb 4-3: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 56.678839] hid-generic 0003:056A:0374.0004: hiddev0,hidraw3: USB HID v1.10 Device [HID 056a:0374] on usb-0000:00:05.0-3/input0 [ 56.697719] CPU 2 Unable to handle kernel paging request at virtual address 0000000000000000, era == 90000000066e35c8, ra == ffff800004f98a80 [ 56.697732] Oops[#1]: [ 56.697734] CPU: 2 PID: 2742 Comm: (udev-worker) Tainted: G OE 6.6.0-loong64-desktop #25.00.2000.015 [ 56.697737] Hardware name: Inspur CE520L2/C09901N000000000, BIOS 2.09.00 10/11/2024 [ 56.697739] pc 90000000066e35c8 ra ffff800004f98a80 tp 9000000125478000 sp 900000012547b8a0 [ 56.697741] a0 0000000000000000 a1 ffff800004818b28 a2 0000000000000000 a3 0000000000000000 [ 56.697743] a4 900000012547b8f0 a5 0000000000000000 a6 0000000000000000 a7 0000000000000000 [ 56.697745] t0 ffff800004818b2d t1 0000000000000000 t2 0000000000000003 t3 0000000000000005 [ 56.697747] t4 0000000000000000 t5 0000000000000000 t6 0000000000000000 t7 0000000000000000 [ 56.697748] t8 0000000000000000 u0 0000000000000000 s9 0000000000000000 s0 900000011aa48028 [ 56.697750] s1 0000000000000000 s2 0000000000000000 s3 ffff800004818e80 s4 ffff800004810000 [ 56.697751] s5 90000001000b98d0 s6 ffff800004811f88 s7 ffff800005470440 s8 0000000000000000 [ 56.697753] ra: ffff800004f98a80 wacom_update_name+0xe0/0x300 [wacom] [ 56.697802] ERA: 90000000066e35c8 strstr+0x28/0x120 [ 56.697806] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) [ 56.697816] PRMD: 0000000c (PPLV0 +PIE +PWE) [ 56.697821] EUEN: 00000000 (-FPE -SXE -ASXE -BTE) [ 56.697827] ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7) [ 56.697831] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0) [ 56.697835] BADV: 0000000000000000 [ 56.697836] PRID: 0014d000 (Loongson-64bit, Loongson-3A6000) [ 56.697838] Modules linked in: wacom(+) bnep bluetooth rfkill qrtr nls_iso8859_1 nls_cp437 snd_hda_codec_conexant snd_hda_codec_generic ledtrig_audio snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_timer snd soundcore input_leds mousedev led_class joydev deepin_netmonitor(OE) fuse nfnetlink dmi_sysfs ip_tables x_tables overlay amdgpu amdxcp drm_exec gpu_sched drm_buddy radeon drm_suballoc_helper i2c_algo_bit drm_ttm_helper r8169 ttm drm_display_helper spi_loongson_pci xhci_pci cec xhci_pci_renesas spi_loongson_core hid_generic realtek gpio_loongson_64bit [ 56.697887] Process (udev-worker) (pid: 2742, threadinfo=00000000aee0d8b4, task=00000000a9eff1f3) [ 56.697890] Stack : 0000000000000000 ffff800004817e00 0000000000000000 0000251c00000000 [ 56.697896] 0000000000000000 00000011fffffffd 0000000000000000 0000000000000000 [ 56.697901] 0000000000000000 1b67a968695184b9 0000000000000000 90000001000b98d0 [ 56.697906] 90000001000bb8d0 900000011aa48028 0000000000000000 ffff800004f9d74c [ 56.697911] 90000001000ba000 ffff800004f9ce58 0000000000000000 ffff800005470440 [ 56.697916] ffff800004811f88 90000001000b98d0 9000000100da2aa8 90000001000bb8d0 [ 56.697921] 0000000000000000 90000001000ba000 900000011aa48028 ffff800004f9d74c [ 56.697926] ffff8000054704e8 90000001000bb8b8 90000001000ba000 0000000000000000 [ 56.697931] 90000001000bb8d0 ---truncated---(CVE-2024-56629)\n\nIn the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix UAF in blkcg_unpin_online() blkcg_unpin_online() walks up the blkcg hierarchy putting the online pin. To walk up, it uses blkcg_parent(blkcg) but it was calling that after blkcg_destroy_blkgs(blkcg) which could free the blkcg, leading to the following UAF: ================================================================== BUG: KASAN: slab-use-after-free in blkcg_unpin_online+0x15a/0x270 Read of size 8 at addr ffff8881057678c0 by task kworker/9:1/117 CPU: 9 UID: 0 PID: 117 Comm: kworker/9:1 Not tainted 6.13.0-rc1-work-00182-gb8f52214c61a-dirty #48 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022 Workqueue: cgwb_release cgwb_release_workfn Call Trace: <TASK> dump_stack_lvl+0x27/0x80 print_report+0x151/0x710 kasan_report+0xc0/0x100 blkcg_unpin_online+0x15a/0x270 cgwb_release_workfn+0x194/0x480 process_scheduled_works+0x71b/0xe20 worker_thread+0x82a/0xbd0 kthread+0x242/0x2c0 ret_from_fork+0x33/0x70 ret_from_fork_asm+0x1a/0x30 </TASK> ... Freed by task 1944: kasan_save_track+0x2b/0x70 kasan_save_free_info+0x3c/0x50 __kasan_slab_free+0x33/0x50 kfree+0x10c/0x330 css_free_rwork_fn+0xe6/0xb30 process_scheduled_works+0x71b/0xe20 worker_thread+0x82a/0xbd0 kthread+0x242/0x2c0 ret_from_fork+0x33/0x70 ret_from_fork_asm+0x1a/0x30 Note that the UAF is not easy to trigger as the free path is indirected behind a couple RCU grace periods and a work item execution. I could only trigger it with artifical msleep() injected in blkcg_unpin_online(). Fix it by reading the parent pointer before destroying the blkcg\'s blkg\'s.(CVE-2024-56672)\n\nIn the Linux kernel, the following vulnerability has been resolved: crypto: bcm - add error check in the ahash_hmac_init function The ahash_init functions may return fails. The ahash_hmac_init should not return ok when ahash_init returns error. For an example, ahash_init will return -ENOMEM when allocation memory is error.(CVE-2024-56681)\n\nIn the Linux kernel, the following vulnerability has been resolved: ext4: fix race in buffer_head read fault injection When I enabled ext4 debug for fault injection testing, I encountered the following warning: EXT4-fs error (device sda): ext4_read_inode_bitmap:201: comm fsstress: Cannot read inode bitmap - block_group = 8, inode_bitmap = 1051 WARNING: CPU: 0 PID: 511 at fs/buffer.c:1181 mark_buffer_dirty+0x1b3/0x1d0 The root cause of the issue lies in the improper implementation of ext4\'s buffer_head read fault injection. The actual completion of buffer_head read and the buffer_head fault injection are not atomic, which can lead to the uptodate flag being cleared on normally used buffer_heads in race conditions. [CPU0] [CPU1] [CPU2] ext4_read_inode_bitmap ext4_read_bh() <bh read complete> ext4_read_inode_bitmap if (buffer_uptodate(bh)) return bh jbd2_journal_commit_transaction __jbd2_journal_refile_buffer __jbd2_journal_unfile_buffer __jbd2_journal_temp_unlink_buffer ext4_simulate_fail_bh() clear_buffer_uptodate mark_buffer_dirty <report warning> WARN_ON_ONCE(!buffer_uptodate(bh)) The best approach would be to perform fault injection in the IO completion callback function, rather than after IO completion. However, the IO completion callback function cannot get the fault injection code in sb. Fix it by passing the result of fault injection into the bh read function, we simulate faults within the bh read function itself. This requires adding an extra parameter to the bh read functions that need fault injection.(CVE-2024-56686)\n\nIn the Linux kernel, the following vulnerability has been resolved: mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device While design wise the idea of converting the driver to use the hierarchy of the IRQ chips is correct, the implementation has (inherited) flaws. This was unveiled when platform_get_irq() had started WARN() on IRQ 0 that is supposed to be a Linux IRQ number (also known as vIRQ). Rework the driver to respect IRQ domain when creating each MFD device separately, as the domain is not the same for all of them.(CVE-2024-56691)\n\nIn the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node blkaddr in truncate_node() syzbot reports a f2fs bug as below: ------------[ cut here ]------------ kernel BUG at fs/f2fs/segment.c:2534! RIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534 Call Trace: truncate_node+0x1ae/0x8c0 fs/f2fs/node.c:909 f2fs_remove_inode_page+0x5c2/0x870 fs/f2fs/node.c:1288 f2fs_evict_inode+0x879/0x15c0 fs/f2fs/inode.c:856 evict+0x4e8/0x9b0 fs/inode.c:723 f2fs_handle_failed_inode+0x271/0x2e0 fs/f2fs/inode.c:986 f2fs_create+0x357/0x530 fs/f2fs/namei.c:394 lookup_open fs/namei.c:3595 [inline] open_last_lookups fs/namei.c:3694 [inline] path_openat+0x1c03/0x3590 fs/namei.c:3930 do_filp_open+0x235/0x490 fs/namei.c:3960 do_sys_openat2+0x13e/0x1d0 fs/open.c:1415 do_sys_open fs/open.c:1430 [inline] __do_sys_openat fs/open.c:1446 [inline] __se_sys_openat fs/open.c:1441 [inline] __x64_sys_openat+0x247/0x2a0 fs/open.c:1441 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534 The root cause is: on a fuzzed image, blkaddr in nat entry may be corrupted, then it will cause system panic when using it in f2fs_invalidate_blocks(), to avoid this, let\'s add sanity check on nat blkaddr in truncate_node().(CVE-2024-56692)\n\nIn the Linux kernel, the following vulnerability has been resolved: media: wl128x: Fix atomicity violation in fmc_send_cmd() Atomicity violation occurs when the fmc_send_cmd() function is executed simultaneously with the modification of the fmdev->resp_skb value. Consider a scenario where, after passing the validity check within the function, a non-null fmdev->resp_skb variable is assigned a null value. This results in an invalid fmdev->resp_skb variable passing the validity check. As seen in the later part of the function, skb = fmdev->resp_skb; when the invalid fmdev->resp_skb passes the check, a null pointer dereference error may occur at line 478, evt_hdr = (void *)skb->data; To address this issue, it is recommended to include the validity check of fmdev->resp_skb within the locked section of the function. This modification ensures that the value of fmdev->resp_skb does not change during the validation process, thereby maintaining its validity. This possible bug is found by an experimental static analysis tool developed by our team. This tool analyzes the locking APIs to extract function pairs that can be concurrently executed, and then analyzes the instructions in the paired functions to identify possible concurrency bugs including data races and atomicity violations.(CVE-2024-56700)\n\nIn the Linux kernel, the following vulnerability has been resolved: io_uring: check if iowq is killed before queuing task work can be executed after the task has gone through io_uring termination, whether it\'s the final task_work run or the fallback path. In this case, task work will find ->io_wq being already killed and null\'ed, which is a problem if it then tries to forward the request to io_queue_iowq(). Make io_queue_iowq() fail requests in this case. Note that it also checks PF_KTHREAD, because the user can first close a DEFER_TASKRUN ring and shortly after kill the task, in which case ->iowq check would race.(CVE-2024-56709)\n\nIn the Linux kernel, the following vulnerability has been resolved: rtc: check if __rtc_read_time was successful in rtc_timer_do_work() If the __rtc_read_time call fails,, the struct rtc_time tm; may contain uninitialized data, or an illegal date/time read from the RTC hardware. When calling rtc_tm_to_ktime later, the result may be a very large value (possibly KTIME_MAX). If there are periodic timers in rtc->timerqueue, they will continually expire, may causing kernel softlockup.(CVE-2024-56739)\n\nIn the Linux kernel, the following vulnerability has been resolved: apparmor: test: Fix memory leak for aa_unpack_strdup() The string allocated by kmemdup() in aa_unpack_strdup() is not freed and cause following memory leaks, free them to fix it. unreferenced object 0xffffff80c6af8a50 (size 8): comm "kunit_try_catch", pid 225, jiffies 4294894407 hex dump (first 8 bytes): 74 65 73 74 69 6e 67 00 testing. backtrace (crc 5eab668b): [<0000000001e3714d>] kmemleak_alloc+0x34/0x40 [<000000006e6c7776>] __kmalloc_node_track_caller_noprof+0x300/0x3e0 [<000000006870467c>] kmemdup_noprof+0x34/0x60 [<000000001176bb03>] aa_unpack_strdup+0xd0/0x18c [<000000008ecde918>] policy_unpack_test_unpack_strdup_with_null_name+0xf8/0x3ec [<0000000032ef8f77>] kunit_try_run_case+0x13c/0x3ac [<00000000f3edea23>] kunit_generic_run_threadfn_adapter+0x80/0xec [<00000000adf936cf>] kthread+0x2e8/0x374 [<0000000041bb1628>] ret_from_fork+0x10/0x20 unreferenced object 0xffffff80c2a29090 (size 8): comm "kunit_try_catch", pid 227, jiffies 4294894409 hex dump (first 8 bytes): 74 65 73 74 69 6e 67 00 testing. backtrace (crc 5eab668b): [<0000000001e3714d>] kmemleak_alloc+0x34/0x40 [<000000006e6c7776>] __kmalloc_node_track_caller_noprof+0x300/0x3e0 [<000000006870467c>] kmemdup_noprof+0x34/0x60 [<000000001176bb03>] aa_unpack_strdup+0xd0/0x18c [<0000000046a45c1a>] policy_unpack_test_unpack_strdup_with_name+0xd0/0x3c4 [<0000000032ef8f77>] kunit_try_run_case+0x13c/0x3ac [<00000000f3edea23>] kunit_generic_run_threadfn_adapter+0x80/0xec [<00000000adf936cf>] kthread+0x2e8/0x374 [<0000000041bb1628>] ret_from_fork+0x10/0x20(CVE-2024-56741)\n\nIn the Linux kernel, the following vulnerability has been resolved: scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb() Hook "qedi_ops->common->sb_init = qed_sb_init" does not release the DMA memory sb_virt when it fails. Add dma_free_coherent() to free it. This is the same way as qedr_alloc_mem_sb() and qede_alloc_mem_sb().(CVE-2024-56747)\n\nIn the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb() Hook "qed_ops->common->sb_init = qed_sb_init" does not release the DMA memory sb_virt when it fails. Add dma_free_coherent() to free it. This is the same way as qedr_alloc_mem_sb() and qede_alloc_mem_sb().(CVE-2024-56748)\n\nIn the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix freeing of the HMB descriptor table The HMB descriptor table is sized to the maximum number of descriptors that could be used for a given device, but __nvme_alloc_host_mem could break out of the loop earlier on memory allocation failure and end up using less descriptors than planned for, which leads to an incorrect size passed to dma_free_coherent. In practice this was not showing up because the number of descriptors tends to be low and the dma coherent allocator always allocates and frees at least a page.(CVE-2024-56756)\n\nIn the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_write If a large count is provided, it will trigger a warning in bitmap_parse_user. Also check zero for it.(CVE-2024-56763)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'kernel', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for kernel is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2025-1037', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2025-01-10T21:10:50+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2025-01-10T21:10:50+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2025-01-10T21:10:50+08:00', 'initial_release_date': '2025-01-10T21:10:50+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'summary': 'openEuler-SA-2025-1037', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2022-49034&packageName=kernel', 'summary': 'CVE-2022-49034', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-47730&packageName=kernel', 'summary': 'CVE-2024-47730', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-49907&packageName=kernel', 'summary': 'CVE-2024-49907', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50001&packageName=kernel', 'summary': 'CVE-2024-50001', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50188&packageName=kernel', 'summary': 'CVE-2024-50188', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50233&packageName=kernel', 'summary': 'CVE-2024-50233', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-50264&packageName=kernel', 'summary': 'CVE-2024-50264', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53146&packageName=kernel', 'summary': 'CVE-2024-53146', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53147&packageName=kernel', 'summary': 'CVE-2024-53147', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53155&packageName=kernel', 'summary': 'CVE-2024-53155', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53158&packageName=kernel', 'summary': 'CVE-2024-53158', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53161&packageName=kernel', 'summary': 'CVE-2024-53161', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53165&packageName=kernel', 'summary': 'CVE-2024-53165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53173&packageName=kernel', 'summary': 'CVE-2024-53173', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53185&packageName=kernel', 'summary': 'CVE-2024-53185', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53187&packageName=kernel', 'summary': 'CVE-2024-53187', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53194&packageName=kernel', 'summary': 'CVE-2024-53194', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53197&packageName=kernel', 'summary': 'CVE-2024-53197', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53217&packageName=kernel', 'summary': 'CVE-2024-53217', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53218&packageName=kernel', 'summary': 'CVE-2024-53218', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53219&packageName=kernel', 'summary': 'CVE-2024-53219', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53221&packageName=kernel', 'summary': 'CVE-2024-53221', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53224&packageName=kernel', 'summary': 'CVE-2024-53224', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-53227&packageName=kernel', 'summary': 'CVE-2024-53227', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56538&packageName=kernel', 'summary': 'CVE-2024-56538', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56548&packageName=kernel', 'summary': 'CVE-2024-56548', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56562&packageName=kernel', 'summary': 'CVE-2024-56562', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56569&packageName=kernel', 'summary': 'CVE-2024-56569', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56570&packageName=kernel', 'summary': 'CVE-2024-56570', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56572&packageName=kernel', 'summary': 'CVE-2024-56572', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56581&packageName=kernel', 'summary': 'CVE-2024-56581', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56583&packageName=kernel', 'summary': 'CVE-2024-56583', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56584&packageName=kernel', 'summary': 'CVE-2024-56584', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56586&packageName=kernel', 'summary': 'CVE-2024-56586', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56594&packageName=kernel', 'summary': 'CVE-2024-56594', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56596&packageName=kernel', 'summary': 'CVE-2024-56596', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56598&packageName=kernel', 'summary': 'CVE-2024-56598', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56604&packageName=kernel', 'summary': 'CVE-2024-56604', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56605&packageName=kernel', 'summary': 'CVE-2024-56605', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56608&packageName=kernel', 'summary': 'CVE-2024-56608', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56615&packageName=kernel', 'summary': 'CVE-2024-56615', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56619&packageName=kernel', 'summary': 'CVE-2024-56619', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56627&packageName=kernel', 'summary': 'CVE-2024-56627', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56629&packageName=kernel', 'summary': 'CVE-2024-56629', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56672&packageName=kernel', 'summary': 'CVE-2024-56672', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56681&packageName=kernel', 'summary': 'CVE-2024-56681', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56686&packageName=kernel', 'summary': 'CVE-2024-56686', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56691&packageName=kernel', 'summary': 'CVE-2024-56691', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56692&packageName=kernel', 'summary': 'CVE-2024-56692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56700&packageName=kernel', 'summary': 'CVE-2024-56700', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56709&packageName=kernel', 'summary': 'CVE-2024-56709', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56739&packageName=kernel', 'summary': 'CVE-2024-56739', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56741&packageName=kernel', 'summary': 'CVE-2024-56741', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56747&packageName=kernel', 'summary': 'CVE-2024-56747', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56748&packageName=kernel', 'summary': 'CVE-2024-56748', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56756&packageName=kernel', 'summary': 'CVE-2024-56756', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56763&packageName=kernel', 'summary': 'CVE-2024-56763', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2022-49034', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-47730', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-49907', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50001', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50188', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50233', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-50264', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53146', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53147', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53155', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53158', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53161', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53173', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53185', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53187', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53194', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53197', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53218', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53219', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53221', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53224', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-53227', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56538', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56548', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56562', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56569', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56570', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56572', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56581', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56583', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56584', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56586', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56594', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56596', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56598', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56604', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56605', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56608', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56615', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56619', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56627', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56629', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56672', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56681', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56686', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56691', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56700', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56709', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56739', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56741', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56747', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56748', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56756', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56763', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2025/csaf-openeuler-sa-2025-1037.json', 'summary': 'openEuler-SA-2025-1037 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product': {'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product': {'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src.rpm', 'product': {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src.rpm', 'product_id': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64'}, 'product_reference': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64'}, 'product_reference': 'python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src'}, 'product_reference': 'kernel-5.10.0-245.0.0.144.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-49034', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK\n\nWhen CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected,\ncpu_max_bits_warn() generates a runtime warning similar as below when\nshowing /proc/cpuinfo. Fix this by using nr_cpu_ids (the runtime limit)\ninstead of NR_CPUS to iterate CPUs.\n\n[ 3.052463] ------------[ cut here ]------------\n[ 3.059679] WARNING: CPU: 3 PID: 1 at include/linux/cpumask.h:108 show_cpuinfo+0x5e8/0x5f0\n[ 3.070072] Modules linked in: efivarfs autofs4\n[ 3.076257] CPU: 0 PID: 1 Comm: systemd Not tainted 5.19-rc5+ #1052\n[ 3.099465] Stack : 9000000100157b08 9000000000f18530 9000000000cf846c 9000000100154000\n[ 3.109127] 9000000100157a50 0000000000000000 9000000100157a58 9000000000ef7430\n[ 3.118774] 90000001001578e8 0000000000000040 0000000000000020 ffffffffffffffff\n[ 3.128412] 0000000000aaaaaa 1ab25f00eec96a37 900000010021de80 900000000101c890\n[ 3.138056] 0000000000000000 0000000000000000 0000000000000000 0000000000aaaaaa\n[ 3.147711] ffff8000339dc220 0000000000000001 0000000006ab4000 0000000000000000\n[ 3.157364] 900000000101c998 0000000000000004 9000000000ef7430 0000000000000000\n[ 3.167012] 0000000000000009 000000000000006c 0000000000000000 0000000000000000\n[ 3.176641] 9000000000d3de08 9000000001639390 90000000002086d8 00007ffff0080286\n[ 3.186260] 00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c\n[ 3.195868] ...\n[ 3.199917] Call Trace:\n[ 3.203941] [<90000000002086d8>] show_stack+0x38/0x14c\n[ 3.210666] [<9000000000cf846c>] dump_stack_lvl+0x60/0x88\n[ 3.217625] [<900000000023d268>] __warn+0xd0/0x100\n[ 3.223958] [<9000000000cf3c90>] warn_slowpath_fmt+0x7c/0xcc\n[ 3.231150] [<9000000000210220>] show_cpuinfo+0x5e8/0x5f0\n[ 3.238080] [<90000000004f578c>] seq_read_iter+0x354/0x4b4\n[ 3.245098] [<90000000004c2e90>] new_sync_read+0x17c/0x1c4\n[ 3.252114] [<90000000004c5174>] vfs_read+0x138/0x1d0\n[ 3.258694] [<90000000004c55f8>] ksys_read+0x70/0x100\n[ 3.265265] [<9000000000cfde9c>] do_syscall+0x7c/0x94\n[ 3.271820] [<9000000000202fe4>] handle_syscall+0xc4/0x160\n[ 3.281824] ---[ end trace 8b484262b4b8c24c ]---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-49034', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-47730', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - inject error before stopping queue\n\nThe master ooo cannot be completely closed when the\naccelerator core reports memory error. Therefore, the driver\nneeds to inject the qm error to close the master ooo. Currently,\nthe qm error is injected after stopping queue, memory may be\nreleased immediately after stopping queue, causing the device to\naccess the released memory. Therefore, error is injected to close master\nooo before stopping queue to ensure that the device does not access\nthe released memory.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-47730', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-49907', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before using dc->clk_mgr\n\n[WHY & HOW]\ndc->clk_mgr is null checked previously in the same function, indicating\nit might be null.\n\nPassing "dc" to "dc->hwss.apply_idle_power_optimizations", which\ndereferences null "dc->clk_mgr". (The function pointer resolves to\n"dcn35_apply_idle_power_optimizations".)\n\nThis fixes 1 FORWARD_NULL issue reported by Coverity.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-49907', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-50001', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix error path in multi-packet WQE transmit\n\nRemove the erroneous unmap in case no DMA mapping was established\n\nThe multi-packet WQE transmit code attempts to obtain a DMA mapping for\nthe skb. This could fail, e.g. under memory pressure, when the IOMMU\ndriver just can't allocate more memory for page tables. While the code\ntries to handle this in the path below the err_unmap label it erroneously\nunmaps one entry from the sq's FIFO list of active mappings. Since the\ncurrent map attempt failed this unmap is removing some random DMA mapping\nthat might still be required. If the PCI function now presents that IOVA,\nthe IOMMU may assumes a rogue DMA access and e.g. on s390 puts the PCI\nfunction in error state.\n\nThe erroneous behavior was seen in a stress-test environment that created\nmemory pressure.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-50001', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-50188', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: dp83869: fix memory corruption when enabling fiber\n\nWhen configuring the fiber port, the DP83869 PHY driver incorrectly\ncalls linkmode_set_bit() with a bit mask (1 << 10) rather than a bit\nnumber (10). This corrupts some other memory location -- in case of\narm64 the priv pointer in the same structure.\n\nSince the advertising flags are updated from supported at the end of the\nfunction the incorrect line isn't needed at all and can be removed.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-50188', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-50233', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: iio: frequency: ad9832: fix division by zero in ad9832_calc_freqreg()\n\nIn the ad9832_write_frequency() function, clk_get_rate() might return 0.\nThis can lead to a division by zero when calling ad9832_calc_freqreg().\nThe check if (fout > (clk_get_rate(st->mclk) / 2)) does not protect\nagainst the case when fout is 0. The ad9832_write_frequency() function\nis called from ad9832_write(), and fout is derived from a text buffer,\nwhich can contain any value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-50233', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-50264', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: Initialization of the dangling pointer occurring in vsk->trans\n\nDuring loopback communication, a dangling pointer can be created in\nvsk->trans, potentially leading to a Use-After-Free condition. This\nissue is resolved by initializing vsk->trans to NULL.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-50264', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53146', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent a potential integer overflow\n\nIf the tag length is >= U32_MAX - 3 then the "length + 4" addition\ncan result in an integer overflow. Address this by splitting the\ndecoding into several steps so that decode_cb_compound4res() does\nnot have to perform arithmetic on the unsafe length value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53146', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53147', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix out-of-bounds access of directory entries\n\nIn the case of the directory size is greater than or equal to\nthe cluster size, if start_clu becomes an EOF cluster(an invalid\ncluster) due to file system corruption, then the directory entry\nwhere ei->hint_femp.eidx hint is outside the directory, resulting\nin an out-of-bounds access, which may cause further file system\ncorruption.\n\nThis commit adds a check for start_clu, if it is an invalid cluster,\nthe file or directory will be treated as empty.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53147', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53155', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix uninitialized value in ocfs2_file_read_iter()\n\nSyzbot has reported the following KMSAN splat:\n\nBUG: KMSAN: uninit-value in ocfs2_file_read_iter+0x9a4/0xf80\n ocfs2_file_read_iter+0x9a4/0xf80\n __io_read+0x8d4/0x20f0\n io_read+0x3e/0xf0\n io_issue_sqe+0x42b/0x22c0\n io_wq_submit_work+0xaf9/0xdc0\n io_worker_handle_work+0xd13/0x2110\n io_wq_worker+0x447/0x1410\n ret_from_fork+0x6f/0x90\n ret_from_fork_asm+0x1a/0x30\n\nUninit was created at:\n __alloc_pages_noprof+0x9a7/0xe00\n alloc_pages_mpol_noprof+0x299/0x990\n alloc_pages_noprof+0x1bf/0x1e0\n allocate_slab+0x33a/0x1250\n ___slab_alloc+0x12ef/0x35e0\n kmem_cache_alloc_bulk_noprof+0x486/0x1330\n __io_alloc_req_refill+0x84/0x560\n io_submit_sqes+0x172f/0x2f30\n __se_sys_io_uring_enter+0x406/0x41c0\n __x64_sys_io_uring_enter+0x11f/0x1a0\n x64_sys_call+0x2b54/0x3ba0\n do_syscall_64+0xcd/0x1e0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nSince an instance of 'struct kiocb' may be passed from the block layer\nwith 'private' field uninitialized, introduce 'ocfs2_iocb_init_rw_locked()'\nand use it from where 'ocfs2_dio_end_io()' might take care, i.e. in\n'ocfs2_file_read_iter()' and 'ocfs2_file_write_iter()'.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53155', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53158', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()\n\nThis loop is supposed to break if the frequency returned from\nclk_round_rate() is the same as on the previous iteration. However,\nthat check doesn't make sense on the first iteration through the loop.\nIt leads to reading before the start of these->clk_perf_tbl[] array.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53158', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53161', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/bluefield: Fix potential integer overflow\n\nThe 64-bit argument for the "get DIMM info" SMC call consists of mem_ctrl_idx\nleft-shifted 16 bits and OR-ed with DIMM index. With mem_ctrl_idx defined as\n32-bits wide the left-shift operation truncates the upper 16 bits of\ninformation during the calculation of the SMC argument.\n\nThe mem_ctrl_idx stack variable must be defined as 64-bits wide to prevent any\npotential integer overflow, i.e. loss of data from upper 16 bits.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53161', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53165', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsh: intc: Fix use-after-free bug in register_intc_controller()\n\nIn the error handling for this function, d is freed without ever\nremoving it from intc_list which would lead to a use after free.\nTo fix this, let's only add it to the list after everything has\nsucceeded.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53165', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53173', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.0: Fix a use-after-free problem in the asynchronous open()\n\nYang Erkun reports that when two threads are opening files at the same\ntime, and are forced to abort before a reply is seen, then the call to\nnfs_release_seqid() in nfs4_opendata_free() can result in a\nuse-after-free of the pointer to the defunct rpc task of the other\nthread.\nThe fix is to ensure that if the RPC call is aborted before the call to\nnfs_wait_on_sequence() is complete, then we must call nfs_release_seqid()\nin nfs4_open_release() before the rpc_task is freed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53173', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53185', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix NULL ptr deref in crypto_aead_setkey()\n\nNeither SMB3.0 or SMB3.02 supports encryption negotiate context, so\nwhen SMB2_GLOBAL_CAP_ENCRYPTION flag is set in the negotiate response,\nthe client uses AES-128-CCM as the default cipher. See MS-SMB2\n3.3.5.4.\n\nCommit b0abcd65ec54 ("smb: client: fix UAF in async decryption") added\na @server->cipher_type check to conditionally call\nsmb3_crypto_aead_allocate(), but that check would always be false as\n@server->cipher_type is unset for SMB3.02.\n\nFix the following KASAN splat by setting @server->cipher_type for\nSMB3.02 as well.\n\nmount.cifs //srv/share /mnt -o vers=3.02,seal,...\n\nBUG: KASAN: null-ptr-deref in crypto_aead_setkey+0x2c/0x130\nRead of size 8 at addr 0000000000000020 by task mount.cifs/1095\nCPU: 1 UID: 0 PID: 1095 Comm: mount.cifs Not tainted 6.12.0 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41\n04/01/2014\nCall Trace:\n <TASK>\n dump_stack_lvl+0x5d/0x80\n ? crypto_aead_setkey+0x2c/0x130\n kasan_report+0xda/0x110\n ? crypto_aead_setkey+0x2c/0x130\n crypto_aead_setkey+0x2c/0x130\n crypt_message+0x258/0xec0 [cifs]\n ? __asan_memset+0x23/0x50\n ? __pfx_crypt_message+0x10/0x10 [cifs]\n ? mark_lock+0xb0/0x6a0\n ? hlock_class+0x32/0xb0\n ? mark_lock+0xb0/0x6a0\n smb3_init_transform_rq+0x352/0x3f0 [cifs]\n ? lock_acquire.part.0+0xf4/0x2a0\n smb_send_rqst+0x144/0x230 [cifs]\n ? __pfx_smb_send_rqst+0x10/0x10 [cifs]\n ? hlock_class+0x32/0xb0\n ? smb2_setup_request+0x225/0x3a0 [cifs]\n ? __pfx_cifs_compound_last_callback+0x10/0x10 [cifs]\n compound_send_recv+0x59b/0x1140 [cifs]\n ? __pfx_compound_send_recv+0x10/0x10 [cifs]\n ? __create_object+0x5e/0x90\n ? hlock_class+0x32/0xb0\n ? do_raw_spin_unlock+0x9a/0xf0\n cifs_send_recv+0x23/0x30 [cifs]\n SMB2_tcon+0x3ec/0xb30 [cifs]\n ? __pfx_SMB2_tcon+0x10/0x10 [cifs]\n ? lock_acquire.part.0+0xf4/0x2a0\n ? __pfx_lock_release+0x10/0x10\n ? do_raw_spin_trylock+0xc6/0x120\n ? lock_acquire+0x3f/0x90\n ? _get_xid+0x16/0xd0 [cifs]\n ? __pfx_SMB2_tcon+0x10/0x10 [cifs]\n ? cifs_get_smb_ses+0xcdd/0x10a0 [cifs]\n cifs_get_smb_ses+0xcdd/0x10a0 [cifs]\n ? __pfx_cifs_get_smb_ses+0x10/0x10 [cifs]\n ? cifs_get_tcp_session+0xaa0/0xca0 [cifs]\n cifs_mount_get_session+0x8a/0x210 [cifs]\n dfs_mount_share+0x1b0/0x11d0 [cifs]\n ? __pfx___lock_acquire+0x10/0x10\n ? __pfx_dfs_mount_share+0x10/0x10 [cifs]\n ? lock_acquire.part.0+0xf4/0x2a0\n ? find_held_lock+0x8a/0xa0\n ? hlock_class+0x32/0xb0\n ? lock_release+0x203/0x5d0\n cifs_mount+0xb3/0x3d0 [cifs]\n ? do_raw_spin_trylock+0xc6/0x120\n ? __pfx_cifs_mount+0x10/0x10 [cifs]\n ? lock_acquire+0x3f/0x90\n ? find_nls+0x16/0xa0\n ? smb3_update_mnt_flags+0x372/0x3b0 [cifs]\n cifs_smb3_do_mount+0x1e2/0xc80 [cifs]\n ? __pfx_vfs_parse_fs_string+0x10/0x10\n ? __pfx_cifs_smb3_do_mount+0x10/0x10 [cifs]\n smb3_get_tree+0x1bf/0x330 [cifs]\n vfs_get_tree+0x4a/0x160\n path_mount+0x3c1/0xfb0\n ? kasan_quarantine_put+0xc7/0x1d0\n ? __pfx_path_mount+0x10/0x10\n ? kmem_cache_free+0x118/0x3e0\n ? user_path_at+0x74/0xa0\n __x64_sys_mount+0x1a6/0x1e0\n ? __pfx___x64_sys_mount+0x10/0x10\n ? mark_held_locks+0x1a/0x90\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53185', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53187', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: check for overflows in io_pin_pages\n\nWARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144\nCPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0\nCall Trace:\n <TASK>\n __io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183\n io_rings_map io_uring/io_uring.c:2611 [inline]\n io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470\n io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692\n io_uring_setup io_uring/io_uring.c:3781 [inline]\n ...\n </TASK>\n\nio_pin_pages()'s uaddr parameter came directly from the user and can be\ngarbage. Don't just add size to it as it can overflow.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53187', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53194', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Fix use-after-free of slot->bus on hot remove\n\nDennis reports a boot crash on recent Lenovo laptops with a USB4 dock.\n\nSince commit 0fc70886569c ("thunderbolt: Reset USB4 v2 host router") and\ncommit 59a54c5f3dbd ("thunderbolt: Reset topology created by the boot\nfirmware"), USB4 v2 and v1 Host Routers are reset on probe of the\nthunderbolt driver.\n\nThe reset clears the Presence Detect State and Data Link Layer Link Active\nbits at the USB4 Host Router\'s Root Port and thus causes hot removal of the\ndock.\n\nThe crash occurs when pciehp is unbound from one of the dock\'s Downstream\nPorts: pciehp creates a pci_slot on bind and destroys it on unbind. The\npci_slot contains a pointer to the pci_bus below the Downstream Port, but\na reference on that pci_bus is never acquired. The pci_bus is destroyed\nbefore the pci_slot, so a use-after-free ensues when pci_slot_release()\naccesses slot->bus.\n\nIn principle this should not happen because pci_stop_bus_device() unbinds\npciehp (and therefore destroys the pci_slot) before the pci_bus is\ndestroyed by pci_remove_bus_device().\n\nHowever the stacktrace provided by Dennis shows that pciehp is unbound from\npci_remove_bus_device() instead of pci_stop_bus_device(). To understand\nthe significance of this, one needs to know that the PCI core uses a two\nstep process to remove a portion of the hierarchy: It first unbinds all\ndrivers in the sub-hierarchy in pci_stop_bus_device() and then actually\nremoves the devices in pci_remove_bus_device(). There is no precaution to\nprevent driver binding in-between pci_stop_bus_device() and\npci_remove_bus_device().\n\nIn Dennis\' case, it seems removal of the hierarchy by pciehp races with\ndriver binding by pci_bus_add_devices(). pciehp is bound to the\nDownstream Port after pci_stop_bus_device() has run, so it is unbound by\npci_remove_bus_device() instead of pci_stop_bus_device(). Because the\npci_bus has already been destroyed at that point, accesses to it result in\na use-after-free.\n\nOne might conclude that driver binding needs to be prevented after\npci_stop_bus_device() has run. However it seems risky that pci_slot points\nto pci_bus without holding a reference. Solely relying on correct ordering\nof driver unbind versus pci_bus destruction is certainly not defensive\nprogramming.\n\nIf pci_slot has a need to access data in pci_bus, it ought to acquire a\nreference. Amend pci_create_slot() accordingly. Dennis reports that the\ncrash is not reproducible with this change.\n\nAbridged stacktrace:\n\n pcieport 0000:00:07.0: PME: Signaling with IRQ 156\n pcieport 0000:00:07.0: pciehp: Slot #12 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ IbPresDis- LLActRep+\n pci_bus 0000:20: dev 00, created physical slot 12\n pcieport 0000:00:07.0: pciehp: Slot(12): Card not present\n ...\n pcieport 0000:21:02.0: pciehp: pcie_disable_notification: SLOTCTRL d8 write cmd 0\n Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 13 UID: 0 PID: 134 Comm: irq/156-pciehp Not tainted 6.11.0-devel+ #1\n RIP: 0010:dev_driver_string+0x12/0x40\n pci_destroy_slot\n pciehp_remove\n pcie_port_remove_service\n device_release_driver_internal\n bus_remove_device\n device_del\n device_unregister\n remove_iter\n device_for_each_child\n pcie_portdrv_remove\n pci_device_remove\n device_release_driver_internal\n bus_remove_device\n device_del\n pci_remove_bus_device (recursive invocation)\n pci_remove_bus_device\n pciehp_unconfigure_device\n pciehp_disable_slot\n pciehp_handle_presence_or_link_change\n pciehp_ist', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53194', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53197', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices\n\nA bogus device can provide a bNumConfigurations value that exceeds the\ninitial value used in usb_get_configuration for allocating dev->config.\n\nThis can lead to out-of-bounds accesses later, e.g. in\nusb_destroy_configuration.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53197', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53217', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent NULL dereference in nfsd4_process_cb_update()\n\n@ses is initialized to NULL. If __nfsd4_find_backchannel() finds no\navailable backchannel session, setup_callback_client() will try to\ndereference @ses and segfault.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53217', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53218', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix race in concurrent f2fs_stop_gc_thread\n\nIn my test case, concurrent calls to f2fs shutdown report the following\nstack trace:\n\n Oops: general protection fault, probably for non-canonical address 0xc6cfff63bb5513fc: 0000 [#1] PREEMPT SMP PTI\n CPU: 0 UID: 0 PID: 678 Comm: f2fs_rep_shutdo Not tainted 6.12.0-rc5-next-20241029-g6fb2fa9805c5-dirty #85\n Call Trace:\n <TASK>\n ? show_regs+0x8b/0xa0\n ? __die_body+0x26/0xa0\n ? die_addr+0x54/0x90\n ? exc_general_protection+0x24b/0x5c0\n ? asm_exc_general_protection+0x26/0x30\n ? kthread_stop+0x46/0x390\n f2fs_stop_gc_thread+0x6c/0x110\n f2fs_do_shutdown+0x309/0x3a0\n f2fs_ioc_shutdown+0x150/0x1c0\n __f2fs_ioctl+0xffd/0x2ac0\n f2fs_ioctl+0x76/0xe0\n vfs_ioctl+0x23/0x60\n __x64_sys_ioctl+0xce/0xf0\n x64_sys_call+0x2b1b/0x4540\n do_syscall_64+0xa7/0x240\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe root cause is a race condition in f2fs_stop_gc_thread() called from\ndifferent f2fs shutdown paths:\n\n [CPU0] [CPU1]\n ---------------------- -----------------------\n f2fs_stop_gc_thread f2fs_stop_gc_thread\n gc_th = sbi->gc_thread\n gc_th = sbi->gc_thread\n kfree(gc_th)\n sbi->gc_thread = NULL\n < gc_th != NULL >\n kthread_stop(gc_th->f2fs_gc_task) //UAF\n\nThe commit c7f114d864ac ("f2fs: fix to avoid use-after-free in\nf2fs_stop_gc_thread()") attempted to fix this issue by using a read\nsemaphore to prevent races between shutdown and remount threads, but\nit fails to prevent all race conditions.\n\nFix it by converting to write lock of s_umount in f2fs_do_shutdown().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53218', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53219', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtiofs: use pages instead of pointer for kernel direct IO\n\nWhen trying to insert a 10MB kernel module kept in a virtio-fs with cache\ndisabled, the following warning was reported:\n\n ------------[ cut here ]------------\n WARNING: CPU: 1 PID: 404 at mm/page_alloc.c:4551 ......\n Modules linked in:\n CPU: 1 PID: 404 Comm: insmod Not tainted 6.9.0-rc5+ #123\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ......\n RIP: 0010:__alloc_pages+0x2bf/0x380\n ......\n Call Trace:\n <TASK>\n ? __warn+0x8e/0x150\n ? __alloc_pages+0x2bf/0x380\n __kmalloc_large_node+0x86/0x160\n __kmalloc+0x33c/0x480\n virtio_fs_enqueue_req+0x240/0x6d0\n virtio_fs_wake_pending_and_unlock+0x7f/0x190\n queue_request_and_unlock+0x55/0x60\n fuse_simple_request+0x152/0x2b0\n fuse_direct_io+0x5d2/0x8c0\n fuse_file_read_iter+0x121/0x160\n __kernel_read+0x151/0x2d0\n kernel_read+0x45/0x50\n kernel_read_file+0x1a9/0x2a0\n init_module_from_file+0x6a/0xe0\n idempotent_init_module+0x175/0x230\n __x64_sys_finit_module+0x5d/0xb0\n x64_sys_call+0x1c3/0x9e0\n do_syscall_64+0x3d/0xc0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n ......\n </TASK>\n ---[ end trace 0000000000000000 ]---\n\nThe warning is triggered as follows:\n\n1) syscall finit_module() handles the module insertion and it invokes\nkernel_read_file() to read the content of the module first.\n\n2) kernel_read_file() allocates a 10MB buffer by using vmalloc() and\npasses it to kernel_read(). kernel_read() constructs a kvec iter by\nusing iov_iter_kvec() and passes it to fuse_file_read_iter().\n\n3) virtio-fs disables the cache, so fuse_file_read_iter() invokes\nfuse_direct_io(). As for now, the maximal read size for kvec iter is\nonly limited by fc->max_read. For virtio-fs, max_read is UINT_MAX, so\nfuse_direct_io() doesn't split the 10MB buffer. It saves the address and\nthe size of the 10MB-sized buffer in out_args[0] of a fuse request and\npasses the fuse request to virtio_fs_wake_pending_and_unlock().\n\n4) virtio_fs_wake_pending_and_unlock() uses virtio_fs_enqueue_req() to\nqueue the request. Because virtiofs need DMA-able address, so\nvirtio_fs_enqueue_req() uses kmalloc() to allocate a bounce buffer for\nall fuse args, copies these args into the bounce buffer and passed the\nphysical address of the bounce buffer to virtiofsd. The total length of\nthese fuse args for the passed fuse request is about 10MB, so\ncopy_args_to_argbuf() invokes kmalloc() with a 10MB size parameter and\nit triggers the warning in __alloc_pages():\n\n\tif (WARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp))\n\t\treturn NULL;\n\n5) virtio_fs_enqueue_req() will retry the memory allocation in a\nkworker, but it won't help, because kmalloc() will always return NULL\ndue to the abnormal size and finit_module() will hang forever.\n\nA feasible solution is to limit the value of max_read for virtio-fs, so\nthe length passed to kmalloc() will be limited. However it will affect\nthe maximal read size for normal read. And for virtio-fs write initiated\nfrom kernel, it has the similar problem but now there is no way to limit\nfc->max_write in kernel.\n\nSo instead of limiting both the values of max_read and max_write in\nkernel, introducing use_pages_for_kvec_io in fuse_conn and setting it as\ntrue in virtiofs. When use_pages_for_kvec_io is enabled, fuse will use\npages instead of pointer to pass the KVEC_IO data.\n\nAfter switching to pages for KVEC_IO data, these pages will be used for\nDMA through virtio-fs. If these pages are backed by vmalloc(),\n{flush|invalidate}_kernel_vmap_range() are necessary to flush or\ninvalidate the cache before the DMA operation. So add two new fields in\nfuse_args_pages to record the base address of vmalloc area and the\ncondition indicating whether invalidation is needed. Perform the flush\nin fuse_get_user_pages() for write operations and the invalidation in\nfuse_release_user_pages() for read operations.\n\nIt may seem necessary to introduce another fie\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53219', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53221', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix null-ptr-deref in f2fs_submit_page_bio()\n\nThere\'s issue as follows when concurrently installing the f2fs.ko\nmodule and mounting the f2fs file system:\nKASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\nRIP: 0010:__bio_alloc+0x2fb/0x6c0 [f2fs]\nCall Trace:\n <TASK>\n f2fs_submit_page_bio+0x126/0x8b0 [f2fs]\n __get_meta_page+0x1d4/0x920 [f2fs]\n get_checkpoint_version.constprop.0+0x2b/0x3c0 [f2fs]\n validate_checkpoint+0xac/0x290 [f2fs]\n f2fs_get_valid_checkpoint+0x207/0x950 [f2fs]\n f2fs_fill_super+0x1007/0x39b0 [f2fs]\n mount_bdev+0x183/0x250\n legacy_get_tree+0xf4/0x1e0\n vfs_get_tree+0x88/0x340\n do_new_mount+0x283/0x5e0\n path_mount+0x2b2/0x15b0\n __x64_sys_mount+0x1fe/0x270\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nAbove issue happens as the biset of the f2fs file system is not\ninitialized before register "f2fs_fs_type".\nTo address above issue just register "f2fs_fs_type" at the last in\ninit_f2fs_fs(). Ensure that all f2fs file system resources are\ninitialized.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53221', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53224', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Move events notifier registration to be after device registration\n\nMove pkey change work initialization and cleanup from device resources\nstage to notifier stage, since this is the stage which handles this work\nevents.\n\nFix a race between the device deregistration and pkey change work by moving\nMLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to\nensure that the notifier is deregistered before the device during cleanup.\nWhich ensures there are no works that are being executed after the\ndevice has already unregistered which can cause the panic below.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1\nHardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023\nWorkqueue: events pkey_change_handler [mlx5_ib]\nRIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib]\nCode: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 <4c> 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40\nRSP: 0018:ffffbcc54068be20 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36\nRDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128\nRBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001\nR10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000\nR13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905\nFS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\nmlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib]\nprocess_one_work+0x1e8/0x3c0\nworker_thread+0x50/0x3b0\n? rescuer_thread+0x380/0x380\nkthread+0x149/0x170\n? set_kthread_struct+0x50/0x50\nret_from_fork+0x22/0x30\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core]\nCR2: 0000000000000000\n---[ end trace f6f8be4eae12f7bc ]---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53224', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-53227', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bfa: Fix use-after-free in bfad_im_module_exit()\n\nBUG: KASAN: slab-use-after-free in __lock_acquire+0x2aca/0x3a20\nRead of size 8 at addr ffff8881082d80c8 by task modprobe/25303\n\nCall Trace:\n <TASK>\n dump_stack_lvl+0x95/0xe0\n print_report+0xcb/0x620\n kasan_report+0xbd/0xf0\n __lock_acquire+0x2aca/0x3a20\n lock_acquire+0x19b/0x520\n _raw_spin_lock+0x2b/0x40\n attribute_container_unregister+0x30/0x160\n fc_release_transport+0x19/0x90 [scsi_transport_fc]\n bfad_im_module_exit+0x23/0x60 [bfa]\n bfad_init+0xdb/0xff0 [bfa]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n\nAllocated by task 25303:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x7f/0x90\n fc_attach_transport+0x4f/0x4740 [scsi_transport_fc]\n bfad_im_module_init+0x17/0x80 [bfa]\n bfad_init+0x23/0xff0 [bfa]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 25303:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x38/0x50\n kfree+0x212/0x480\n bfad_im_module_init+0x7e/0x80 [bfa]\n bfad_init+0x23/0xff0 [bfa]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nAbove issue happens as follows:\n\nbfad_init\n error = bfad_im_module_init()\n fc_release_transport(bfad_im_scsi_transport_template);\n if (error)\n goto ext;\n\next:\n bfad_im_module_exit();\n fc_release_transport(bfad_im_scsi_transport_template);\n --> Trigger double release\n\nDon't call bfad_im_module_exit() if bfad_im_module_init() failed.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-53227', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56538', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: zynqmp_kms: Unplug DRM device before removal\n\nPrevent userspace accesses to the DRM device from causing\nuse-after-frees by unplugging the device before we remove it. This\ncauses any further userspace accesses to result in an error without\nfurther calls into this driver's internals.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56538', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56548', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: don't query the device logical block size multiple times\n\nDevices block sizes may change. One of these cases is a loop device by\nusing ioctl LOOP_SET_BLOCK_SIZE.\n\nWhile this may cause other issues like IO being rejected, in the case of\nhfsplus, it will allocate a block by using that size and potentially write\nout-of-bounds when hfsplus_read_wrapper calls hfsplus_submit_bio and the\nlatter function reads a different io_size.\n\nUsing a new min_io_size initally set to sb_min_blocksize works for the\npurposes of the original fix, since it will be set to the max between\nHFSPLUS_SECTOR_SIZE and the first seen logical block size. We still use the\nmax between HFSPLUS_SECTOR_SIZE and min_io_size in case the latter is not\ninitialized.\n\nTested by mounting an hfsplus filesystem with loop block sizes 512, 1024\nand 4096.\n\nThe produced KASAN report before the fix looks like this:\n\n[ 419.944641] ==================================================================\n[ 419.945655] BUG: KASAN: slab-use-after-free in hfsplus_read_wrapper+0x659/0xa0a\n[ 419.946703] Read of size 2 at addr ffff88800721fc00 by task repro/10678\n[ 419.947612]\n[ 419.947846] CPU: 0 UID: 0 PID: 10678 Comm: repro Not tainted 6.12.0-rc5-00008-gdf56e0f2f3ca #84\n[ 419.949007] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\n[ 419.950035] Call Trace:\n[ 419.950384] <TASK>\n[ 419.950676] dump_stack_lvl+0x57/0x78\n[ 419.951212] ? hfsplus_read_wrapper+0x659/0xa0a\n[ 419.951830] print_report+0x14c/0x49e\n[ 419.952361] ? __virt_addr_valid+0x267/0x278\n[ 419.952979] ? kmem_cache_debug_flags+0xc/0x1d\n[ 419.953561] ? hfsplus_read_wrapper+0x659/0xa0a\n[ 419.954231] kasan_report+0x89/0xb0\n[ 419.954748] ? hfsplus_read_wrapper+0x659/0xa0a\n[ 419.955367] hfsplus_read_wrapper+0x659/0xa0a\n[ 419.955948] ? __pfx_hfsplus_read_wrapper+0x10/0x10\n[ 419.956618] ? do_raw_spin_unlock+0x59/0x1a9\n[ 419.957214] ? _raw_spin_unlock+0x1a/0x2e\n[ 419.957772] hfsplus_fill_super+0x348/0x1590\n[ 419.958355] ? hlock_class+0x4c/0x109\n[ 419.958867] ? __pfx_hfsplus_fill_super+0x10/0x10\n[ 419.959499] ? __pfx_string+0x10/0x10\n[ 419.960006] ? lock_acquire+0x3e2/0x454\n[ 419.960532] ? bdev_name.constprop.0+0xce/0x243\n[ 419.961129] ? __pfx_bdev_name.constprop.0+0x10/0x10\n[ 419.961799] ? pointer+0x3f0/0x62f\n[ 419.962277] ? __pfx_pointer+0x10/0x10\n[ 419.962761] ? vsnprintf+0x6c4/0xfba\n[ 419.963178] ? __pfx_vsnprintf+0x10/0x10\n[ 419.963621] ? setup_bdev_super+0x376/0x3b3\n[ 419.964029] ? snprintf+0x9d/0xd2\n[ 419.964344] ? __pfx_snprintf+0x10/0x10\n[ 419.964675] ? lock_acquired+0x45c/0x5e9\n[ 419.965016] ? set_blocksize+0x139/0x1c1\n[ 419.965381] ? sb_set_blocksize+0x6d/0xae\n[ 419.965742] ? __pfx_hfsplus_fill_super+0x10/0x10\n[ 419.966179] mount_bdev+0x12f/0x1bf\n[ 419.966512] ? __pfx_mount_bdev+0x10/0x10\n[ 419.966886] ? vfs_parse_fs_string+0xce/0x111\n[ 419.967293] ? __pfx_vfs_parse_fs_string+0x10/0x10\n[ 419.967702] ? __pfx_hfsplus_mount+0x10/0x10\n[ 419.968073] legacy_get_tree+0x104/0x178\n[ 419.968414] vfs_get_tree+0x86/0x296\n[ 419.968751] path_mount+0xba3/0xd0b\n[ 419.969157] ? __pfx_path_mount+0x10/0x10\n[ 419.969594] ? kmem_cache_free+0x1e2/0x260\n[ 419.970311] do_mount+0x99/0xe0\n[ 419.970630] ? __pfx_do_mount+0x10/0x10\n[ 419.971008] __do_sys_mount+0x199/0x1c9\n[ 419.971397] do_syscall_64+0xd0/0x135\n[ 419.971761] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 419.972233] RIP: 0033:0x7c3cb812972e\n[ 419.972564] Code: 48 8b 0d f5 46 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c2 46 0d 00 f7 d8 64 89 01 48\n[ 419.974371] RSP: 002b:00007ffe30632548 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5\n[ 419.975048] RAX: ffffffffffffffda RBX: 00007ffe306328d8 RCX: 00007c3cb812972e\n[ 419.975701] RDX: 0000000020000000 RSI: 0000000020000c80 RDI:\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56548', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56562', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()\n\nif (dev->boardinfo && dev->boardinfo->init_dyn_addr)\n ^^^ here check "init_dyn_addr"\n\ti3c_bus_set_addr_slot_status(&master->bus, dev->info.dyn_addr, ...)\n\t\t\t\t\t\t ^^^^\n\t\t\t\t\t\t\tfree "dyn_addr"\nFix copy/paste error "dyn_addr" by replacing it with "init_dyn_addr".', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56562', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56569', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix regression with module command in stack_trace_filter\n\nWhen executing the following command:\n\n # echo "write*:mod:ext3" > /sys/kernel/tracing/stack_trace_filter\n\nThe current mod command causes a null pointer dereference. While commit\n0f17976568b3f ("ftrace: Fix regression with module command in stack_trace_filter")\nhas addressed part of the issue, it left a corner case unhandled, which still\nresults in a kernel crash.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56570', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\novl: Filter invalid inodes with missing lookup function\n\nAdd a check to the ovl_dentry_weird() function to prevent the\nprocessing of directory inodes that lack the lookup function.\nThis is important because such inodes can cause errors in overlayfs\nwhen passed to the lowerstack.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56572', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal()\n\nThe buffer in the loop should be released under the exception path,\notherwise there may be a memory leak here.\n\nTo mitigate this, free the buffer when allegro_alloc_buffer fails.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56581', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: ref-verify: fix use-after-free after invalid ref action\n\nAt btrfs_ref_tree_mod() after we successfully inserted the new ref entry\n(local variable 'ref') into the respective block entry's rbtree (local\nvariable 'be'), if we find an unexpected action of BTRFS_DROP_DELAYED_REF,\nwe error out and free the ref entry without removing it from the block\nentry's rbtree. Then in the error path of btrfs_ref_tree_mod() we call\nbtrfs_free_ref_cache(), which iterates over all block entries and then\ncalls free_block_entry() for each one, and there we will trigger a\nuse-after-free when we are called against the block entry to which we\nadded the freed ref entry to its rbtree, since the rbtree still points\nto the block entry, as we didn't remove it from the rbtree before freeing\nit in the error path at btrfs_ref_tree_mod(). Fix this by removing the\nnew ref entry from the rbtree before freeing it.\n\nSyzbot report this with the following stack traces:\n\n BTRFS error (device loop0 state EA): Ref action 2, root 5, ref_root 0, parent 8564736, owner 0, offset 0, num_refs 18446744073709551615\n __btrfs_mod_ref+0x7dd/0xac0 fs/btrfs/extent-tree.c:2523\n update_ref_for_cow+0x9cd/0x11f0 fs/btrfs/ctree.c:512\n btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594\n btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754\n btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116\n btrfs_insert_empty_items+0x9c/0x1a0 fs/btrfs/ctree.c:4314\n btrfs_insert_empty_item fs/btrfs/ctree.h:669 [inline]\n btrfs_insert_orphan_item+0x1f1/0x320 fs/btrfs/orphan.c:23\n btrfs_orphan_add+0x6d/0x1a0 fs/btrfs/inode.c:3482\n btrfs_unlink+0x267/0x350 fs/btrfs/inode.c:4293\n vfs_unlink+0x365/0x650 fs/namei.c:4469\n do_unlinkat+0x4ae/0x830 fs/namei.c:4533\n __do_sys_unlinkat fs/namei.c:4576 [inline]\n __se_sys_unlinkat fs/namei.c:4569 [inline]\n __x64_sys_unlinkat+0xcc/0xf0 fs/namei.c:4569\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n BTRFS error (device loop0 state EA): Ref action 1, root 5, ref_root 5, parent 0, owner 260, offset 0, num_refs 1\n __btrfs_mod_ref+0x76b/0xac0 fs/btrfs/extent-tree.c:2521\n update_ref_for_cow+0x96a/0x11f0\n btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594\n btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754\n btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116\n btrfs_lookup_inode+0xdc/0x480 fs/btrfs/inode-item.c:411\n __btrfs_update_delayed_inode+0x1e7/0xb90 fs/btrfs/delayed-inode.c:1030\n btrfs_update_delayed_inode fs/btrfs/delayed-inode.c:1114 [inline]\n __btrfs_commit_inode_delayed_items+0x2318/0x24a0 fs/btrfs/delayed-inode.c:1137\n __btrfs_run_delayed_items+0x213/0x490 fs/btrfs/delayed-inode.c:1171\n btrfs_commit_transaction+0x8a8/0x3740 fs/btrfs/transaction.c:2313\n prepare_to_relocate+0x3c4/0x4c0 fs/btrfs/relocation.c:3586\n relocate_block_group+0x16c/0xd40 fs/btrfs/relocation.c:3611\n btrfs_relocate_block_group+0x77d/0xd90 fs/btrfs/relocation.c:4081\n btrfs_relocate_chunk+0x12c/0x3b0 fs/btrfs/volumes.c:3377\n __btrfs_balance+0x1b0f/0x26b0 fs/btrfs/volumes.c:4161\n btrfs_balance+0xbdc/0x10c0 fs/btrfs/volumes.c:4538\n BTRFS error (device loop0 state EA): Ref action 2, root 5, ref_root 0, parent 8564736, owner 0, offset 0, num_refs 18446744073709551615\n __btrfs_mod_ref+0x7dd/0xac0 fs/btrfs/extent-tree.c:2523\n update_ref_for_cow+0x9cd/0x11f0 fs/btrfs/ctree.c:512\n btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594\n btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754\n btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116\n btrfs_lookup_inode+0xdc/0x480 fs/btrfs/inode-item.c:411\n __btrfs_update_delayed_inode+0x1e7/0xb90 fs/btrfs/delayed-inode.c:1030\n btrfs_update_delayed_i\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56581', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56583', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/deadline: Fix warning in migrate_enable for boosted tasks\n\nWhen running the following command:\n\nwhile true; do\n stress-ng --cyclic 30 --timeout 30s --minimize --quiet\ndone\n\na warning is eventually triggered:\n\nWARNING: CPU: 43 PID: 2848 at kernel/sched/deadline.c:794\nsetup_new_dl_entity+0x13e/0x180\n...\nCall Trace:\n <TASK>\n ? show_trace_log_lvl+0x1c4/0x2df\n ? enqueue_dl_entity+0x631/0x6e0\n ? setup_new_dl_entity+0x13e/0x180\n ? __warn+0x7e/0xd0\n ? report_bug+0x11a/0x1a0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n enqueue_dl_entity+0x631/0x6e0\n enqueue_task_dl+0x7d/0x120\n __do_set_cpus_allowed+0xe3/0x280\n __set_cpus_allowed_ptr_locked+0x140/0x1d0\n __set_cpus_allowed_ptr+0x54/0xa0\n migrate_enable+0x7e/0x150\n rt_spin_unlock+0x1c/0x90\n group_send_sig_info+0xf7/0x1a0\n ? kill_pid_info+0x1f/0x1d0\n kill_pid_info+0x78/0x1d0\n kill_proc_info+0x5b/0x110\n __x64_sys_kill+0x93/0xc0\n do_syscall_64+0x5c/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n RIP: 0033:0x7f0dab31f92b\n\nThis warning occurs because set_cpus_allowed dequeues and enqueues tasks\nwith the ENQUEUE_RESTORE flag set. If the task is boosted, the warning\nis triggered. A boosted task already had its parameters set by\nrt_mutex_setprio, and a new call to setup_new_dl_entity is unnecessary,\nhence the WARN_ON call.\n\nCheck if we are requeueing a boosted task and avoid calling\nsetup_new_dl_entity if that's the case.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56583', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56584', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/tctx: work around xa_store() allocation error issue\n\nsyzbot triggered the following WARN_ON:\n\nWARNING: CPU: 0 PID: 16 at io_uring/tctx.c:51 __io_uring_free+0xfa/0x140 io_uring/tctx.c:51\n\nwhich is the\n\nWARN_ON_ONCE(!xa_empty(&tctx->xa));\n\nsanity check in __io_uring_free() when a io_uring_task is going through\nits final put. The syzbot test case includes injecting memory allocation\nfailures, and it very much looks like xa_store() can fail one of its\nmemory allocations and end up with ->head being non-NULL even though no\nentries exist in the xarray.\n\nUntil this issue gets sorted out, work around it by attempting to\niterate entries in our xarray, and WARN_ON_ONCE() if one is found.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56584', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56586', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.\n\ncreating a large files during checkpoint disable until it runs out of\nspace and then delete it, then remount to enable checkpoint again, and\nthen unmount the filesystem triggers the f2fs_bug_on as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/inode.c:896!\nCPU: 2 UID: 0 PID: 1286 Comm: umount Not tainted 6.11.0-rc7-dirty #360\nOops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nRIP: 0010:f2fs_evict_inode+0x58c/0x610\nCall Trace:\n __die_body+0x15/0x60\n die+0x33/0x50\n do_trap+0x10a/0x120\n f2fs_evict_inode+0x58c/0x610\n do_error_trap+0x60/0x80\n f2fs_evict_inode+0x58c/0x610\n exc_invalid_op+0x53/0x60\n f2fs_evict_inode+0x58c/0x610\n asm_exc_invalid_op+0x16/0x20\n f2fs_evict_inode+0x58c/0x610\n evict+0x101/0x260\n dispose_list+0x30/0x50\n evict_inodes+0x140/0x190\n generic_shutdown_super+0x2f/0x150\n kill_block_super+0x11/0x40\n kill_f2fs_super+0x7d/0x140\n deactivate_locked_super+0x2a/0x70\n cleanup_mnt+0xb3/0x140\n task_work_run+0x61/0x90\n\nThe root cause is: creating large files during disable checkpoint\nperiod results in not enough free segments, so when writing back root\ninode will failed in f2fs_enable_checkpoint. When umount the file\nsystem after enabling checkpoint, the root inode is dirty in\nf2fs_evict_inode function, which triggers BUG_ON. The steps to\nreproduce are as follows:\n\ndd if=/dev/zero of=f2fs.img bs=1M count=55\nmount f2fs.img f2fs_dir -o checkpoint=disable:10%\ndd if=/dev/zero of=big bs=1M count=50\nsync\nrm big\nmount -o remount,checkpoint=enable f2fs_dir\numount f2fs_dir\n\nLet's redirty inode when there is not free segments during checkpoint\nis disable.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56586', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56594', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: set the right AMDGPU sg segment limitation\n\nThe driver needs to set the correct max_segment_size;\notherwise debug_dma_map_sg() will complain about the\nover-mapping of the AMDGPU sg length as following:\n\nWARNING: CPU: 6 PID: 1964 at kernel/dma/debug.c:1178 debug_dma_map_sg+0x2dc/0x370\n[ 364.049444] Modules linked in: veth amdgpu(OE) amdxcp drm_exec gpu_sched drm_buddy drm_ttm_helper ttm(OE) drm_suballoc_helper drm_display_helper drm_kms_helper i2c_algo_bit rpcsec_gss_krb5 auth_rpcgss nfsv4 nfs lockd grace netfs xt_conntrack xt_MASQUERADE nf_conntrack_netlink xfrm_user xfrm_algo iptable_nat xt_addrtype iptable_filter br_netfilter nvme_fabrics overlay nfnetlink_cttimeout nfnetlink openvswitch nsh nf_conncount nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c bridge stp llc amd_atl intel_rapl_msr intel_rapl_common sunrpc sch_fq_codel snd_hda_codec_realtek snd_hda_codec_generic snd_hda_scodec_component snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg edac_mce_amd binfmt_misc snd_hda_codec snd_pci_acp6x snd_hda_core snd_acp_config snd_hwdep snd_soc_acpi kvm_amd snd_pcm kvm snd_seq_midi snd_seq_midi_event crct10dif_pclmul ghash_clmulni_intel sha512_ssse3 snd_rawmidi sha256_ssse3 sha1_ssse3 aesni_intel snd_seq nls_iso8859_1 crypto_simd snd_seq_device cryptd snd_timer rapl input_leds snd\n[ 364.049532] ipmi_devintf wmi_bmof ccp serio_raw k10temp sp5100_tco soundcore ipmi_msghandler cm32181 industrialio mac_hid msr parport_pc ppdev lp parport drm efi_pstore ip_tables x_tables pci_stub crc32_pclmul nvme ahci libahci i2c_piix4 r8169 nvme_core i2c_designware_pci realtek i2c_ccgx_ucsi video wmi hid_generic cdc_ether usbnet usbhid hid r8152 mii\n[ 364.049576] CPU: 6 PID: 1964 Comm: rocminfo Tainted: G OE 6.10.0-custom #492\n[ 364.049579] Hardware name: AMD Majolica-RN/Majolica-RN, BIOS RMJ1009A 06/13/2021\n[ 364.049582] RIP: 0010:debug_dma_map_sg+0x2dc/0x370\n[ 364.049585] Code: 89 4d b8 e8 36 b1 86 00 8b 4d b8 48 8b 55 b0 44 8b 45 a8 4c 8b 4d a0 48 89 c6 48 c7 c7 00 4b 74 bc 4c 89 4d b8 e8 b4 73 f3 ff <0f> 0b 4c 8b 4d b8 8b 15 c8 2c b8 01 85 d2 0f 85 ee fd ff ff 8b 05\n[ 364.049588] RSP: 0018:ffff9ca600b57ac0 EFLAGS: 00010286\n[ 364.049590] RAX: 0000000000000000 RBX: ffff88b7c132b0c8 RCX: 0000000000000027\n[ 364.049592] RDX: ffff88bb0f521688 RSI: 0000000000000001 RDI: ffff88bb0f521680\n[ 364.049594] RBP: ffff9ca600b57b20 R08: 000000000000006f R09: ffff9ca600b57930\n[ 364.049596] R10: ffff9ca600b57928 R11: ffffffffbcb46328 R12: 0000000000000000\n[ 364.049597] R13: 0000000000000001 R14: ffff88b7c19c0700 R15: ffff88b7c9059800\n[ 364.049599] FS: 00007fb2d3516e80(0000) GS:ffff88bb0f500000(0000) knlGS:0000000000000000\n[ 364.049601] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 364.049603] CR2: 000055610bd03598 CR3: 00000001049f6000 CR4: 0000000000350ef0\n[ 364.049605] Call Trace:\n[ 364.049607] <TASK>\n[ 364.049609] ? show_regs+0x6d/0x80\n[ 364.049614] ? __warn+0x8c/0x140\n[ 364.049618] ? debug_dma_map_sg+0x2dc/0x370\n[ 364.049621] ? report_bug+0x193/0x1a0\n[ 364.049627] ? handle_bug+0x46/0x80\n[ 364.049631] ? exc_invalid_op+0x1d/0x80\n[ 364.049635] ? asm_exc_invalid_op+0x1f/0x30\n[ 364.049642] ? debug_dma_map_sg+0x2dc/0x370\n[ 364.049647] __dma_map_sg_attrs+0x90/0xe0\n[ 364.049651] dma_map_sgtable+0x25/0x40\n[ 364.049654] amdgpu_bo_move+0x59a/0x850 [amdgpu]\n[ 364.049935] ? srso_return_thunk+0x5/0x5f\n[ 364.049939] ? amdgpu_ttm_tt_populate+0x5d/0xc0 [amdgpu]\n[ 364.050095] ttm_bo_handle_move_mem+0xc3/0x180 [ttm]\n[ 364.050103] ttm_bo_validate+0xc1/0x160 [ttm]\n[ 364.050108] ? amdgpu_ttm_tt_get_user_pages+0xe5/0x1b0 [amdgpu]\n[ 364.050263] amdgpu_amdkfd_gpuvm_alloc_memory_of_gpu+0xa12/0xc90 [amdgpu]\n[ 364.050473] kfd_ioctl_alloc_memory_of_gpu+0x16b/0x3b0 [amdgpu]\n[ 364.050680] kfd_ioctl+0x3c2/0x530 [amdgpu]\n[ 364.050866] ? __pfx_kfd_ioctl_alloc_memory_of_gpu+0x10/0x10 [amdgpu]\n[ 364.05105\n---truncated---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56594', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56596', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in jfs_readdir\n\nThe stbl might contain some invalid values. Added a check to\nreturn error code in that case.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56596', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56598', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: array-index-out-of-bounds fix in dtReadFirst\n\nThe value of stbl can be sometimes out of bounds due\nto a bad filesystem. Added a check with appopriate return\nof error code in that case.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56598', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56604', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc()\n\nbt_sock_alloc() attaches allocated sk object to the provided sock object.\nIf rfcomm_dlc_alloc() fails, we release the sk object, but leave the\ndangling pointer in the sock object, which may cause use-after-free.\n\nFix this by swapping calls to bt_sock_alloc() and rfcomm_dlc_alloc().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56604', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56605', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()\n\nbt_sock_alloc() allocates the sk object and attaches it to the provided\nsock object. On error l2cap_sock_alloc() frees the sk object, but the\ndangling pointer is still attached to the sock object, which may create\nuse-after-free in other code.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56608', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix out-of-bounds access in 'dcn21_link_encoder_create'\n\nAn issue was identified in the dcn21_link_encoder_create function where\nan out-of-bounds access could occur when the hpd_source index was used\nto reference the link_enc_hpd_regs array. This array has a fixed size\nand the index was not being checked against the array's bounds before\naccessing it.\n\nThis fix adds a conditional check to ensure that the hpd_source index is\nwithin the valid range of the link_enc_hpd_regs array. If the index is\nout of bounds, the function now returns NULL to prevent undefined\nbehavior.\n\nReferences:\n\n[ 65.920507] ------------[ cut here ]------------\n[ 65.920510] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn21/dcn21_resource.c:1312:29\n[ 65.920519] index 7 is out of range for type 'dcn10_link_enc_hpd_registers [5]'\n[ 65.920523] CPU: 3 PID: 1178 Comm: modprobe Tainted: G OE 6.8.0-cleanershaderfeatureresetasdntipmi200nv2132 #13\n[ 65.920525] Hardware name: AMD Majolica-RN/Majolica-RN, BIOS WMJ0429N_Weekly_20_04_2 04/29/2020\n[ 65.920527] Call Trace:\n[ 65.920529] <TASK>\n[ 65.920532] dump_stack_lvl+0x48/0x70\n[ 65.920541] dump_stack+0x10/0x20\n[ 65.920543] __ubsan_handle_out_of_bounds+0xa2/0xe0\n[ 65.920549] dcn21_link_encoder_create+0xd9/0x140 [amdgpu]\n[ 65.921009] link_create+0x6d3/0xed0 [amdgpu]\n[ 65.921355] create_links+0x18a/0x4e0 [amdgpu]\n[ 65.921679] dc_create+0x360/0x720 [amdgpu]\n[ 65.921999] ? dmi_matches+0xa0/0x220\n[ 65.922004] amdgpu_dm_init+0x2b6/0x2c90 [amdgpu]\n[ 65.922342] ? console_unlock+0x77/0x120\n[ 65.922348] ? dev_printk_emit+0x86/0xb0\n[ 65.922354] dm_hw_init+0x15/0x40 [amdgpu]\n[ 65.922686] amdgpu_device_init+0x26a8/0x33a0 [amdgpu]\n[ 65.922921] amdgpu_driver_load_kms+0x1b/0xa0 [amdgpu]\n[ 65.923087] amdgpu_pci_probe+0x1b7/0x630 [amdgpu]\n[ 65.923087] local_pci_probe+0x4b/0xb0\n[ 65.923087] pci_device_probe+0xc8/0x280\n[ 65.923087] really_probe+0x187/0x300\n[ 65.923087] __driver_probe_device+0x85/0x130\n[ 65.923087] driver_probe_device+0x24/0x110\n[ 65.923087] __driver_attach+0xac/0x1d0\n[ 65.923087] ? __pfx___driver_attach+0x10/0x10\n[ 65.923087] bus_for_each_dev+0x7d/0xd0\n[ 65.923087] driver_attach+0x1e/0x30\n[ 65.923087] bus_add_driver+0xf2/0x200\n[ 65.923087] driver_register+0x64/0x130\n[ 65.923087] ? __pfx_amdgpu_init+0x10/0x10 [amdgpu]\n[ 65.923087] __pci_register_driver+0x61/0x70\n[ 65.923087] amdgpu_init+0x7d/0xff0 [amdgpu]\n[ 65.923087] do_one_initcall+0x49/0x310\n[ 65.923087] ? kmalloc_trace+0x136/0x360\n[ 65.923087] do_init_module+0x6a/0x270\n[ 65.923087] load_module+0x1fce/0x23a0\n[ 65.923087] init_module_from_file+0x9c/0xe0\n[ 65.923087] ? init_module_from_file+0x9c/0xe0\n[ 65.923087] idempotent_init_module+0x179/0x230\n[ 65.923087] __x64_sys_finit_module+0x5d/0xa0\n[ 65.923087] do_syscall_64+0x76/0x120\n[ 65.923087] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[ 65.923087] RIP: 0033:0x7f2d80f1e88d\n[ 65.923087] Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 b5 0f 00 f7 d8 64 89 01 48\n[ 65.923087] RSP: 002b:00007ffc7bc1aa78 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n[ 65.923087] RAX: ffffffffffffffda RBX: 0000564c9c1db130 RCX: 00007f2d80f1e88d\n[ 65.923087] RDX: 0000000000000000 RSI: 0000564c9c1e5480 RDI: 000000000000000f\n[ 65.923087] RBP: 0000000000040000 R08: 0000000000000000 R09: 0000000000000002\n[ 65.923087] R10: 000000000000000f R11: 0000000000000246 R12: 0000564c9c1e5480\n[ 65.923087] R13: 0000564c9c1db260 R14: 0000000000000000 R15: 0000564c9c1e54b0\n[ 65.923087] </TASK>\n[ 65.923927] ---[ end trace ]---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56608', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56615', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix OOB devmap writes when deleting elements\n\nJordy reported issue against XSKMAP which also applies to DEVMAP - the\nindex used for accessing map entry, due to being a signed integer,\ncauses the OOB writes. Fix is simple as changing the type from int to\nu32, however, when compared to XSKMAP case, one more thing needs to be\naddressed.\n\nWhen map is released from system via dev_map_free(), we iterate through\nall of the entries and an iterator variable is also an int, which\nimplies OOB accesses. Again, change it to be u32.\n\nExample splat below:\n\n[ 160.724676] BUG: unable to handle page fault for address: ffffc8fc2c001000\n[ 160.731662] #PF: supervisor read access in kernel mode\n[ 160.736876] #PF: error_code(0x0000) - not-present page\n[ 160.742095] PGD 0 P4D 0\n[ 160.744678] Oops: Oops: 0000 [#1] PREEMPT SMP\n[ 160.749106] CPU: 1 UID: 0 PID: 520 Comm: kworker/u145:12 Not tainted 6.12.0-rc1+ #487\n[ 160.757050] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019\n[ 160.767642] Workqueue: events_unbound bpf_map_free_deferred\n[ 160.773308] RIP: 0010:dev_map_free+0x77/0x170\n[ 160.777735] Code: 00 e8 fd 91 ed ff e8 b8 73 ed ff 41 83 7d 18 19 74 6e 41 8b 45 24 49 8b bd f8 00 00 00 31 db 85 c0 74 48 48 63 c3 48 8d 04 c7 <48> 8b 28 48 85 ed 74 30 48 8b 7d 18 48 85 ff 74 05 e8 b3 52 fa ff\n[ 160.796777] RSP: 0018:ffffc9000ee1fe38 EFLAGS: 00010202\n[ 160.802086] RAX: ffffc8fc2c001000 RBX: 0000000080000000 RCX: 0000000000000024\n[ 160.809331] RDX: 0000000000000000 RSI: 0000000000000024 RDI: ffffc9002c001000\n[ 160.816576] RBP: 0000000000000000 R08: 0000000000000023 R09: 0000000000000001\n[ 160.823823] R10: 0000000000000001 R11: 00000000000ee6b2 R12: dead000000000122\n[ 160.831066] R13: ffff88810c928e00 R14: ffff8881002df405 R15: 0000000000000000\n[ 160.838310] FS: 0000000000000000(0000) GS:ffff8897e0c40000(0000) knlGS:0000000000000000\n[ 160.846528] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 160.852357] CR2: ffffc8fc2c001000 CR3: 0000000005c32006 CR4: 00000000007726f0\n[ 160.859604] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 160.866847] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 160.874092] PKRU: 55555554\n[ 160.876847] Call Trace:\n[ 160.879338] <TASK>\n[ 160.881477] ? __die+0x20/0x60\n[ 160.884586] ? page_fault_oops+0x15a/0x450\n[ 160.888746] ? search_extable+0x22/0x30\n[ 160.892647] ? search_bpf_extables+0x5f/0x80\n[ 160.896988] ? exc_page_fault+0xa9/0x140\n[ 160.900973] ? asm_exc_page_fault+0x22/0x30\n[ 160.905232] ? dev_map_free+0x77/0x170\n[ 160.909043] ? dev_map_free+0x58/0x170\n[ 160.912857] bpf_map_free_deferred+0x51/0x90\n[ 160.917196] process_one_work+0x142/0x370\n[ 160.921272] worker_thread+0x29e/0x3b0\n[ 160.925082] ? rescuer_thread+0x4b0/0x4b0\n[ 160.929157] kthread+0xd4/0x110\n[ 160.932355] ? kthread_park+0x80/0x80\n[ 160.936079] ret_from_fork+0x2d/0x50\n[ 160.943396] ? kthread_park+0x80/0x80\n[ 160.950803] ret_from_fork_asm+0x11/0x20\n[ 160.958482] </TASK>', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56615', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56619', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()\n\nSyzbot reported that when searching for records in a directory where the\ninode\'s i_size is corrupted and has a large value, memory access outside\nthe folio/page range may occur, or a use-after-free bug may be detected if\nKASAN is enabled.\n\nThis is because nilfs_last_byte(), which is called by nilfs_find_entry()\nand others to calculate the number of valid bytes of directory data in a\npage from i_size and the page index, loses the upper 32 bits of the 64-bit\nsize information due to an inappropriate type of local variable to which\nthe i_size value is assigned.\n\nThis caused a large byte offset value due to underflow in the end address\ncalculation in the calling nilfs_find_entry(), resulting in memory access\nthat exceeds the folio/page size.\n\nFix this issue by changing the type of the local variable causing the bit\nloss from "unsigned int" to "u64". The return value of nilfs_last_byte()\nis also of type "unsigned int", but it is truncated so as not to exceed\nPAGE_SIZE and no bit loss occurs, so no change is required.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56619', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56627', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read\n\nAn offset from client could be a negative value, It could lead\nto an out-of-bounds read from the stream_buf.\nNote that this issue is coming when setting\n'vfs objects = streams_xattr parameter' in ksmbd.conf.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56627', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56629', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: fix when get product name maybe null pointer\n\nDue to incorrect dev->product reporting by certain devices, null\npointer dereferences occur when dev->product is empty, leading to\npotential system crashes.\n\nThis issue was found on EXCELSIOR DL37-D05 device with\nLoongson-LS3A6000-7A2000-DL37 motherboard.\n\nKernel logs:\n[ 56.470885] usb 4-3: new full-speed USB device number 4 using ohci-pci\n[ 56.671638] usb 4-3: string descriptor 0 read error: -22\n[ 56.671644] usb 4-3: New USB device found, idVendor=056a, idProduct=0374, bcdDevice= 1.07\n[ 56.671647] usb 4-3: New USB device strings: Mfr=1, Product=2, SerialNumber=3\n[ 56.678839] hid-generic 0003:056A:0374.0004: hiddev0,hidraw3: USB HID v1.10 Device [HID 056a:0374] on usb-0000:00:05.0-3/input0\n[ 56.697719] CPU 2 Unable to handle kernel paging request at virtual address 0000000000000000, era == 90000000066e35c8, ra == ffff800004f98a80\n[ 56.697732] Oops[#1]:\n[ 56.697734] CPU: 2 PID: 2742 Comm: (udev-worker) Tainted: G OE 6.6.0-loong64-desktop #25.00.2000.015\n[ 56.697737] Hardware name: Inspur CE520L2/C09901N000000000, BIOS 2.09.00 10/11/2024\n[ 56.697739] pc 90000000066e35c8 ra ffff800004f98a80 tp 9000000125478000 sp 900000012547b8a0\n[ 56.697741] a0 0000000000000000 a1 ffff800004818b28 a2 0000000000000000 a3 0000000000000000\n[ 56.697743] a4 900000012547b8f0 a5 0000000000000000 a6 0000000000000000 a7 0000000000000000\n[ 56.697745] t0 ffff800004818b2d t1 0000000000000000 t2 0000000000000003 t3 0000000000000005\n[ 56.697747] t4 0000000000000000 t5 0000000000000000 t6 0000000000000000 t7 0000000000000000\n[ 56.697748] t8 0000000000000000 u0 0000000000000000 s9 0000000000000000 s0 900000011aa48028\n[ 56.697750] s1 0000000000000000 s2 0000000000000000 s3 ffff800004818e80 s4 ffff800004810000\n[ 56.697751] s5 90000001000b98d0 s6 ffff800004811f88 s7 ffff800005470440 s8 0000000000000000\n[ 56.697753] ra: ffff800004f98a80 wacom_update_name+0xe0/0x300 [wacom]\n[ 56.697802] ERA: 90000000066e35c8 strstr+0x28/0x120\n[ 56.697806] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n[ 56.697816] PRMD: 0000000c (PPLV0 +PIE +PWE)\n[ 56.697821] EUEN: 00000000 (-FPE -SXE -ASXE -BTE)\n[ 56.697827] ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)\n[ 56.697831] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0)\n[ 56.697835] BADV: 0000000000000000\n[ 56.697836] PRID: 0014d000 (Loongson-64bit, Loongson-3A6000)\n[ 56.697838] Modules linked in: wacom(+) bnep bluetooth rfkill qrtr nls_iso8859_1 nls_cp437 snd_hda_codec_conexant snd_hda_codec_generic ledtrig_audio snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_timer snd soundcore input_leds mousedev led_class joydev deepin_netmonitor(OE) fuse nfnetlink dmi_sysfs ip_tables x_tables overlay amdgpu amdxcp drm_exec gpu_sched drm_buddy radeon drm_suballoc_helper i2c_algo_bit drm_ttm_helper r8169 ttm drm_display_helper spi_loongson_pci xhci_pci cec xhci_pci_renesas spi_loongson_core hid_generic realtek gpio_loongson_64bit\n[ 56.697887] Process (udev-worker) (pid: 2742, threadinfo=00000000aee0d8b4, task=00000000a9eff1f3)\n[ 56.697890] Stack : 0000000000000000 ffff800004817e00 0000000000000000 0000251c00000000\n[ 56.697896] 0000000000000000 00000011fffffffd 0000000000000000 0000000000000000\n[ 56.697901] 0000000000000000 1b67a968695184b9 0000000000000000 90000001000b98d0\n[ 56.697906] 90000001000bb8d0 900000011aa48028 0000000000000000 ffff800004f9d74c\n[ 56.697911] 90000001000ba000 ffff800004f9ce58 0000000000000000 ffff800005470440\n[ 56.697916] ffff800004811f88 90000001000b98d0 9000000100da2aa8 90000001000bb8d0\n[ 56.697921] 0000000000000000 90000001000ba000 900000011aa48028 ffff800004f9d74c\n[ 56.697926] ffff8000054704e8 90000001000bb8b8 90000001000ba000 0000000000000000\n[ 56.697931] 90000001000bb8d0 \n---truncated---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56629', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56672', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: Fix UAF in blkcg_unpin_online()\n\nblkcg_unpin_online() walks up the blkcg hierarchy putting the online pin. To\nwalk up, it uses blkcg_parent(blkcg) but it was calling that after\nblkcg_destroy_blkgs(blkcg) which could free the blkcg, leading to the\nfollowing UAF:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in blkcg_unpin_online+0x15a/0x270\n Read of size 8 at addr ffff8881057678c0 by task kworker/9:1/117\n\n CPU: 9 UID: 0 PID: 117 Comm: kworker/9:1 Not tainted 6.13.0-rc1-work-00182-gb8f52214c61a-dirty #48\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022\n Workqueue: cgwb_release cgwb_release_workfn\n Call Trace:\n <TASK>\n dump_stack_lvl+0x27/0x80\n print_report+0x151/0x710\n kasan_report+0xc0/0x100\n blkcg_unpin_online+0x15a/0x270\n cgwb_release_workfn+0x194/0x480\n process_scheduled_works+0x71b/0xe20\n worker_thread+0x82a/0xbd0\n kthread+0x242/0x2c0\n ret_from_fork+0x33/0x70\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n ...\n Freed by task 1944:\n kasan_save_track+0x2b/0x70\n kasan_save_free_info+0x3c/0x50\n __kasan_slab_free+0x33/0x50\n kfree+0x10c/0x330\n css_free_rwork_fn+0xe6/0xb30\n process_scheduled_works+0x71b/0xe20\n worker_thread+0x82a/0xbd0\n kthread+0x242/0x2c0\n ret_from_fork+0x33/0x70\n ret_from_fork_asm+0x1a/0x30\n\nNote that the UAF is not easy to trigger as the free path is indirected\nbehind a couple RCU grace periods and a work item execution. I could only\ntrigger it with artifical msleep() injected in blkcg_unpin_online().\n\nFix it by reading the parent pointer before destroying the blkcg's blkg's.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56672', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56681', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: bcm - add error check in the ahash_hmac_init function\n\nThe ahash_init functions may return fails. The ahash_hmac_init should\nnot return ok when ahash_init returns error. For an example, ahash_init\nwill return -ENOMEM when allocation memory is error.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56681', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56686', 'notes': [{'text': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56686', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56691', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device\n\nWhile design wise the idea of converting the driver to use\nthe hierarchy of the IRQ chips is correct, the implementation\nhas (inherited) flaws. This was unveiled when platform_get_irq()\nhad started WARN() on IRQ 0 that is supposed to be a Linux\nIRQ number (also known as vIRQ).\n\nRework the driver to respect IRQ domain when creating each MFD\ndevice separately, as the domain is not the same for all of them.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56691', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 3.9, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Low', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56692', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node blkaddr in truncate_node()\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/segment.c:2534!\nRIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534\nCall Trace:\n truncate_node+0x1ae/0x8c0 fs/f2fs/node.c:909\n f2fs_remove_inode_page+0x5c2/0x870 fs/f2fs/node.c:1288\n f2fs_evict_inode+0x879/0x15c0 fs/f2fs/inode.c:856\n evict+0x4e8/0x9b0 fs/inode.c:723\n f2fs_handle_failed_inode+0x271/0x2e0 fs/f2fs/inode.c:986\n f2fs_create+0x357/0x530 fs/f2fs/namei.c:394\n lookup_open fs/namei.c:3595 [inline]\n open_last_lookups fs/namei.c:3694 [inline]\n path_openat+0x1c03/0x3590 fs/namei.c:3930\n do_filp_open+0x235/0x490 fs/namei.c:3960\n do_sys_openat2+0x13e/0x1d0 fs/open.c:1415\n do_sys_open fs/open.c:1430 [inline]\n __do_sys_openat fs/open.c:1446 [inline]\n __se_sys_openat fs/open.c:1441 [inline]\n __x64_sys_openat+0x247/0x2a0 fs/open.c:1441\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534\n\nThe root cause is: on a fuzzed image, blkaddr in nat entry may be\ncorrupted, then it will cause system panic when using it in\nf2fs_invalidate_blocks(), to avoid this, let's add sanity check on\nnat blkaddr in truncate_node().", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56692', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56700', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: wl128x: Fix atomicity violation in fmc_send_cmd()\n\nAtomicity violation occurs when the fmc_send_cmd() function is executed\nsimultaneously with the modification of the fmdev->resp_skb value.\nConsider a scenario where, after passing the validity check within the\nfunction, a non-null fmdev->resp_skb variable is assigned a null value.\nThis results in an invalid fmdev->resp_skb variable passing the validity\ncheck. As seen in the later part of the function, skb = fmdev->resp_skb;\nwhen the invalid fmdev->resp_skb passes the check, a null pointer\ndereference error may occur at line 478, evt_hdr = (void *)skb->data;\n\nTo address this issue, it is recommended to include the validity check of\nfmdev->resp_skb within the locked section of the function. This\nmodification ensures that the value of fmdev->resp_skb does not change\nduring the validation process, thereby maintaining its validity.\n\nThis possible bug is found by an experimental static analysis tool\ndeveloped by our team. This tool analyzes the locking APIs\nto extract function pairs that can be concurrently executed, and then\nanalyzes the instructions in the paired functions to identify possible\nconcurrency bugs including data races and atomicity violations.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56700', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56709', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: check if iowq is killed before queuing\n\ntask work can be executed after the task has gone through io_uring\ntermination, whether it's the final task_work run or the fallback path.\nIn this case, task work will find ->io_wq being already killed and\nnull'ed, which is a problem if it then tries to forward the request to\nio_queue_iowq(). Make io_queue_iowq() fail requests in this case.\n\nNote that it also checks PF_KTHREAD, because the user can first close\na DEFER_TASKRUN ring and shortly after kill the task, in which case\n->iowq check would race.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56709', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56739', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrtc: check if __rtc_read_time was successful in rtc_timer_do_work()\n\nIf the __rtc_read_time call fails,, the struct rtc_time tm; may contain\nuninitialized data, or an illegal date/time read from the RTC hardware.\n\nWhen calling rtc_tm_to_ktime later, the result may be a very large value\n(possibly KTIME_MAX). If there are periodic timers in rtc->timerqueue,\nthey will continually expire, may causing kernel softlockup.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56739', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56741', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: test: Fix memory leak for aa_unpack_strdup()\n\nThe string allocated by kmemdup() in aa_unpack_strdup() is not\nfreed and cause following memory leaks, free them to fix it.\n\n\tunreferenced object 0xffffff80c6af8a50 (size 8):\n\t comm "kunit_try_catch", pid 225, jiffies 4294894407\n\t hex dump (first 8 bytes):\n\t 74 65 73 74 69 6e 67 00 testing.\n\t backtrace (crc 5eab668b):\n\t [<0000000001e3714d>] kmemleak_alloc+0x34/0x40\n\t [<000000006e6c7776>] __kmalloc_node_track_caller_noprof+0x300/0x3e0\n\t [<000000006870467c>] kmemdup_noprof+0x34/0x60\n\t [<000000001176bb03>] aa_unpack_strdup+0xd0/0x18c\n\t [<000000008ecde918>] policy_unpack_test_unpack_strdup_with_null_name+0xf8/0x3ec\n\t [<0000000032ef8f77>] kunit_try_run_case+0x13c/0x3ac\n\t [<00000000f3edea23>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000adf936cf>] kthread+0x2e8/0x374\n\t [<0000000041bb1628>] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80c2a29090 (size 8):\n\t comm "kunit_try_catch", pid 227, jiffies 4294894409\n\t hex dump (first 8 bytes):\n\t 74 65 73 74 69 6e 67 00 testing.\n\t backtrace (crc 5eab668b):\n\t [<0000000001e3714d>] kmemleak_alloc+0x34/0x40\n\t [<000000006e6c7776>] __kmalloc_node_track_caller_noprof+0x300/0x3e0\n\t [<000000006870467c>] kmemdup_noprof+0x34/0x60\n\t [<000000001176bb03>] aa_unpack_strdup+0xd0/0x18c\n\t [<0000000046a45c1a>] policy_unpack_test_unpack_strdup_with_name+0xd0/0x3c4\n\t [<0000000032ef8f77>] kunit_try_run_case+0x13c/0x3ac\n\t [<00000000f3edea23>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000adf936cf>] kthread+0x2e8/0x374\n\t [<0000000041bb1628>] ret_from_fork+0x10/0x20', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56741', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56747', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()\n\nHook "qedi_ops->common->sb_init = qed_sb_init" does not release the DMA\nmemory sb_virt when it fails. Add dma_free_coherent() to free it. This\nis the same way as qedr_alloc_mem_sb() and qede_alloc_mem_sb().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56747', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56748', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()\n\nHook "qed_ops->common->sb_init = qed_sb_init" does not release the DMA\nmemory sb_virt when it fails. Add dma_free_coherent() to free it. This\nis the same way as qedr_alloc_mem_sb() and qede_alloc_mem_sb().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56756', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix freeing of the HMB descriptor table\n\nThe HMB descriptor table is sized to the maximum number of descriptors\nthat could be used for a given device, but __nvme_alloc_host_mem could\nbreak out of the loop earlier on memory allocation failure and end up\nusing less descriptors than planned for, which leads to an incorrect\nsize passed to dma_free_coherent.\n\nIn practice this was not showing up because the number of descriptors\ntends to be low and the dma coherent allocator always allocates and\nfrees at least a page.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56756', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}, {'cve': 'CVE-2024-56763', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Prevent bad count for tracing_cpumask_write\n\nIf a large count is provided, it will trigger a warning in bitmap_parse_user.\nAlso check zero for it.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56763', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1037', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-245.0.0.144.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-245.0.0.144.oe2203sp4.src']}}]}
ab9f6831e386c9656daf1ac0a7f89a0966aa7aba82fd807a890b3a01558ce050
2026-06-01 19:43:53.684013+03:00
2026-06-23 00:58:24.194250+03:00
openEuler-SA-2026-2365
An update for OpenEXR is now available for openEuler-24.03-LTS
Critical
2026-05-22 16:21:55+03:00
2026-05-22 16:21:55+03:00
['CVE-2026-41142', 'CVE-2026-42216', 'CVE-2026-42217']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-3.1.11-9.oe2403.src.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2365', 'summary': 'openEuler-SA-2026-2365', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41142&packageName=OpenEXR', 'summary': 'CVE-2026-41142', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42216&packageName=OpenEXR', 'summary': 'CVE-2026-42216', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42217&packageName=OpenEXR', 'summary': 'CVE-2026-42217', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41142', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42216', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2365.json', 'summary': 'openEuler-SA-2026-2365 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'OpenEXR security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for OpenEXR is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp; Magic for use in computer imaging applications.\n\nSecurity Fix(es):\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-41142)\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42216)\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42217)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for OpenEXR is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'OpenEXR', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for OpenEXR is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2365', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:55+08:00', 'initial_release_date': '2026-05-22T21:21:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2365', 'summary': 'openEuler-SA-2026-2365', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41142&packageName=OpenEXR', 'summary': 'CVE-2026-41142', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42216&packageName=OpenEXR', 'summary': 'CVE-2026-42216', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42217&packageName=OpenEXR', 'summary': 'CVE-2026-42217', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41142', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42216', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2365.json', 'summary': 'openEuler-SA-2026-2365 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'OpenEXR-3.1.11-9.oe2403.aarch64.rpm', 'product': {'name': 'OpenEXR-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64.rpm', 'product': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64.rpm', 'product': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64.rpm', 'product': {'name': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64.rpm', 'product': {'name': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'OpenEXR-3.1.11-9.oe2403.src.rpm', 'product': {'name': 'OpenEXR-3.1.11-9.oe2403.src.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'OpenEXR-3.1.11-9.oe2403.x86_64.rpm', 'product': {'name': 'OpenEXR-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64.rpm', 'product': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64.rpm', 'product': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64.rpm', 'product': {'name': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64.rpm', 'product': {'name': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.11-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-3.1.11-9.oe2403.aarch64'}, 'product_reference': 'OpenEXR-3.1.11-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64'}, 'product_reference': 'OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-debugsource-3.1.11-9.oe2403.aarch64'}, 'product_reference': 'OpenEXR-debugsource-3.1.11-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-devel-3.1.11-9.oe2403.aarch64'}, 'product_reference': 'OpenEXR-devel-3.1.11-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-libs-3.1.11-9.oe2403.aarch64'}, 'product_reference': 'OpenEXR-libs-3.1.11-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.11-9.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-3.1.11-9.oe2403.src'}, 'product_reference': 'OpenEXR-3.1.11-9.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.11-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-3.1.11-9.oe2403.x86_64'}, 'product_reference': 'OpenEXR-3.1.11-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64'}, 'product_reference': 'OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-debugsource-3.1.11-9.oe2403.x86_64'}, 'product_reference': 'OpenEXR-debugsource-3.1.11-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-devel-3.1.11-9.oe2403.x86_64'}, 'product_reference': 'OpenEXR-devel-3.1.11-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:OpenEXR-libs-3.1.11-9.oe2403.x86_64'}, 'product_reference': 'OpenEXR-libs-3.1.11-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41142', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41142', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2365', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:OpenEXR-3.1.11-9.oe2403.aarch64', 'openEuler-24.03-LTS:OpenEXR-debuginfo-3.1.11-9.oe2403.aarch64', 'openEuler-24.03-LTS:OpenEXR-debugsource-3.1.11-9.oe2403.aarch64', 'openEuler-24.03-LTS:OpenEXR-devel-3.1.11-9.oe2403.aarch64', 'openEuler-24.03-LTS:OpenEXR-libs-3.1.11-9.oe2403.aarch64', 'openEuler-24.03-LTS:OpenEXR-3.1.11-9.oe2403.src', 'openEuler-24.03-LTS:OpenEXR-3.1.11-9.oe2403.x86_64', 'openEuler-24.03-LTS:OpenEXR-debuginfo-3.1.11-9.oe2403.x86_64', 'openEuler-24.03-LTS:OpenEXR-debugsource-3.1.11-9.oe2403.x86_64', 'openEuler-24.03-LTS:OpenEXR-devel-3.1.11-9.oe2403.x86_64', 'openEuler-24.03-LTS:OpenEXR-libs-3.1.11-9.oe2403.x86_64']}}, {'cve': 'CVE-2026-42216', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42216', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2365', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42217', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42217', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2365', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
7efadec8ac9a74d6d285b8fec0532461c638d5829685ad976b28c890376e8ce8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2366
An update for OpenEXR is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-22 16:21:55+03:00
2026-05-22 16:21:55+03:00
['CVE-2026-41142', 'CVE-2026-42216', 'CVE-2026-42217']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-3.1.11-9.oe2403sp3.src.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2366', 'summary': 'openEuler-SA-2026-2366', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41142&packageName=OpenEXR', 'summary': 'CVE-2026-41142', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42216&packageName=OpenEXR', 'summary': 'CVE-2026-42216', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42217&packageName=OpenEXR', 'summary': 'CVE-2026-42217', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41142', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42216', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2366.json', 'summary': 'openEuler-SA-2026-2366 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'OpenEXR security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for OpenEXR is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp; Magic for use in computer imaging applications.\n\nSecurity Fix(es):\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-41142)\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42216)\n\nOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42217)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for OpenEXR is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'OpenEXR', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for OpenEXR is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2366', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:55+08:00', 'initial_release_date': '2026-05-22T21:21:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2366', 'summary': 'openEuler-SA-2026-2366', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41142&packageName=OpenEXR', 'summary': 'CVE-2026-41142', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42216&packageName=OpenEXR', 'summary': 'CVE-2026-42216', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42217&packageName=OpenEXR', 'summary': 'CVE-2026-42217', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41142', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42216', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42217', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2366.json', 'summary': 'openEuler-SA-2026-2366 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'OpenEXR-3.1.11-9.oe2403sp3.src.rpm', 'product': {'name': 'OpenEXR-3.1.11-9.oe2403sp3.src.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_id': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-3.1.11-9.oe2403sp3.aarch64'}, 'product_reference': 'OpenEXR-3.1.11-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64'}, 'product_reference': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64'}, 'product_reference': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64'}, 'product_reference': 'OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64'}, 'product_reference': 'OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.11-9.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-3.1.11-9.oe2403sp3.src'}, 'product_reference': 'OpenEXR-3.1.11-9.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-3.1.11-9.oe2403sp3.x86_64'}, 'product_reference': 'OpenEXR-3.1.11-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64'}, 'product_reference': 'OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64'}, 'product_reference': 'OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64'}, 'product_reference': 'OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64'}, 'product_reference': 'OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41142', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41142', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2366', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:OpenEXR-3.1.11-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:OpenEXR-debuginfo-3.1.11-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:OpenEXR-debugsource-3.1.11-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:OpenEXR-devel-3.1.11-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:OpenEXR-libs-3.1.11-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:OpenEXR-3.1.11-9.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:OpenEXR-3.1.11-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:OpenEXR-debuginfo-3.1.11-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:OpenEXR-debugsource-3.1.11-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:OpenEXR-devel-3.1.11-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:OpenEXR-libs-3.1.11-9.oe2403sp3.x86_64']}}, {'cve': 'CVE-2026-42216', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42216', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2366', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42217', 'notes': [{'text': 'OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42217', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2366', 'details': 'OpenEXR security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
f262ae63cecd30071e143a6598c2a514a8a08d0710e1f23278c5a63386279cfd
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2367
An update for python-twisted is now available for openEuler-20.03-LTS-SP4
High
2026-05-22 16:21:55+03:00
2026-05-22 16:21:55+03:00
['CVE-2026-42304']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python-twisted-22.4.0-5.oe2003sp4.src.rpm', 'product_id': 'python-twisted-22.4.0-5.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch.rpm', 'product_id': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2367', 'summary': 'openEuler-SA-2026-2367', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2367.json', 'summary': 'openEuler-SA-2026-2367 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-twisted security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:\n\nSecurity Fix(es):\n\nA denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.(CVE-2026-42304)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'python-twisted', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-twisted is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2367', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:55+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:55+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:55+08:00', 'initial_release_date': '2026-05-22T21:21:55+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2367', 'summary': 'openEuler-SA-2026-2367', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2367.json', 'summary': 'openEuler-SA-2026-2367 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64.rpm', 'product': {'name': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'python-twisted-22.4.0-5.oe2003sp4.src.rpm', 'product': {'name': 'python-twisted-22.4.0-5.oe2003sp4.src.rpm', 'product_id': 'python-twisted-22.4.0-5.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch.rpm', 'product': {'name': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch.rpm', 'product_id': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64.rpm', 'product': {'name': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-twisted-22.4.0-5.oe2003sp4.x86_64'}, 'product_reference': 'python3-twisted-22.4.0-5.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-22.4.0-5.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python-twisted-22.4.0-5.oe2003sp4.src'}, 'product_reference': 'python-twisted-22.4.0-5.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python-twisted-help-22.4.0-5.oe2003sp4.noarch'}, 'product_reference': 'python-twisted-help-22.4.0-5.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-twisted-22.4.0-5.oe2003sp4.aarch64'}, 'product_reference': 'python3-twisted-22.4.0-5.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42304', 'notes': [{'text': "A denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2367', 'details': 'python-twisted security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:python3-twisted-22.4.0-5.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:python-twisted-22.4.0-5.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:python-twisted-help-22.4.0-5.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:python3-twisted-22.4.0-5.oe2003sp4.aarch64']}}]}
db7367b5591f38d77e007881921a303a6cdc932efd8ab2e32fc82bff6f0696de
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2368
An update for python-twisted is now available for openEuler-22.03-LTS-SP4
High
2026-05-22 16:21:56+03:00
2026-05-22 16:21:56+03:00
['CVE-2026-42304']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch.rpm', 'product_id': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python-twisted-22.4.0-5.oe2203sp4.src.rpm', 'product_id': 'python-twisted-22.4.0-5.oe2203sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2368', 'summary': 'openEuler-SA-2026-2368', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2368.json', 'summary': 'openEuler-SA-2026-2368 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-twisted security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:\n\nSecurity Fix(es):\n\nA denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.(CVE-2026-42304)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'python-twisted', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-twisted is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2368', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:56+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:56+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:56+08:00', 'initial_release_date': '2026-05-22T21:21:56+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2368', 'summary': 'openEuler-SA-2026-2368', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2368.json', 'summary': 'openEuler-SA-2026-2368 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch.rpm', 'product': {'name': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch.rpm', 'product_id': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64.rpm', 'product': {'name': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64.rpm', 'product': {'name': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64.rpm', 'product_id': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'python-twisted-22.4.0-5.oe2203sp4.src.rpm', 'product': {'name': 'python-twisted-22.4.0-5.oe2203sp4.src.rpm', 'product_id': 'python-twisted-22.4.0-5.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python-twisted-help-22.4.0-5.oe2203sp4.noarch'}, 'product_reference': 'python-twisted-help-22.4.0-5.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-twisted-22.4.0-5.oe2203sp4.aarch64'}, 'product_reference': 'python3-twisted-22.4.0-5.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-twisted-22.4.0-5.oe2203sp4.x86_64'}, 'product_reference': 'python3-twisted-22.4.0-5.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-22.4.0-5.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python-twisted-22.4.0-5.oe2203sp4.src'}, 'product_reference': 'python-twisted-22.4.0-5.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42304', 'notes': [{'text': "A denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2368', 'details': 'python-twisted security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:python-twisted-help-22.4.0-5.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:python3-twisted-22.4.0-5.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-twisted-22.4.0-5.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python-twisted-22.4.0-5.oe2203sp4.src']}}]}
c0791bf5d0e1eced1bd703e176af235b655ef072664f6167d43bb4e0f264b42f
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2369
An update for python-twisted is now available for openEuler-24.03-LTS
High
2026-05-22 16:21:56+03:00
2026-05-22 16:21:56+03:00
['CVE-2026-42304']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-twisted-help-22.10.0-5.oe2403.noarch.rpm', 'product_id': 'python-twisted-help-22.10.0-5.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-twisted-22.10.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-twisted-22.10.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-twisted-22.10.0-5.oe2403.src.rpm', 'product_id': 'python-twisted-22.10.0-5.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2369', 'summary': 'openEuler-SA-2026-2369', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2369.json', 'summary': 'openEuler-SA-2026-2369 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-twisted security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': "Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:\n\nSecurity Fix(es):\n\nA denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.(CVE-2026-42304)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'python-twisted', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-twisted is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2369', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:56+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:56+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:56+08:00', 'initial_release_date': '2026-05-22T21:21:56+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2369', 'summary': 'openEuler-SA-2026-2369', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2369.json', 'summary': 'openEuler-SA-2026-2369 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'python-twisted-help-22.10.0-5.oe2403.noarch.rpm', 'product': {'name': 'python-twisted-help-22.10.0-5.oe2403.noarch.rpm', 'product_id': 'python-twisted-help-22.10.0-5.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'python3-twisted-22.10.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python3-twisted-22.10.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'python3-twisted-22.10.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python3-twisted-22.10.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'python-twisted-22.10.0-5.oe2403.src.rpm', 'product': {'name': 'python-twisted-22.10.0-5.oe2403.src.rpm', 'product_id': 'python-twisted-22.10.0-5.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-help-22.10.0-5.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-twisted-help-22.10.0-5.oe2403.noarch'}, 'product_reference': 'python-twisted-help-22.10.0-5.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.10.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-twisted-22.10.0-5.oe2403.aarch64'}, 'product_reference': 'python3-twisted-22.10.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.10.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-twisted-22.10.0-5.oe2403.x86_64'}, 'product_reference': 'python3-twisted-22.10.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-22.10.0-5.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-twisted-22.10.0-5.oe2403.src'}, 'product_reference': 'python-twisted-22.10.0-5.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42304', 'notes': [{'text': "A denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2369', 'details': 'python-twisted security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:python-twisted-help-22.10.0-5.oe2403.noarch', 'openEuler-24.03-LTS:python3-twisted-22.10.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python3-twisted-22.10.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python-twisted-22.10.0-5.oe2403.src']}}]}
57952304fd5750497cbf709d72cde485b54b40601a7fc29c40a9441f2278c8b8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2370
An update for python-twisted is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:21:56+03:00
2026-05-22 16:21:56+03:00
['CVE-2026-42304']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-twisted-22.10.0-5.oe2403sp3.src.rpm', 'product_id': 'python-twisted-22.10.0-5.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch.rpm', 'product_id': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2370', 'summary': 'openEuler-SA-2026-2370', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2370.json', 'summary': 'openEuler-SA-2026-2370 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-twisted security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': "Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:\n\nSecurity Fix(es):\n\nA denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.(CVE-2026-42304)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-twisted is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'python-twisted', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-twisted is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2370', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:56+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:56+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:56+08:00', 'initial_release_date': '2026-05-22T21:21:56+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2370', 'summary': 'openEuler-SA-2026-2370', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42304&packageName=python-twisted', 'summary': 'CVE-2026-42304', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2370.json', 'summary': 'openEuler-SA-2026-2370 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'python-twisted-22.10.0-5.oe2403sp3.src.rpm', 'product': {'name': 'python-twisted-22.10.0-5.oe2403sp3.src.rpm', 'product_id': 'python-twisted-22.10.0-5.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch.rpm', 'product': {'name': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch.rpm', 'product_id': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-twisted-22.10.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python3-twisted-22.10.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-twisted-22.10.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python3-twisted-22.10.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-22.10.0-5.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-twisted-22.10.0-5.oe2403sp3.src'}, 'product_reference': 'python-twisted-22.10.0-5.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-twisted-help-22.10.0-5.oe2403sp3.noarch'}, 'product_reference': 'python-twisted-help-22.10.0-5.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42304', 'notes': [{'text': "A denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2370', 'details': 'python-twisted security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:python3-twisted-22.10.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-twisted-22.10.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python-twisted-22.10.0-5.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:python-twisted-help-22.10.0-5.oe2403sp3.noarch']}}]}
0d104d827b34c5408c49c2874262f55a382740bdeadf97db99d7c03990860e57
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2371
An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS
Medium
2026-05-22 16:21:56+03:00
2026-05-22 16:21:56+03:00
['CVE-2026-7010']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perl-HTTP-Tiny-0.088-2.oe2403.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2371', 'summary': 'openEuler-SA-2026-2371', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2371.json', 'summary': 'openEuler-SA-2026-2371 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'perl-HTTP-Tiny security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'This is a very simple HTTP/1.1 client, designed for doing simple requests without the overhead of a large framework like LWP::UserAgent.\n\nSecurity Fix(es):\n\nHTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.(CVE-2026-7010)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'perl-HTTP-Tiny', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2371', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:56+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:56+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:56+08:00', 'initial_release_date': '2026-05-22T21:21:56+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2371', 'summary': 'openEuler-SA-2026-2371', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2371.json', 'summary': 'openEuler-SA-2026-2371 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'perl-HTTP-Tiny-0.088-2.oe2403.src.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perl-HTTP-Tiny-0.088-2.oe2403.noarch'}, 'product_reference': 'perl-HTTP-Tiny-0.088-2.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perl-HTTP-Tiny-help-0.088-2.oe2403.noarch'}, 'product_reference': 'perl-HTTP-Tiny-help-0.088-2.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perl-HTTP-Tiny-0.088-2.oe2403.src'}, 'product_reference': 'perl-HTTP-Tiny-0.088-2.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-7010', 'notes': [{'text': 'HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2371', 'details': 'perl-HTTP-Tiny security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:perl-HTTP-Tiny-0.088-2.oe2403.noarch', 'openEuler-24.03-LTS:perl-HTTP-Tiny-help-0.088-2.oe2403.noarch', 'openEuler-24.03-LTS:perl-HTTP-Tiny-0.088-2.oe2403.src']}}]}
50e71cae883151b5379c11d78beb709b1fb8bd0ff27c9de9fe445c7d6651060e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2372
An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-22 16:21:56+03:00
2026-05-22 16:21:56+03:00
['CVE-2026-7010']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2372', 'summary': 'openEuler-SA-2026-2372', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2372.json', 'summary': 'openEuler-SA-2026-2372 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'perl-HTTP-Tiny security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'This is a very simple HTTP/1.1 client, designed for doing simple requests without the overhead of a large framework like LWP::UserAgent.\n\nSecurity Fix(es):\n\nHTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.(CVE-2026-7010)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'perl-HTTP-Tiny', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for perl-HTTP-Tiny is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2372', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:56+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:56+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:56+08:00', 'initial_release_date': '2026-05-22T21:21:56+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2372', 'summary': 'openEuler-SA-2026-2372', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2372.json', 'summary': 'openEuler-SA-2026-2372 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch'}, 'product_reference': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch'}, 'product_reference': 'perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perl-HTTP-Tiny-0.088-2.oe2403sp3.src'}, 'product_reference': 'perl-HTTP-Tiny-0.088-2.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-7010', 'notes': [{'text': 'HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2372', 'details': 'perl-HTTP-Tiny security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:perl-HTTP-Tiny-0.088-2.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:perl-HTTP-Tiny-help-0.088-2.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:perl-HTTP-Tiny-0.088-2.oe2403sp3.src']}}]}
06ad7ccaef674b97b9ec275bf4be39b24dde66c2551effb0a42a5f604fa19c76
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2373
An update for perl-HTTP-Tiny is now available for openEuler-20.03-LTS-SP4
Medium
2026-05-22 16:21:57+03:00
2026-05-22 16:21:57+03:00
['CVE-2026-7010']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2373', 'summary': 'openEuler-SA-2026-2373', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2373.json', 'summary': 'openEuler-SA-2026-2373 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'perl-HTTP-Tiny security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'This is a very simple HTTP/1.1 client, designed for doing simple requests without the overhead of a large framework like LWP::UserAgent.\n\nSecurity Fix(es):\n\nHTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.(CVE-2026-7010)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'perl-HTTP-Tiny', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for perl-HTTP-Tiny is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2373', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:57+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:57+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:57+08:00', 'initial_release_date': '2026-05-22T21:21:57+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2373', 'summary': 'openEuler-SA-2026-2373', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2373.json', 'summary': 'openEuler-SA-2026-2373 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch'}, 'product_reference': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch'}, 'product_reference': 'perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perl-HTTP-Tiny-0.076-5.oe2003sp4.src'}, 'product_reference': 'perl-HTTP-Tiny-0.076-5.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-7010', 'notes': [{'text': 'HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2373', 'details': 'perl-HTTP-Tiny security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:perl-HTTP-Tiny-0.076-5.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:perl-HTTP-Tiny-help-0.076-5.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:perl-HTTP-Tiny-0.076-5.oe2003sp4.src']}}]}
cb6c171a24640e4131358fac1ff661b513d73d3bea2cfb0f5f64916d300d670b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2374
An update for perl-HTTP-Tiny is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-22 16:21:57+03:00
2026-05-22 16:21:57+03:00
['CVE-2026-7010']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2374', 'summary': 'openEuler-SA-2026-2374', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2374.json', 'summary': 'openEuler-SA-2026-2374 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'perl-HTTP-Tiny security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'This is a very simple HTTP/1.1 client, designed for doing simple requests without the overhead of a large framework like LWP::UserAgent.\n\nSecurity Fix(es):\n\nHTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.(CVE-2026-7010)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for perl-HTTP-Tiny is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'perl-HTTP-Tiny', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for perl-HTTP-Tiny is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2374', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:57+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:57+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:57+08:00', 'initial_release_date': '2026-05-22T21:21:57+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2374', 'summary': 'openEuler-SA-2026-2374', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7010&packageName=perl-HTTP-Tiny', 'summary': 'CVE-2026-7010', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2374.json', 'summary': 'openEuler-SA-2026-2374 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch.rpm', 'product': {'name': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch.rpm', 'product_id': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src.rpm', 'product': {'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src.rpm', 'product_id': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch'}, 'product_reference': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch'}, 'product_reference': 'perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perl-HTTP-Tiny-0.080-3.oe2203sp4.src'}, 'product_reference': 'perl-HTTP-Tiny-0.080-3.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-7010', 'notes': [{'text': 'HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2374', 'details': 'perl-HTTP-Tiny security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:perl-HTTP-Tiny-0.080-3.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:perl-HTTP-Tiny-help-0.080-3.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:perl-HTTP-Tiny-0.080-3.oe2203sp4.src']}}]}
3ec5da639369103d10b0e0981dce1dee1e724d97808e496d416db9b63b3c1f72
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2376
An update for vorbis-tools is now available for openEuler-22.03-LTS-SP4
High
2026-05-22 16:21:57+03:00
2026-05-22 16:21:57+03:00
['CVE-2026-34253']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch.rpm', 'product_id': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-1.4.2-5.oe2203sp4.src.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2376', 'summary': 'openEuler-SA-2026-2376', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34253&packageName=vorbis-tools', 'summary': 'CVE-2026-34253', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2376.json', 'summary': 'openEuler-SA-2026-2376 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'vorbis-tools security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for vorbis-tools is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Ogg Vorbis is a fully open, non-proprietary, patent-and-royalty-free, general-purpose compressed audio format for mid to high quality (8kHz-48.0kHz, 16+ bit, polyphonic) audio and music at fixed and variable bitrates from 16 to 128 kbps/channel. This places Vorbis in the same competitive class as audio representations such as MPEG-4 (AAC), and similar to, but higher performance than MPEG-1/2 audio layer 3, MPEG-4 audio (TwinVQ), WMA and PAC.\n\nSecurity Fix(es):\n\nA buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.(CVE-2026-34253)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for vorbis-tools is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'vorbis-tools', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for vorbis-tools is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2376', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:57+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:57+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:57+08:00', 'initial_release_date': '2026-05-22T21:21:57+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2376', 'summary': 'openEuler-SA-2026-2376', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34253&packageName=vorbis-tools', 'summary': 'CVE-2026-34253', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2376.json', 'summary': 'openEuler-SA-2026-2376 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch.rpm', 'product': {'name': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch.rpm', 'product_id': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64.rpm', 'product': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64.rpm', 'product': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2203sp4.src.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2203sp4.src.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64.rpm', 'product': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64.rpm', 'product': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-help-1.4.2-5.oe2203sp4.noarch'}, 'product_reference': 'vorbis-tools-help-1.4.2-5.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-1.4.2-5.oe2203sp4.aarch64'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64'}, 'product_reference': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64'}, 'product_reference': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-1.4.2-5.oe2203sp4.src'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-1.4.2-5.oe2203sp4.x86_64'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64'}, 'product_reference': 'vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64'}, 'product_reference': 'vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34253', 'notes': [{'text': 'A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34253', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2376', 'details': 'vorbis-tools security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:vorbis-tools-help-1.4.2-5.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:vorbis-tools-1.4.2-5.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:vorbis-tools-debugsource-1.4.2-5.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:vorbis-tools-1.4.2-5.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:vorbis-tools-1.4.2-5.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:vorbis-tools-debuginfo-1.4.2-5.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:vorbis-tools-debugsource-1.4.2-5.oe2203sp4.x86_64']}}]}
6ff0b93b6153e3fd934051e7f7b0e3ac91d4e1bc9e961a846833079016adefd2
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2377
An update for vorbis-tools is now available for openEuler-24.03-LTS
High
2026-05-22 16:21:57+03:00
2026-05-22 16:21:57+03:00
['CVE-2026-34253']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-1.4.2-5.oe2403.aarch64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-1.4.2-5.oe2403.src.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-1.4.2-5.oe2403.x86_64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'vorbis-tools-help-1.4.2-5.oe2403.noarch.rpm', 'product_id': 'vorbis-tools-help-1.4.2-5.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2377', 'summary': 'openEuler-SA-2026-2377', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34253&packageName=vorbis-tools', 'summary': 'CVE-2026-34253', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2377.json', 'summary': 'openEuler-SA-2026-2377 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'vorbis-tools security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for vorbis-tools is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Ogg Vorbis is a fully open, non-proprietary, patent-and-royalty-free, general-purpose compressed audio format for mid to high quality (8kHz-48.0kHz, 16+ bit, polyphonic) audio and music at fixed and variable bitrates from 16 to 128 kbps/channel. This places Vorbis in the same competitive class as audio representations such as MPEG-4 (AAC), and similar to, but higher performance than MPEG-1/2 audio layer 3, MPEG-4 audio (TwinVQ), WMA and PAC.\n\nSecurity Fix(es):\n\nA buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.(CVE-2026-34253)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for vorbis-tools is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'vorbis-tools', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for vorbis-tools is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2377', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:57+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:57+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:57+08:00', 'initial_release_date': '2026-05-22T21:21:57+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2377', 'summary': 'openEuler-SA-2026-2377', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34253&packageName=vorbis-tools', 'summary': 'CVE-2026-34253', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2377.json', 'summary': 'openEuler-SA-2026-2377 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2403.aarch64.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2403.aarch64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64.rpm', 'product': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64.rpm', 'product': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2403.src.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2403.src.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2403.x86_64.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2403.x86_64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64.rpm', 'product': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64.rpm', 'product': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'vorbis-tools-help-1.4.2-5.oe2403.noarch.rpm', 'product': {'name': 'vorbis-tools-help-1.4.2-5.oe2403.noarch.rpm', 'product_id': 'vorbis-tools-help-1.4.2-5.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-1.4.2-5.oe2403.aarch64'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64'}, 'product_reference': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64'}, 'product_reference': 'vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-1.4.2-5.oe2403.src'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-1.4.2-5.oe2403.x86_64'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64'}, 'product_reference': 'vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64'}, 'product_reference': 'vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-help-1.4.2-5.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:vorbis-tools-help-1.4.2-5.oe2403.noarch'}, 'product_reference': 'vorbis-tools-help-1.4.2-5.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34253', 'notes': [{'text': 'A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34253', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2377', 'details': 'vorbis-tools security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:vorbis-tools-1.4.2-5.oe2403.aarch64', 'openEuler-24.03-LTS:vorbis-tools-debuginfo-1.4.2-5.oe2403.aarch64', 'openEuler-24.03-LTS:vorbis-tools-debugsource-1.4.2-5.oe2403.aarch64', 'openEuler-24.03-LTS:vorbis-tools-1.4.2-5.oe2403.src', 'openEuler-24.03-LTS:vorbis-tools-1.4.2-5.oe2403.x86_64', 'openEuler-24.03-LTS:vorbis-tools-debuginfo-1.4.2-5.oe2403.x86_64', 'openEuler-24.03-LTS:vorbis-tools-debugsource-1.4.2-5.oe2403.x86_64', 'openEuler-24.03-LTS:vorbis-tools-help-1.4.2-5.oe2403.noarch']}}]}
3b05476ad9304540158bb610f687d878b138da9cbb4285fdc42025fb1a231dd9
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2378
An update for vorbis-tools is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:21:58+03:00
2026-05-22 16:21:58+03:00
['CVE-2026-34253']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-1.4.2-5.oe2403sp3.src.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch.rpm', 'product_id': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2378', 'summary': 'openEuler-SA-2026-2378', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34253&packageName=vorbis-tools', 'summary': 'CVE-2026-34253', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2378.json', 'summary': 'openEuler-SA-2026-2378 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'vorbis-tools security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for vorbis-tools is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Ogg Vorbis is a fully open, non-proprietary, patent-and-royalty-free, general-purpose compressed audio format for mid to high quality (8kHz-48.0kHz, 16+ bit, polyphonic) audio and music at fixed and variable bitrates from 16 to 128 kbps/channel. This places Vorbis in the same competitive class as audio representations such as MPEG-4 (AAC), and similar to, but higher performance than MPEG-1/2 audio layer 3, MPEG-4 audio (TwinVQ), WMA and PAC.\n\nSecurity Fix(es):\n\nA buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.(CVE-2026-34253)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for vorbis-tools is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'vorbis-tools', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for vorbis-tools is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2378', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:58+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:58+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:58+08:00', 'initial_release_date': '2026-05-22T21:21:58+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2378', 'summary': 'openEuler-SA-2026-2378', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34253&packageName=vorbis-tools', 'summary': 'CVE-2026-34253', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2378.json', 'summary': 'openEuler-SA-2026-2378 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2403sp3.src.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2403sp3.src.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_id': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_id': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_id': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch.rpm', 'product': {'name': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch.rpm', 'product_id': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-1.4.2-5.oe2403sp3.aarch64'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64'}, 'product_reference': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64'}, 'product_reference': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-1.4.2-5.oe2403sp3.src'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-1.4.2-5.oe2403sp3.x86_64'}, 'product_reference': 'vorbis-tools-1.4.2-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64'}, 'product_reference': 'vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64'}, 'product_reference': 'vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:vorbis-tools-help-1.4.2-5.oe2403sp3.noarch'}, 'product_reference': 'vorbis-tools-help-1.4.2-5.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34253', 'notes': [{'text': 'A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34253', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2378', 'details': 'vorbis-tools security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:vorbis-tools-1.4.2-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:vorbis-tools-debugsource-1.4.2-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:vorbis-tools-1.4.2-5.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:vorbis-tools-1.4.2-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:vorbis-tools-debuginfo-1.4.2-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:vorbis-tools-debugsource-1.4.2-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:vorbis-tools-help-1.4.2-5.oe2403sp3.noarch']}}]}
070b6b775dac69e4cdfca2662785e56600542d152527cb68141e5b7830ad1326
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2379
An update for libsoup3 is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:21:58+03:00
2026-05-22 16:21:58+03:00
['CVE-2026-5119']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-3.4.5-14.oe2403sp3.src.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2379', 'summary': 'openEuler-SA-2026-2379', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5119&packageName=libsoup3', 'summary': 'CVE-2026-5119', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5119', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2379.json', 'summary': 'openEuler-SA-2026-2379 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libsoup3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.\n\nSecurity Fix(es):\n\nA flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.(CVE-2026-5119)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libsoup3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libsoup3 is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2379', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:58+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:58+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:58+08:00', 'initial_release_date': '2026-05-22T21:21:58+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2379', 'summary': 'openEuler-SA-2026-2379', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5119&packageName=libsoup3', 'summary': 'CVE-2026-5119', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5119', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2379.json', 'summary': 'openEuler-SA-2026-2379 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libsoup3-3.4.5-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libsoup3-3.4.5-14.oe2403sp3.src.rpm', 'product': {'name': 'libsoup3-3.4.5-14.oe2403sp3.src.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libsoup3-3.4.5-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch.rpm', 'product': {'name': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-14.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-3.4.5-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-14.oe2403sp3.aarch64'}, 'product_reference': 'libsoup3-devel-3.4.5-14.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-14.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-14.oe2403sp3.src'}, 'product_reference': 'libsoup3-3.4.5-14.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-14.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-3.4.5-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-14.oe2403sp3.x86_64'}, 'product_reference': 'libsoup3-devel-3.4.5-14.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libsoup3-help-3.4.5-14.oe2403sp3.noarch'}, 'product_reference': 'libsoup3-help-3.4.5-14.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-5119', 'notes': [{'text': 'A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5119', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2379', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:libsoup3-3.4.5-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-14.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-14.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:libsoup3-3.4.5-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-debuginfo-3.4.5-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-debugsource-3.4.5-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-devel-3.4.5-14.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libsoup3-help-3.4.5-14.oe2403sp3.noarch']}}]}
99a43195051b1293eb9e6a64c456ba755e418063a4ff5df549e145cfb0741581
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2380
An update for libsoup3 is now available for openEuler-24.03-LTS
High
2026-05-22 16:21:58+03:00
2026-05-22 16:21:58+03:00
['CVE-2026-5119']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-devel-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-3.4.5-14.oe2403.src.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-devel-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libsoup3-help-3.4.5-14.oe2403.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-14.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2380', 'summary': 'openEuler-SA-2026-2380', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5119&packageName=libsoup3', 'summary': 'CVE-2026-5119', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5119', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2380.json', 'summary': 'openEuler-SA-2026-2380 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libsoup3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.\n\nSecurity Fix(es):\n\nA flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.(CVE-2026-5119)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libsoup3 is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libsoup3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libsoup3 is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2380', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:58+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:58+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:58+08:00', 'initial_release_date': '2026-05-22T21:21:58+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2380', 'summary': 'openEuler-SA-2026-2380', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5119&packageName=libsoup3', 'summary': 'CVE-2026-5119', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5119', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2380.json', 'summary': 'openEuler-SA-2026-2380 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libsoup3-3.4.5-14.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-14.oe2403.aarch64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-14.oe2403.aarch64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libsoup3-3.4.5-14.oe2403.src.rpm', 'product': {'name': 'libsoup3-3.4.5-14.oe2403.src.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libsoup3-3.4.5-14.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-3.4.5-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libsoup3-devel-3.4.5-14.oe2403.x86_64.rpm', 'product': {'name': 'libsoup3-devel-3.4.5-14.oe2403.x86_64.rpm', 'product_id': 'libsoup3-devel-3.4.5-14.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'libsoup3-help-3.4.5-14.oe2403.noarch.rpm', 'product': {'name': 'libsoup3-help-3.4.5-14.oe2403.noarch.rpm', 'product_id': 'libsoup3-help-3.4.5-14.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-3.4.5-14.oe2403.aarch64'}, 'product_reference': 'libsoup3-3.4.5-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-14.oe2403.aarch64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-14.oe2403.aarch64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-14.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-14.oe2403.aarch64'}, 'product_reference': 'libsoup3-devel-3.4.5-14.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-14.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-3.4.5-14.oe2403.src'}, 'product_reference': 'libsoup3-3.4.5-14.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-3.4.5-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-3.4.5-14.oe2403.x86_64'}, 'product_reference': 'libsoup3-3.4.5-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-14.oe2403.x86_64'}, 'product_reference': 'libsoup3-debuginfo-3.4.5-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-14.oe2403.x86_64'}, 'product_reference': 'libsoup3-debugsource-3.4.5-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-devel-3.4.5-14.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-14.oe2403.x86_64'}, 'product_reference': 'libsoup3-devel-3.4.5-14.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libsoup3-help-3.4.5-14.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libsoup3-help-3.4.5-14.oe2403.noarch'}, 'product_reference': 'libsoup3-help-3.4.5-14.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-5119', 'notes': [{'text': 'A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5119', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2380', 'details': 'libsoup3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:libsoup3-3.4.5-14.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-14.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-14.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-14.oe2403.aarch64', 'openEuler-24.03-LTS:libsoup3-3.4.5-14.oe2403.src', 'openEuler-24.03-LTS:libsoup3-3.4.5-14.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-debuginfo-3.4.5-14.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-debugsource-3.4.5-14.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-devel-3.4.5-14.oe2403.x86_64', 'openEuler-24.03-LTS:libsoup3-help-3.4.5-14.oe2403.noarch']}}]}
dcb03996973fc9d31f2a94e9caa07b050aa8981d48c59a465d48c6f64074401b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2381
An update for libpq is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:21:58+03:00
2026-05-22 16:21:58+03:00
['CVE-2026-6472', 'CVE-2026-6473', 'CVE-2026-6474', 'CVE-2026-6475', 'CVE-2026-6477', 'CVE-2026-6478', 'CVE-2026-6479', 'CVE-2026-6637']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-15.18-1.oe2403sp3.src.rpm', 'product_id': 'libpq-15.18-1.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libpq-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'summary': 'openEuler-SA-2026-2381', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=libpq', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=libpq', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=libpq', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=libpq', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=libpq', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=libpq', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=libpq', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=libpq', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2381.json', 'summary': 'openEuler-SA-2026-2381 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libpq security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libpq is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'PostgreSQL is a powerful, open source object-relational database system that uses and extends the SQL language combined with many features that safely store and scale the most complicated data workloads. This package provides the essential shared library for any PostgreSQL client program or interface.\n\nSecurity Fix(es):\n\nMissing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker\'s choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6472)\n\nInteger wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6473)\n\nExternally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6474)\n\nSymlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6475)\n\nUse of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6477)\n\nCovert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6478)\n\nUncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6479)\n\nStack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6637)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libpq is now available for master/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libpq', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libpq is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2381', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:58+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:58+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:58+08:00', 'initial_release_date': '2026-05-22T21:21:58+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'summary': 'openEuler-SA-2026-2381', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=libpq', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=libpq', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=libpq', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=libpq', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=libpq', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=libpq', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=libpq', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=libpq', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2381.json', 'summary': 'openEuler-SA-2026-2381 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libpq-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'libpq-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libpq-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'libpq-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libpq-15.18-1.oe2403sp3.src.rpm', 'product': {'name': 'libpq-15.18-1.oe2403sp3.src.rpm', 'product_id': 'libpq-15.18-1.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libpq-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'libpq-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libpq-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'libpq-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libpq-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'libpq-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-debuginfo-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'libpq-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-debugsource-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'libpq-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-devel-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-devel-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'libpq-devel-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-15.18-1.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-15.18-1.oe2403sp3.src'}, 'product_reference': 'libpq-15.18-1.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'libpq-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-debuginfo-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'libpq-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-debugsource-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'libpq-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-devel-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libpq-devel-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'libpq-devel-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-6472', 'notes': [{'text': "Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6472', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:libpq-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libpq-debuginfo-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libpq-debugsource-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libpq-devel-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libpq-15.18-1.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:libpq-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libpq-debuginfo-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libpq-debugsource-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libpq-devel-15.18-1.oe2403sp3.x86_64']}}, {'cve': 'CVE-2026-6473', 'notes': [{'text': 'Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6473', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6474', 'notes': [{'text': 'Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6474', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6475', 'notes': [{'text': 'Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6475', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6477', 'notes': [{'text': 'Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6477', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6478', 'notes': [{'text': 'Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6478', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6479', 'notes': [{'text': 'Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6479', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6637', 'notes': [{'text': 'Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6637', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2381', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
901634801d52178db4c67040e420bc0a572d4ce40122dce1bb284a3e7ec25f61
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2382
An update for libpq is now available for openEuler-24.03-LTS
High
2026-05-22 16:21:59+03:00
2026-05-22 16:21:59+03:00
['CVE-2026-6472', 'CVE-2026-6473', 'CVE-2026-6474', 'CVE-2026-6475', 'CVE-2026-6477', 'CVE-2026-6478', 'CVE-2026-6479', 'CVE-2026-6637']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-debugsource-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-devel-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-15.18-1.oe2403.src.rpm', 'product_id': 'libpq-15.18-1.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-debugsource-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libpq-devel-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'summary': 'openEuler-SA-2026-2382', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=libpq', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=libpq', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=libpq', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=libpq', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=libpq', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=libpq', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=libpq', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=libpq', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2382.json', 'summary': 'openEuler-SA-2026-2382 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'libpq security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for libpq is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'PostgreSQL is a powerful, open source object-relational database system that uses and extends the SQL language combined with many features that safely store and scale the most complicated data workloads. This package provides the essential shared library for any PostgreSQL client program or interface.\n\nSecurity Fix(es):\n\nMissing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker\'s choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6472)\n\nInteger wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6473)\n\nExternally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6474)\n\nSymlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6475)\n\nUse of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6477)\n\nCovert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6478)\n\nUncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6479)\n\nStack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6637)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for libpq is now available for master/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'libpq', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for libpq is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2382', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:59+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:59+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:59+08:00', 'initial_release_date': '2026-05-22T21:21:59+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'summary': 'openEuler-SA-2026-2382', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=libpq', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=libpq', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=libpq', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=libpq', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=libpq', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=libpq', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=libpq', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=libpq', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2382.json', 'summary': 'openEuler-SA-2026-2382 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'libpq-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'libpq-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libpq-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'libpq-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libpq-debugsource-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'libpq-debugsource-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libpq-devel-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'libpq-devel-15.18-1.oe2403.aarch64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'libpq-15.18-1.oe2403.src.rpm', 'product': {'name': 'libpq-15.18-1.oe2403.src.rpm', 'product_id': 'libpq-15.18-1.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'libpq-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'libpq-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libpq-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'libpq-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libpq-debugsource-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'libpq-debugsource-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-debugsource-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libpq-devel-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'libpq-devel-15.18-1.oe2403.x86_64.rpm', 'product_id': 'libpq-devel-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'libpq-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-15.18-1.oe2403.aarch64'}, 'product_reference': 'libpq-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debuginfo-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-debuginfo-15.18-1.oe2403.aarch64'}, 'product_reference': 'libpq-debuginfo-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debugsource-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-debugsource-15.18-1.oe2403.aarch64'}, 'product_reference': 'libpq-debugsource-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-devel-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-devel-15.18-1.oe2403.aarch64'}, 'product_reference': 'libpq-devel-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-15.18-1.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-15.18-1.oe2403.src'}, 'product_reference': 'libpq-15.18-1.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-15.18-1.oe2403.x86_64'}, 'product_reference': 'libpq-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debuginfo-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-debuginfo-15.18-1.oe2403.x86_64'}, 'product_reference': 'libpq-debuginfo-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-debugsource-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-debugsource-15.18-1.oe2403.x86_64'}, 'product_reference': 'libpq-debugsource-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libpq-devel-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libpq-devel-15.18-1.oe2403.x86_64'}, 'product_reference': 'libpq-devel-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-6472', 'notes': [{'text': "Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6472', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:libpq-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:libpq-debuginfo-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:libpq-debugsource-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:libpq-devel-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:libpq-15.18-1.oe2403.src', 'openEuler-24.03-LTS:libpq-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:libpq-debuginfo-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:libpq-debugsource-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:libpq-devel-15.18-1.oe2403.x86_64']}}, {'cve': 'CVE-2026-6473', 'notes': [{'text': 'Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6473', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6474', 'notes': [{'text': 'Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6474', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6475', 'notes': [{'text': 'Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6475', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6477', 'notes': [{'text': 'Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6477', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6478', 'notes': [{'text': 'Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6478', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6479', 'notes': [{'text': 'Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6479', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6637', 'notes': [{'text': 'Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6637', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2382', 'details': 'libpq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
f3a10ab7e3f4273e672125788bf9cc2e0576829fa419d3b59ea0325ffec3834b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2383
An update for trafficserver is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:21:59+03:00
2026-05-22 16:21:59+03:00
['CVE-2025-58136', 'CVE-2025-65114']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-9.2.11-3.oe2403sp3.src.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2383', 'summary': 'openEuler-SA-2026-2383', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-58136&packageName=trafficserver', 'summary': 'CVE-2025-58136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-65114&packageName=trafficserver', 'summary': 'CVE-2025-65114', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-58136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-65114', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2383.json', 'summary': 'openEuler-SA-2026-2383 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'trafficserver security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for trafficserver is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.\n\nSecurity Fix(es):\n\nA bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set\xa0proxy.config.http.request_buffer_enabled to 0 (the default value is 0).(CVE-2025-58136)\n\nApache Traffic Server allows request smuggling if chunked messages are malformed.\xa0\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.\n\nUsers are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.(CVE-2025-65114)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for trafficserver is now available for master/openEuler-20.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'trafficserver', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for trafficserver is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2383', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:59+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:59+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:59+08:00', 'initial_release_date': '2026-05-22T21:21:59+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2383', 'summary': 'openEuler-SA-2026-2383', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-58136&packageName=trafficserver', 'summary': 'CVE-2025-58136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-65114&packageName=trafficserver', 'summary': 'CVE-2025-65114', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-58136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-65114', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2383.json', 'summary': 'openEuler-SA-2026-2383 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'trafficserver-9.2.11-3.oe2403sp3.src.rpm', 'product': {'name': 'trafficserver-9.2.11-3.oe2403sp3.src.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'trafficserver-9.2.11-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'trafficserver-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64.rpm', 'product': {'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'trafficserver-9.2.11-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'trafficserver-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64.rpm', 'product': {'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.2.11-3.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-9.2.11-3.oe2403sp3.src'}, 'product_reference': 'trafficserver-9.2.11-3.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.2.11-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-9.2.11-3.oe2403sp3.x86_64'}, 'product_reference': 'trafficserver-9.2.11-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64'}, 'product_reference': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64'}, 'product_reference': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-devel-9.2.11-3.oe2403sp3.x86_64'}, 'product_reference': 'trafficserver-devel-9.2.11-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-perl-9.2.11-3.oe2403sp3.x86_64'}, 'product_reference': 'trafficserver-perl-9.2.11-3.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.2.11-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-9.2.11-3.oe2403sp3.aarch64'}, 'product_reference': 'trafficserver-9.2.11-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64'}, 'product_reference': 'trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64'}, 'product_reference': 'trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-devel-9.2.11-3.oe2403sp3.aarch64'}, 'product_reference': 'trafficserver-devel-9.2.11-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:trafficserver-perl-9.2.11-3.oe2403sp3.aarch64'}, 'product_reference': 'trafficserver-perl-9.2.11-3.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-58136', 'notes': [{'text': 'A bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set\xa0proxy.config.http.request_buffer_enabled to 0 (the default value is 0).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-58136', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2383', 'details': 'trafficserver security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:trafficserver-9.2.11-3.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:trafficserver-9.2.11-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:trafficserver-debuginfo-9.2.11-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:trafficserver-debugsource-9.2.11-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:trafficserver-devel-9.2.11-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:trafficserver-perl-9.2.11-3.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:trafficserver-9.2.11-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:trafficserver-debuginfo-9.2.11-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:trafficserver-debugsource-9.2.11-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:trafficserver-devel-9.2.11-3.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:trafficserver-perl-9.2.11-3.oe2403sp3.aarch64']}}, {'cve': 'CVE-2025-65114', 'notes': [{'text': 'Apache Traffic Server allows request smuggling if chunked messages are malformed.\xa0\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.\n\nUsers are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-65114', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2383', 'details': 'trafficserver security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
b59fe4dd187e4b1527df037cc51aaef3ad8f60bd1681d58545f21aefef39305e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2384
An update for trafficserver is now available for openEuler-20.03-LTS-SP4
High
2026-05-22 16:21:59+03:00
2026-05-22 16:21:59+03:00
['CVE-2025-58136']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-9.1.4-6.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-9.1.4-6.oe2003sp4.src.rpm', 'product_id': 'trafficserver-9.1.4-6.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-9.1.4-6.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2384', 'summary': 'openEuler-SA-2026-2384', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-58136&packageName=trafficserver', 'summary': 'CVE-2025-58136', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-58136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2384.json', 'summary': 'openEuler-SA-2026-2384 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'trafficserver security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for trafficserver is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.\n\nSecurity Fix(es):\n\nA bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set\xa0proxy.config.http.request_buffer_enabled to 0 (the default value is 0).(CVE-2025-58136)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for trafficserver is now available for master/openEuler-20.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'trafficserver', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for trafficserver is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2384', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:59+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:59+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:59+08:00', 'initial_release_date': '2026-05-22T21:21:59+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2384', 'summary': 'openEuler-SA-2026-2384', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-58136&packageName=trafficserver', 'summary': 'CVE-2025-58136', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-58136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2384.json', 'summary': 'openEuler-SA-2026-2384 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'trafficserver-9.1.4-6.oe2003sp4.aarch64.rpm', 'product': {'name': 'trafficserver-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64.rpm', 'product': {'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64.rpm', 'product': {'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64.rpm', 'product': {'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64.rpm', 'product': {'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_id': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'trafficserver-9.1.4-6.oe2003sp4.src.rpm', 'product': {'name': 'trafficserver-9.1.4-6.oe2003sp4.src.rpm', 'product_id': 'trafficserver-9.1.4-6.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'trafficserver-9.1.4-6.oe2003sp4.x86_64.rpm', 'product': {'name': 'trafficserver-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64.rpm', 'product': {'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64.rpm', 'product': {'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64.rpm', 'product': {'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64.rpm', 'product': {'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_id': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.1.4-6.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-9.1.4-6.oe2003sp4.aarch64'}, 'product_reference': 'trafficserver-9.1.4-6.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64'}, 'product_reference': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64'}, 'product_reference': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-devel-9.1.4-6.oe2003sp4.aarch64'}, 'product_reference': 'trafficserver-devel-9.1.4-6.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-perl-9.1.4-6.oe2003sp4.aarch64'}, 'product_reference': 'trafficserver-perl-9.1.4-6.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.1.4-6.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-9.1.4-6.oe2003sp4.src'}, 'product_reference': 'trafficserver-9.1.4-6.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.1.4-6.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-9.1.4-6.oe2003sp4.x86_64'}, 'product_reference': 'trafficserver-9.1.4-6.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64'}, 'product_reference': 'trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64'}, 'product_reference': 'trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-devel-9.1.4-6.oe2003sp4.x86_64'}, 'product_reference': 'trafficserver-devel-9.1.4-6.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:trafficserver-perl-9.1.4-6.oe2003sp4.x86_64'}, 'product_reference': 'trafficserver-perl-9.1.4-6.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-58136', 'notes': [{'text': 'A bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set\xa0proxy.config.http.request_buffer_enabled to 0 (the default value is 0).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-58136', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2384', 'details': 'trafficserver security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:trafficserver-9.1.4-6.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:trafficserver-debuginfo-9.1.4-6.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:trafficserver-debugsource-9.1.4-6.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:trafficserver-devel-9.1.4-6.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:trafficserver-perl-9.1.4-6.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:trafficserver-9.1.4-6.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:trafficserver-9.1.4-6.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:trafficserver-debuginfo-9.1.4-6.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:trafficserver-debugsource-9.1.4-6.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:trafficserver-devel-9.1.4-6.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:trafficserver-perl-9.1.4-6.oe2003sp4.x86_64']}}]}
7768dcfda2dd2ec7778a1bfa0922b1fdf1bd5011a91cfc27597ff0eda8608e99
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2385
An update for trafficserver is now available for openEuler-24.03-LTS
High
2026-05-22 16:21:59+03:00
2026-05-22 16:21:59+03:00
['CVE-2025-58136', 'CVE-2025-65114']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-devel-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-perl-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-9.2.11-3.oe2403.src.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-devel-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'trafficserver-perl-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2385', 'summary': 'openEuler-SA-2026-2385', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-58136&packageName=trafficserver', 'summary': 'CVE-2025-58136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-65114&packageName=trafficserver', 'summary': 'CVE-2025-65114', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-58136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-65114', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2385.json', 'summary': 'openEuler-SA-2026-2385 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'trafficserver security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for trafficserver is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.\n\nSecurity Fix(es):\n\nA bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set\xa0proxy.config.http.request_buffer_enabled to 0 (the default value is 0).(CVE-2025-58136)\n\nApache Traffic Server allows request smuggling if chunked messages are malformed.\xa0\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.\n\nUsers are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.(CVE-2025-65114)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for trafficserver is now available for master/openEuler-20.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'trafficserver', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for trafficserver is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2385', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:59+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:59+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:59+08:00', 'initial_release_date': '2026-05-22T21:21:59+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2385', 'summary': 'openEuler-SA-2026-2385', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-58136&packageName=trafficserver', 'summary': 'CVE-2025-58136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-65114&packageName=trafficserver', 'summary': 'CVE-2025-65114', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-58136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-65114', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2385.json', 'summary': 'openEuler-SA-2026-2385 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'trafficserver-9.2.11-3.oe2403.aarch64.rpm', 'product': {'name': 'trafficserver-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64.rpm', 'product': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64.rpm', 'product': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-devel-9.2.11-3.oe2403.aarch64.rpm', 'product': {'name': 'trafficserver-devel-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-perl-9.2.11-3.oe2403.aarch64.rpm', 'product': {'name': 'trafficserver-perl-9.2.11-3.oe2403.aarch64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'trafficserver-9.2.11-3.oe2403.src.rpm', 'product': {'name': 'trafficserver-9.2.11-3.oe2403.src.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'trafficserver-9.2.11-3.oe2403.x86_64.rpm', 'product': {'name': 'trafficserver-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-9.2.11-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64.rpm', 'product': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64.rpm', 'product': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-devel-9.2.11-3.oe2403.x86_64.rpm', 'product': {'name': 'trafficserver-devel-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-devel-9.2.11-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'trafficserver-perl-9.2.11-3.oe2403.x86_64.rpm', 'product': {'name': 'trafficserver-perl-9.2.11-3.oe2403.x86_64.rpm', 'product_id': 'trafficserver-perl-9.2.11-3.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.2.11-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-9.2.11-3.oe2403.aarch64'}, 'product_reference': 'trafficserver-9.2.11-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-debuginfo-9.2.11-3.oe2403.aarch64'}, 'product_reference': 'trafficserver-debuginfo-9.2.11-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-debugsource-9.2.11-3.oe2403.aarch64'}, 'product_reference': 'trafficserver-debugsource-9.2.11-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-devel-9.2.11-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-devel-9.2.11-3.oe2403.aarch64'}, 'product_reference': 'trafficserver-devel-9.2.11-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-perl-9.2.11-3.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-perl-9.2.11-3.oe2403.aarch64'}, 'product_reference': 'trafficserver-perl-9.2.11-3.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.2.11-3.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-9.2.11-3.oe2403.src'}, 'product_reference': 'trafficserver-9.2.11-3.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-9.2.11-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-9.2.11-3.oe2403.x86_64'}, 'product_reference': 'trafficserver-9.2.11-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-debuginfo-9.2.11-3.oe2403.x86_64'}, 'product_reference': 'trafficserver-debuginfo-9.2.11-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-debugsource-9.2.11-3.oe2403.x86_64'}, 'product_reference': 'trafficserver-debugsource-9.2.11-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-devel-9.2.11-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-devel-9.2.11-3.oe2403.x86_64'}, 'product_reference': 'trafficserver-devel-9.2.11-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'trafficserver-perl-9.2.11-3.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:trafficserver-perl-9.2.11-3.oe2403.x86_64'}, 'product_reference': 'trafficserver-perl-9.2.11-3.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-58136', 'notes': [{'text': 'A bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set\xa0proxy.config.http.request_buffer_enabled to 0 (the default value is 0).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-58136', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2385', 'details': 'trafficserver security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:trafficserver-9.2.11-3.oe2403.aarch64', 'openEuler-24.03-LTS:trafficserver-debuginfo-9.2.11-3.oe2403.aarch64', 'openEuler-24.03-LTS:trafficserver-debugsource-9.2.11-3.oe2403.aarch64', 'openEuler-24.03-LTS:trafficserver-devel-9.2.11-3.oe2403.aarch64', 'openEuler-24.03-LTS:trafficserver-perl-9.2.11-3.oe2403.aarch64', 'openEuler-24.03-LTS:trafficserver-9.2.11-3.oe2403.src', 'openEuler-24.03-LTS:trafficserver-9.2.11-3.oe2403.x86_64', 'openEuler-24.03-LTS:trafficserver-debuginfo-9.2.11-3.oe2403.x86_64', 'openEuler-24.03-LTS:trafficserver-debugsource-9.2.11-3.oe2403.x86_64', 'openEuler-24.03-LTS:trafficserver-devel-9.2.11-3.oe2403.x86_64', 'openEuler-24.03-LTS:trafficserver-perl-9.2.11-3.oe2403.x86_64']}}, {'cve': 'CVE-2025-65114', 'notes': [{'text': 'Apache Traffic Server allows request smuggling if chunked messages are malformed.\xa0\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.\n\nUsers are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-65114', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2385', 'details': 'trafficserver security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
13f42e766403729d1fbbd3e5e860d5f547053c31a707f1f25e71befa300be15c
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2386
An update for ImageMagick is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:21:59+03:00
2026-05-22 16:21:59+03:00
['CVE-2026-42326', 'CVE-2026-45031', 'CVE-2026-45358', 'CVE-2026-45359', 'CVE-2026-45624', 'CVE-2026-45664', 'CVE-2026-46520', 'CVE-2026-46521', 'CVE-2026-46522', 'CVE-2026-46523', 'CVE-2026-46557', 'CVE-2026-46559', 'CVE-2026-46692', 'CVE-2026-46693', 'CVE-2026-47165', 'CVE-2026-47166']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.src.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch.rpm', 'product_id': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'summary': 'openEuler-SA-2026-2386', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45359&packageName=ImageMagick', 'summary': 'CVE-2026-45359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2386.json', 'summary': 'openEuler-SA-2026-2386 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'ImageMagick security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.\n\nSecurity Fix(es):\n\n(CVE-2026-42326)\n\n(CVE-2026-45031)\n\n(CVE-2026-45358)\n\n(CVE-2026-45359)\n\n(CVE-2026-45624)\n\n(CVE-2026-45664)\n\n(CVE-2026-46520)\n\n(CVE-2026-46521)\n\n(CVE-2026-46522)\n\n(CVE-2026-46523)\n\n(CVE-2026-46557)\n\n(CVE-2026-46559)\n\n(CVE-2026-46692)\n\n(CVE-2026-46693)\n\nImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.(CVE-2026-47165)\n\nAn attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.(CVE-2026-47166)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'ImageMagick', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for ImageMagick is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2386', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:21:59+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:21:59+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:21:59+08:00', 'initial_release_date': '2026-05-22T21:21:59+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'summary': 'openEuler-SA-2026-2386', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45359&packageName=ImageMagick', 'summary': 'CVE-2026-45359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2386.json', 'summary': 'openEuler-SA-2026-2386 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.src.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.src.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch.rpm', 'product': {'name': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch.rpm', 'product_id': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-7.1.2.23-1.oe2403sp3.src'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64'}, 'product_reference': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch'}, 'product_reference': 'ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64'}, 'product_reference': 'ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42326', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42326', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:ImageMagick-7.1.2.23-1.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:ImageMagick-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-c++-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-devel-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-perl-7.1.2.23-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:ImageMagick-help-7.1.2.23-1.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:ImageMagick-7.1.2.23-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:ImageMagick-c++-7.1.2.23-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:ImageMagick-c++-devel-7.1.2.23-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:ImageMagick-debuginfo-7.1.2.23-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:ImageMagick-debugsource-7.1.2.23-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:ImageMagick-devel-7.1.2.23-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:ImageMagick-perl-7.1.2.23-1.oe2403sp3.aarch64']}}, {'cve': 'CVE-2026-45031', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45031', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45358', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45358', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45359', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45359', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45624', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45624', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45664', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45664', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46520', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46520', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46521', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46521', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46522', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46522', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46523', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46557', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46557', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46559', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46559', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46692', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46692', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46693', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46693', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47165', 'notes': [{'text': 'ImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47165', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47166', 'notes': [{'text': 'An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47166', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2386', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
b0f39fd698a31012bdfb1d656f0c9f81baf63520c7b55e64c862667dbfb2910c
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2387
An update for ImageMagick is now available for openEuler-20.03-LTS-SP4
High
2026-05-22 16:22:00+03:00
2026-05-22 16:22:00+03:00
['CVE-2026-42326', 'CVE-2026-45031', 'CVE-2026-45358', 'CVE-2026-45624', 'CVE-2026-45664', 'CVE-2026-46520', 'CVE-2026-46521', 'CVE-2026-46522', 'CVE-2026-46523', 'CVE-2026-46557', 'CVE-2026-46559', 'CVE-2026-46692', 'CVE-2026-46693', 'CVE-2026-47165', 'CVE-2026-47166']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.src.rpm', 'product_id': 'ImageMagick-6.9.13.48-1.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch.rpm', 'product_id': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'summary': 'openEuler-SA-2026-2387', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2387.json', 'summary': 'openEuler-SA-2026-2387 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'ImageMagick security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.\n\nSecurity Fix(es):\n\n(CVE-2026-42326)\n\n(CVE-2026-45031)\n\n(CVE-2026-45358)\n\n(CVE-2026-45624)\n\n(CVE-2026-45664)\n\n(CVE-2026-46520)\n\n(CVE-2026-46521)\n\n(CVE-2026-46522)\n\n(CVE-2026-46523)\n\n(CVE-2026-46557)\n\n(CVE-2026-46559)\n\n(CVE-2026-46692)\n\n(CVE-2026-46693)\n\nImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.(CVE-2026-47165)\n\nAn attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.(CVE-2026-47166)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'ImageMagick', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for ImageMagick is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2387', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:00+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:00+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:00+08:00', 'initial_release_date': '2026-05-22T21:22:00+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'summary': 'openEuler-SA-2026-2387', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2387.json', 'summary': 'openEuler-SA-2026-2387 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_id': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.src.rpm', 'product': {'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.src.rpm', 'product_id': 'ImageMagick-6.9.13.48-1.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_id': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch.rpm', 'product': {'name': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch.rpm', 'product_id': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64'}, 'product_reference': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-6.9.13.48-1.oe2003sp4.src'}, 'product_reference': 'ImageMagick-6.9.13.48-1.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64'}, 'product_reference': 'ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch'}, 'product_reference': 'ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42326', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42326', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:ImageMagick-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-c++-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-devel-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-perl-6.9.13.48-1.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:ImageMagick-6.9.13.48-1.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:ImageMagick-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-c++-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-c++-devel-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-debuginfo-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-debugsource-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-devel-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-perl-6.9.13.48-1.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:ImageMagick-help-6.9.13.48-1.oe2003sp4.noarch']}}, {'cve': 'CVE-2026-45031', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45031', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45358', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45358', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45624', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45624', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45664', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45664', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46520', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46520', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46521', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46521', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46522', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46522', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46523', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46557', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46557', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46559', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46559', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46692', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46692', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46693', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46693', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47165', 'notes': [{'text': 'ImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47165', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47166', 'notes': [{'text': 'An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47166', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2387', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
3fc383450e8cbc9ccecfb2b00fd4a88ef9e48313e6b6053f07600dca960808f5
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2388
An update for ImageMagick is now available for openEuler-22.03-LTS-SP4
High
2026-05-22 16:22:00+03:00
2026-05-22 16:22:00+03:00
['CVE-2026-42326', 'CVE-2026-45031', 'CVE-2026-45358', 'CVE-2026-45359', 'CVE-2026-45624', 'CVE-2026-45664', 'CVE-2026-46520', 'CVE-2026-46521', 'CVE-2026-46522', 'CVE-2026-46523', 'CVE-2026-46557', 'CVE-2026-46559', 'CVE-2026-46692', 'CVE-2026-46693', 'CVE-2026-47165', 'CVE-2026-47166']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.src.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch.rpm', 'product_id': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'summary': 'openEuler-SA-2026-2388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45359&packageName=ImageMagick', 'summary': 'CVE-2026-45359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2388.json', 'summary': 'openEuler-SA-2026-2388 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'ImageMagick security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.\n\nSecurity Fix(es):\n\n(CVE-2026-42326)\n\n(CVE-2026-45031)\n\n(CVE-2026-45358)\n\n(CVE-2026-45359)\n\n(CVE-2026-45624)\n\n(CVE-2026-45664)\n\n(CVE-2026-46520)\n\n(CVE-2026-46521)\n\n(CVE-2026-46522)\n\n(CVE-2026-46523)\n\n(CVE-2026-46557)\n\n(CVE-2026-46559)\n\n(CVE-2026-46692)\n\n(CVE-2026-46693)\n\nImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.(CVE-2026-47165)\n\nAn attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.(CVE-2026-47166)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'ImageMagick', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for ImageMagick is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2388', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:00+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:00+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:00+08:00', 'initial_release_date': '2026-05-22T21:22:00+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'summary': 'openEuler-SA-2026-2388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45359&packageName=ImageMagick', 'summary': 'CVE-2026-45359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2388.json', 'summary': 'openEuler-SA-2026-2388 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.src.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.src.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch.rpm', 'product': {'name': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch.rpm', 'product_id': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-7.1.2.23-1.oe2203sp4.src'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64'}, 'product_reference': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch'}, 'product_reference': 'ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64'}, 'product_reference': 'ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42326', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42326', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:ImageMagick-7.1.2.23-1.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:ImageMagick-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-c++-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-devel-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-perl-7.1.2.23-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:ImageMagick-help-7.1.2.23-1.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:ImageMagick-7.1.2.23-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:ImageMagick-c++-7.1.2.23-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:ImageMagick-c++-devel-7.1.2.23-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:ImageMagick-debuginfo-7.1.2.23-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:ImageMagick-debugsource-7.1.2.23-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:ImageMagick-devel-7.1.2.23-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:ImageMagick-perl-7.1.2.23-1.oe2203sp4.aarch64']}}, {'cve': 'CVE-2026-45031', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45031', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45358', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45358', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45359', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45359', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45624', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45624', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45664', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45664', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46520', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46520', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46521', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46521', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46522', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46522', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46523', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46557', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46557', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46559', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46559', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46692', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46692', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46693', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46693', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47165', 'notes': [{'text': 'ImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47165', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47166', 'notes': [{'text': 'An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47166', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2388', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
e3b7f9cf92143db2fae7cf1d891c181c36fd1eba3a50d972def5972871c62e35
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2389
An update for ImageMagick is now available for openEuler-24.03-LTS
High
2026-05-22 16:22:00+03:00
2026-05-22 16:22:00+03:00
['CVE-2026-42326', 'CVE-2026-45031', 'CVE-2026-45358', 'CVE-2026-45359', 'CVE-2026-45624', 'CVE-2026-45664', 'CVE-2026-46520', 'CVE-2026-46521', 'CVE-2026-46522', 'CVE-2026-46523', 'CVE-2026-46557', 'CVE-2026-46559', 'CVE-2026-46692', 'CVE-2026-46693', 'CVE-2026-47165', 'CVE-2026-47166']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-7.1.2.23-1.oe2403.src.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch.rpm', 'product_id': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'summary': 'openEuler-SA-2026-2389', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45359&packageName=ImageMagick', 'summary': 'CVE-2026-45359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2389.json', 'summary': 'openEuler-SA-2026-2389 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'ImageMagick security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.\n\nSecurity Fix(es):\n\n(CVE-2026-42326)\n\n(CVE-2026-45031)\n\n(CVE-2026-45358)\n\n(CVE-2026-45359)\n\n(CVE-2026-45624)\n\n(CVE-2026-45664)\n\n(CVE-2026-46520)\n\n(CVE-2026-46521)\n\n(CVE-2026-46522)\n\n(CVE-2026-46523)\n\n(CVE-2026-46557)\n\n(CVE-2026-46559)\n\n(CVE-2026-46692)\n\n(CVE-2026-46693)\n\nImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.(CVE-2026-47165)\n\nAn attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.(CVE-2026-47166)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for ImageMagick is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'ImageMagick', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for ImageMagick is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2389', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:00+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:00+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:00+08:00', 'initial_release_date': '2026-05-22T21:22:00+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'summary': 'openEuler-SA-2026-2389', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42326&packageName=ImageMagick', 'summary': 'CVE-2026-42326', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45031&packageName=ImageMagick', 'summary': 'CVE-2026-45031', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45358&packageName=ImageMagick', 'summary': 'CVE-2026-45358', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45359&packageName=ImageMagick', 'summary': 'CVE-2026-45359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45624&packageName=ImageMagick', 'summary': 'CVE-2026-45624', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-45664&packageName=ImageMagick', 'summary': 'CVE-2026-45664', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46520&packageName=ImageMagick', 'summary': 'CVE-2026-46520', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46521&packageName=ImageMagick', 'summary': 'CVE-2026-46521', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46522&packageName=ImageMagick', 'summary': 'CVE-2026-46522', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46523&packageName=ImageMagick', 'summary': 'CVE-2026-46523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46557&packageName=ImageMagick', 'summary': 'CVE-2026-46557', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46559&packageName=ImageMagick', 'summary': 'CVE-2026-46559', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46692&packageName=ImageMagick', 'summary': 'CVE-2026-46692', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46693&packageName=ImageMagick', 'summary': 'CVE-2026-46693', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47165&packageName=ImageMagick', 'summary': 'CVE-2026-47165', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-47166&packageName=ImageMagick', 'summary': 'CVE-2026-47166', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42326', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45031', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45358', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45624', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-45664', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46520', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46521', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46522', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46557', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46559', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46692', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46693', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47165', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-47166', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2389.json', 'summary': 'openEuler-SA-2026-2389 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64.rpm', 'product': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2403.src.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2403.src.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'ImageMagick-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64.rpm', 'product': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64.rpm', 'product_id': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch.rpm', 'product': {'name': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch.rpm', 'product_id': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-c++-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-c++-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-devel-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-devel-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-perl-7.1.2.23-1.oe2403.aarch64'}, 'product_reference': 'ImageMagick-perl-7.1.2.23-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-7.1.2.23-1.oe2403.src'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-c++-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-c++-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-devel-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-devel-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-perl-7.1.2.23-1.oe2403.x86_64'}, 'product_reference': 'ImageMagick-perl-7.1.2.23-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:ImageMagick-help-7.1.2.23-1.oe2403.noarch'}, 'product_reference': 'ImageMagick-help-7.1.2.23-1.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42326', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42326', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:ImageMagick-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-c++-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-c++-devel-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-debuginfo-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-debugsource-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-devel-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-perl-7.1.2.23-1.oe2403.aarch64', 'openEuler-24.03-LTS:ImageMagick-7.1.2.23-1.oe2403.src', 'openEuler-24.03-LTS:ImageMagick-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-c++-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-c++-devel-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-debuginfo-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-debugsource-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-devel-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-perl-7.1.2.23-1.oe2403.x86_64', 'openEuler-24.03-LTS:ImageMagick-help-7.1.2.23-1.oe2403.noarch']}}, {'cve': 'CVE-2026-45031', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45031', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45358', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45358', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45359', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45359', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45624', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45624', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-45664', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-45664', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46520', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46520', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46521', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46521', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46522', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46522', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46523', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46557', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46557', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46559', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46559', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46692', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46692', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46693', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46693', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47165', 'notes': [{'text': 'ImageMagick versions prior to 7.1.2-23 and 6.9.13-48 do not implement a challenge-response authentication model for the distributed pixel cache server. Originally designed to operate without authentication, a local attacker with high privileges may exploit this flaw to access sensitive pixel data in the distributed pixel cache, resulting in information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47165', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-47166', 'notes': [{'text': 'An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This vulnerability affects ImageMagick versions prior to 7.1.2-23 and 6.9.13-48, and could lead to information disclosure or denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-47166', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2389', 'details': 'ImageMagick security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
6a0b70223d65fba88e450e024c755f408541e75fdd3ccd7463540c25d8cb789f
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2257
An update for krb5 is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS
Medium
2026-05-09 15:35:14+03:00
2026-05-09 15:35:14+03:00
['CVE-2026-40355', 'CVE-2026-40356']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-client-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-server-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-client-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-server-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-client-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-client-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-server-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-server-1.18.2-23.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-client-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-client-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-server-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-server-1.19.2-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-client-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-debugsource-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-devel-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-libs-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-server-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-1.21.2-20.oe2403sp1.src.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-1.21.2-20.oe2403sp3.src.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-1.18.2-23.oe2003sp4.src.rpm', 'product_id': 'krb5-1.18.2-23.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-1.19.2-30.oe2203sp4.src.rpm', 'product_id': 'krb5-1.19.2-30.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-1.21.2-20.oe2403.src.rpm', 'product_id': 'krb5-1.21.2-20.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-client-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-server-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-client-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-server-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-client-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-client-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-server-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-server-1.18.2-23.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-client-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-client-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-server-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-server-1.19.2-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-client-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-debugsource-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-devel-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-libs-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-server-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'krb5-help-1.21.2-20.oe2403sp1.noarch.rpm', 'product_id': 'krb5-help-1.21.2-20.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'krb5-help-1.21.2-20.oe2403sp3.noarch.rpm', 'product_id': 'krb5-help-1.21.2-20.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'krb5-help-1.18.2-23.oe2003sp4.noarch.rpm', 'product_id': 'krb5-help-1.18.2-23.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'krb5-help-1.19.2-30.oe2203sp4.noarch.rpm', 'product_id': 'krb5-help-1.19.2-30.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'krb5-help-1.21.2-20.oe2403.noarch.rpm', 'product_id': 'krb5-help-1.21.2-20.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2257', 'summary': 'openEuler-SA-2026-2257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40355&packageName=krb5', 'summary': 'CVE-2026-40355', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40356&packageName=krb5', 'summary': 'CVE-2026-40356', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40355', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40356', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2257.json', 'summary': 'openEuler-SA-2026-2257 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'krb5 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for krb5 is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography.\n\nSecurity Fix(es):\n\nIn MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.(CVE-2026-40355)\n\nIn MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.(CVE-2026-40356)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for krb5 is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'krb5', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for krb5 is now available for openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2257', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-09T20:35:14+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-09T20:35:14+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-09T20:35:14+08:00', 'initial_release_date': '2026-05-09T20:35:14+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2257', 'summary': 'openEuler-SA-2026-2257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40355&packageName=krb5', 'summary': 'CVE-2026-40355', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40356&packageName=krb5', 'summary': 'CVE-2026-40356', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40355', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40356', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2257.json', 'summary': 'openEuler-SA-2026-2257 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'krb5-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-client-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.21.2-20.oe2403sp1.aarch64.rpm', 'product': {'name': 'krb5-server-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-client-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.21.2-20.oe2403sp3.aarch64.rpm', 'product': {'name': 'krb5-server-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-client-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-client-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.18.2-23.oe2003sp4.aarch64.rpm', 'product': {'name': 'krb5-server-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_id': 'krb5-server-1.18.2-23.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-client-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-client-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.19.2-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'krb5-server-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_id': 'krb5-server-1.19.2-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-client-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-debugsource-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-devel-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-libs-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.21.2-20.oe2403.aarch64.rpm', 'product': {'name': 'krb5-server-1.21.2-20.oe2403.aarch64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'krb5-1.21.2-20.oe2403sp1.src.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403sp1.src.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-1.21.2-20.oe2403sp3.src.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403sp3.src.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-1.18.2-23.oe2003sp4.src.rpm', 'product': {'name': 'krb5-1.18.2-23.oe2003sp4.src.rpm', 'product_id': 'krb5-1.18.2-23.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-1.19.2-30.oe2203sp4.src.rpm', 'product': {'name': 'krb5-1.19.2-30.oe2203sp4.src.rpm', 'product_id': 'krb5-1.19.2-30.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-1.21.2-20.oe2403.src.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403.src.rpm', 'product_id': 'krb5-1.21.2-20.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'krb5-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-client-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.21.2-20.oe2403sp1.x86_64.rpm', 'product': {'name': 'krb5-server-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-client-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.21.2-20.oe2403sp3.x86_64.rpm', 'product': {'name': 'krb5-server-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-client-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-client-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.18.2-23.oe2003sp4.x86_64.rpm', 'product': {'name': 'krb5-server-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_id': 'krb5-server-1.18.2-23.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-client-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-client-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.19.2-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'krb5-server-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_id': 'krb5-server-1.19.2-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-client-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-client-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-client-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-debugsource-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-debugsource-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-debugsource-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-devel-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-devel-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-devel-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-libs-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-libs-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-libs-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'krb5-server-1.21.2-20.oe2403.x86_64.rpm', 'product': {'name': 'krb5-server-1.21.2-20.oe2403.x86_64.rpm', 'product_id': 'krb5-server-1.21.2-20.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'krb5-help-1.21.2-20.oe2403sp1.noarch.rpm', 'product': {'name': 'krb5-help-1.21.2-20.oe2403sp1.noarch.rpm', 'product_id': 'krb5-help-1.21.2-20.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'krb5-help-1.21.2-20.oe2403sp3.noarch.rpm', 'product': {'name': 'krb5-help-1.21.2-20.oe2403sp3.noarch.rpm', 'product_id': 'krb5-help-1.21.2-20.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'krb5-help-1.18.2-23.oe2003sp4.noarch.rpm', 'product': {'name': 'krb5-help-1.18.2-23.oe2003sp4.noarch.rpm', 'product_id': 'krb5-help-1.18.2-23.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-help-1.19.2-30.oe2203sp4.noarch.rpm', 'product': {'name': 'krb5-help-1.19.2-30.oe2203sp4.noarch.rpm', 'product_id': 'krb5-help-1.19.2-30.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'krb5-help-1.21.2-20.oe2403.noarch.rpm', 'product': {'name': 'krb5-help-1.21.2-20.oe2403.noarch.rpm', 'product_id': 'krb5-help-1.21.2-20.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-client-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-client-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-debugsource-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-debugsource-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-devel-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-devel-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-libs-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-libs-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.21.2-20.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-server-1.21.2-20.oe2403sp1.aarch64'}, 'product_reference': 'krb5-server-1.21.2-20.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-client-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-client-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-debugsource-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-debugsource-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-devel-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-devel-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-libs-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-libs-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.21.2-20.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-server-1.21.2-20.oe2403sp3.aarch64'}, 'product_reference': 'krb5-server-1.21.2-20.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-client-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-client-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-debugsource-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-debugsource-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-devel-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-devel-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-libs-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-libs-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.18.2-23.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-server-1.18.2-23.oe2003sp4.aarch64'}, 'product_reference': 'krb5-server-1.18.2-23.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-client-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-client-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-debugsource-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-debugsource-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-devel-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-devel-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-libs-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-libs-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.19.2-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-server-1.19.2-30.oe2203sp4.aarch64'}, 'product_reference': 'krb5-server-1.19.2-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-client-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-client-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-debuginfo-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-debuginfo-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-debugsource-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-debugsource-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-devel-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-devel-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-libs-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-libs-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.21.2-20.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-server-1.21.2-20.oe2403.aarch64'}, 'product_reference': 'krb5-server-1.21.2-20.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-1.21.2-20.oe2403sp1.src'}, 'product_reference': 'krb5-1.21.2-20.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-1.21.2-20.oe2403sp3.src'}, 'product_reference': 'krb5-1.21.2-20.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.18.2-23.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-1.18.2-23.oe2003sp4.src'}, 'product_reference': 'krb5-1.18.2-23.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.19.2-30.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-1.19.2-30.oe2203sp4.src'}, 'product_reference': 'krb5-1.19.2-30.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-1.21.2-20.oe2403.src'}, 'product_reference': 'krb5-1.21.2-20.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-client-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-client-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-debugsource-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-debugsource-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-devel-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-devel-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-libs-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-libs-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.21.2-20.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-server-1.21.2-20.oe2403sp1.x86_64'}, 'product_reference': 'krb5-server-1.21.2-20.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-client-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-client-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-debugsource-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-debugsource-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-devel-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-devel-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-libs-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-libs-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.21.2-20.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-server-1.21.2-20.oe2403sp3.x86_64'}, 'product_reference': 'krb5-server-1.21.2-20.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-client-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-client-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-debugsource-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-debugsource-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-devel-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-devel-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-libs-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-libs-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.18.2-23.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-server-1.18.2-23.oe2003sp4.x86_64'}, 'product_reference': 'krb5-server-1.18.2-23.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-client-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-client-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-debugsource-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-debugsource-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-devel-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-devel-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-libs-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-libs-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.19.2-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-server-1.19.2-30.oe2203sp4.x86_64'}, 'product_reference': 'krb5-server-1.19.2-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-client-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-client-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-client-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-debuginfo-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-debuginfo-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-debugsource-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-debugsource-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-debugsource-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-devel-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-devel-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-devel-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-libs-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-libs-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-libs-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-server-1.21.2-20.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-server-1.21.2-20.oe2403.x86_64'}, 'product_reference': 'krb5-server-1.21.2-20.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-help-1.21.2-20.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:krb5-help-1.21.2-20.oe2403sp1.noarch'}, 'product_reference': 'krb5-help-1.21.2-20.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-help-1.21.2-20.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:krb5-help-1.21.2-20.oe2403sp3.noarch'}, 'product_reference': 'krb5-help-1.21.2-20.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-help-1.18.2-23.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:krb5-help-1.18.2-23.oe2003sp4.noarch'}, 'product_reference': 'krb5-help-1.18.2-23.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-help-1.19.2-30.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:krb5-help-1.19.2-30.oe2203sp4.noarch'}, 'product_reference': 'krb5-help-1.19.2-30.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'krb5-help-1.21.2-20.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:krb5-help-1.21.2-20.oe2403.noarch'}, 'product_reference': 'krb5-help-1.21.2-20.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40355', 'notes': [{'text': 'In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40355', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2257', 'details': 'krb5 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:krb5-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:krb5-client-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:krb5-debuginfo-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:krb5-debugsource-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:krb5-devel-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:krb5-libs-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:krb5-server-1.21.2-20.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP3:krb5-1.21.2-20.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:krb5-client-1.21.2-20.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:krb5-debuginfo-1.21.2-20.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:krb5-debugsource-1.21.2-20.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:krb5-devel-1.21.2-20.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:krb5-libs-1.21.2-20.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:krb5-server-1.21.2-20.oe2403sp3.aarch64', 'openEuler-20.03-LTS-SP4:krb5-1.18.2-23.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:krb5-client-1.18.2-23.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:krb5-debuginfo-1.18.2-23.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:krb5-debugsource-1.18.2-23.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:krb5-devel-1.18.2-23.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:krb5-libs-1.18.2-23.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:krb5-server-1.18.2-23.oe2003sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-1.19.2-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-client-1.19.2-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-debuginfo-1.19.2-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-debugsource-1.19.2-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-devel-1.19.2-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-libs-1.19.2-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:krb5-server-1.19.2-30.oe2203sp4.aarch64', 'openEuler-24.03-LTS:krb5-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS:krb5-client-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS:krb5-debuginfo-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS:krb5-debugsource-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS:krb5-devel-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS:krb5-libs-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS:krb5-server-1.21.2-20.oe2403.aarch64', 'openEuler-24.03-LTS-SP1:krb5-1.21.2-20.oe2403sp1.src', 'openEuler-24.03-LTS-SP3:krb5-1.21.2-20.oe2403sp3.src', 'openEuler-20.03-LTS-SP4:krb5-1.18.2-23.oe2003sp4.src', 'openEuler-22.03-LTS-SP4:krb5-1.19.2-30.oe2203sp4.src', 'openEuler-24.03-LTS:krb5-1.21.2-20.oe2403.src', 'openEuler-24.03-LTS-SP1:krb5-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:krb5-client-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:krb5-debuginfo-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:krb5-debugsource-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:krb5-devel-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:krb5-libs-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:krb5-server-1.21.2-20.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP3:krb5-1.21.2-20.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:krb5-client-1.21.2-20.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:krb5-debuginfo-1.21.2-20.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:krb5-debugsource-1.21.2-20.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:krb5-devel-1.21.2-20.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:krb5-libs-1.21.2-20.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:krb5-server-1.21.2-20.oe2403sp3.x86_64', 'openEuler-20.03-LTS-SP4:krb5-1.18.2-23.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:krb5-client-1.18.2-23.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:krb5-debuginfo-1.18.2-23.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:krb5-debugsource-1.18.2-23.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:krb5-devel-1.18.2-23.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:krb5-libs-1.18.2-23.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:krb5-server-1.18.2-23.oe2003sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-1.19.2-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-client-1.19.2-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-debuginfo-1.19.2-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-debugsource-1.19.2-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-devel-1.19.2-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-libs-1.19.2-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:krb5-server-1.19.2-30.oe2203sp4.x86_64', 'openEuler-24.03-LTS:krb5-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS:krb5-client-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS:krb5-debuginfo-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS:krb5-debugsource-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS:krb5-devel-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS:krb5-libs-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS:krb5-server-1.21.2-20.oe2403.x86_64', 'openEuler-24.03-LTS-SP1:krb5-help-1.21.2-20.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP3:krb5-help-1.21.2-20.oe2403sp3.noarch', 'openEuler-20.03-LTS-SP4:krb5-help-1.18.2-23.oe2003sp4.noarch', 'openEuler-22.03-LTS-SP4:krb5-help-1.19.2-30.oe2203sp4.noarch', 'openEuler-24.03-LTS:krb5-help-1.21.2-20.oe2403.noarch']}}, {'cve': 'CVE-2026-40356', 'notes': [{'text': 'In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40356', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2257', 'details': 'krb5 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
8ca9918ca66bdd7e51dcb6d36e0cf4eef179cf2fa8bee3707c09b4a04c351a92
2026-06-01 21:24:54.157429+03:00
2026-06-23 02:36:22.792272+03:00
openEuler-SA-2026-2390
An update for python-urllib3 is now available for openEuler-20.03-LTS-SP4
Medium
2026-05-22 16:22:00+03:00
2026-05-22 16:22:00+03:00
['CVE-2026-44431']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python-urllib3-1.25.9-17.oe2003sp4.src.rpm', 'product_id': 'python-urllib3-1.25.9-17.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product_id': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product_id': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2390', 'summary': 'openEuler-SA-2026-2390', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44431&packageName=python-urllib3', 'summary': 'CVE-2026-44431', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44431', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2390.json', 'summary': 'openEuler-SA-2026-2390 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-urllib3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-urllib3 is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'HTTP library with thread-safe connection pooling, file post support, sanity friendly, and more.\n\nSecurity Fix(es):\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.(CVE-2026-44431)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-urllib3 is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'python-urllib3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-urllib3 is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2390', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:00+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:00+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:00+08:00', 'initial_release_date': '2026-05-22T21:22:00+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2390', 'summary': 'openEuler-SA-2026-2390', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44431&packageName=python-urllib3', 'summary': 'CVE-2026-44431', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44431', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2390.json', 'summary': 'openEuler-SA-2026-2390 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-urllib3-1.25.9-17.oe2003sp4.src.rpm', 'product': {'name': 'python-urllib3-1.25.9-17.oe2003sp4.src.rpm', 'product_id': 'python-urllib3-1.25.9-17.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product': {'name': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product_id': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product': {'name': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product_id': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-urllib3-1.25.9-17.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python-urllib3-1.25.9-17.oe2003sp4.src'}, 'product_reference': 'python-urllib3-1.25.9-17.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python2-urllib3-1.25.9-17.oe2003sp4.noarch'}, 'product_reference': 'python2-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-urllib3-1.25.9-17.oe2003sp4.noarch'}, 'product_reference': 'python3-urllib3-1.25.9-17.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-44431', 'notes': [{'text': 'urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-44431', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2390', 'details': 'python-urllib3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:python-urllib3-1.25.9-17.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:python2-urllib3-1.25.9-17.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:python3-urllib3-1.25.9-17.oe2003sp4.noarch']}}]}
ec7f805a00637cbba4b7598127d9d98c2407ffda6ae44343d32e31ec730c7c5d
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2391
An update for python-urllib3 is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-22 16:22:00+03:00
2026-05-22 16:22:00+03:00
['CVE-2026-44431']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python-urllib3-1.26.12-13.oe2203sp4.src.rpm', 'product_id': 'python-urllib3-1.26.12-13.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch.rpm', 'product_id': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2391', 'summary': 'openEuler-SA-2026-2391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44431&packageName=python-urllib3', 'summary': 'CVE-2026-44431', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44431', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2391.json', 'summary': 'openEuler-SA-2026-2391 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-urllib3 security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-urllib3 is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'HTTP library with thread-safe connection pooling, file post support, sanity friendly, and more.\n\nSecurity Fix(es):\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.(CVE-2026-44431)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-urllib3 is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'python-urllib3', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-urllib3 is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2391', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:00+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:00+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:00+08:00', 'initial_release_date': '2026-05-22T21:22:00+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2391', 'summary': 'openEuler-SA-2026-2391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44431&packageName=python-urllib3', 'summary': 'CVE-2026-44431', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44431', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2391.json', 'summary': 'openEuler-SA-2026-2391 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-urllib3-1.26.12-13.oe2203sp4.src.rpm', 'product': {'name': 'python-urllib3-1.26.12-13.oe2203sp4.src.rpm', 'product_id': 'python-urllib3-1.26.12-13.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch.rpm', 'product': {'name': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch.rpm', 'product_id': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-urllib3-1.26.12-13.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python-urllib3-1.26.12-13.oe2203sp4.src'}, 'product_reference': 'python-urllib3-1.26.12-13.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-urllib3-1.26.12-13.oe2203sp4.noarch'}, 'product_reference': 'python3-urllib3-1.26.12-13.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-44431', 'notes': [{'text': 'urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-44431', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2391', 'details': 'python-urllib3 security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:python-urllib3-1.26.12-13.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:python3-urllib3-1.26.12-13.oe2203sp4.noarch']}}]}
f8a3d109d5ca438a9134490718187cbb9b6b98e80f51d2cbbf5e975c3dc4230e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2392
An update for firefox is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-22 16:22:01+03:00
2026-05-22 16:22:01+03:00
['CVE-2026-8388', 'CVE-2026-8391', 'CVE-2026-8401', 'CVE-2026-8946', 'CVE-2026-8947', 'CVE-2026-8949', 'CVE-2026-8950', 'CVE-2026-8953', 'CVE-2026-8954', 'CVE-2026-8955', 'CVE-2026-8956', 'CVE-2026-8957', 'CVE-2026-8958', 'CVE-2026-8959', 'CVE-2026-8961', 'CVE-2026-8962', 'CVE-2026-8968', 'CVE-2026-8970', 'CVE-2026-8974', 'CVE-2026-8975']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-140.11.0-1.oe2403sp3.src.rpm', 'product_id': 'firefox-140.11.0-1.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'summary': 'openEuler-SA-2026-2392', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8388&packageName=firefox', 'summary': 'CVE-2026-8388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8391&packageName=firefox', 'summary': 'CVE-2026-8391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8401&packageName=firefox', 'summary': 'CVE-2026-8401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8946&packageName=firefox', 'summary': 'CVE-2026-8946', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8947&packageName=firefox', 'summary': 'CVE-2026-8947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8949&packageName=firefox', 'summary': 'CVE-2026-8949', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8950&packageName=firefox', 'summary': 'CVE-2026-8950', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8953&packageName=firefox', 'summary': 'CVE-2026-8953', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8954&packageName=firefox', 'summary': 'CVE-2026-8954', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8955&packageName=firefox', 'summary': 'CVE-2026-8955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8956&packageName=firefox', 'summary': 'CVE-2026-8956', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8957&packageName=firefox', 'summary': 'CVE-2026-8957', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8958&packageName=firefox', 'summary': 'CVE-2026-8958', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8959&packageName=firefox', 'summary': 'CVE-2026-8959', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8961&packageName=firefox', 'summary': 'CVE-2026-8961', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8962&packageName=firefox', 'summary': 'CVE-2026-8962', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8968&packageName=firefox', 'summary': 'CVE-2026-8968', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8970&packageName=firefox', 'summary': 'CVE-2026-8970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8974&packageName=firefox', 'summary': 'CVE-2026-8974', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8975&packageName=firefox', 'summary': 'CVE-2026-8975', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8391', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8401', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8946', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8949', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8950', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8953', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8954', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8956', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8957', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8958', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8959', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8961', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8962', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8968', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8974', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8975', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2392.json', 'summary': 'openEuler-SA-2026-2392 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nA critical vulnerability has been discovered in Mozilla Firefox browser versions up to 150.0.2, classified as CWE-119 buffer error. The vulnerability allows the product to read from or write to memory locations outside the intended boundary of the buffer when performing operations on a memory buffer. This vulnerability affects confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.(CVE-2026-8388)\n\nA vulnerability was found in Mozilla Firefox up to 150.0.2 (Web Browser). It has been declared as critical. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.(CVE-2026-8391)\n\nA sandbox escape vulnerability exists in the Profile Backup component of Mozilla Firefox. This vulnerability affects Firefox versions up to 150.0.2 and was fixed in version 150.0.3. An attacker could potentially exploit this vulnerability to bypass sandbox protections, impacting the confidentiality, integrity, and availability of the system.(CVE-2026-8401)\n\nIncorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8946)\n\nUse-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8947)\n\nInteger overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8949)\n\nSame-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8950)\n\nSandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8953)\n\nIncorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8954)\n\nPrivilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8955)\n\nInteger overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8956)\n\nPrivilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8957)\n\nInformation disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8958)\n\nSandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8959)\n\nSpoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.(CVE-2026-8961)\n\nMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.(CVE-2026-8962)\n\nDenial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8968)\n\nPrivilege escalation in the Security component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8970)\n\nMemory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8974)\n\nMemory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8975)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2392', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:01+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:01+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:01+08:00', 'initial_release_date': '2026-05-22T21:22:01+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'summary': 'openEuler-SA-2026-2392', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8388&packageName=firefox', 'summary': 'CVE-2026-8388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8391&packageName=firefox', 'summary': 'CVE-2026-8391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8401&packageName=firefox', 'summary': 'CVE-2026-8401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8946&packageName=firefox', 'summary': 'CVE-2026-8946', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8947&packageName=firefox', 'summary': 'CVE-2026-8947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8949&packageName=firefox', 'summary': 'CVE-2026-8949', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8950&packageName=firefox', 'summary': 'CVE-2026-8950', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8953&packageName=firefox', 'summary': 'CVE-2026-8953', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8954&packageName=firefox', 'summary': 'CVE-2026-8954', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8955&packageName=firefox', 'summary': 'CVE-2026-8955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8956&packageName=firefox', 'summary': 'CVE-2026-8956', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8957&packageName=firefox', 'summary': 'CVE-2026-8957', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8958&packageName=firefox', 'summary': 'CVE-2026-8958', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8959&packageName=firefox', 'summary': 'CVE-2026-8959', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8961&packageName=firefox', 'summary': 'CVE-2026-8961', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8962&packageName=firefox', 'summary': 'CVE-2026-8962', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8968&packageName=firefox', 'summary': 'CVE-2026-8968', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8970&packageName=firefox', 'summary': 'CVE-2026-8970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8974&packageName=firefox', 'summary': 'CVE-2026-8974', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8975&packageName=firefox', 'summary': 'CVE-2026-8975', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8391', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8401', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8946', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8949', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8950', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8953', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8954', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8956', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8957', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8958', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8959', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8961', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8962', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8968', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8974', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8975', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2392.json', 'summary': 'openEuler-SA-2026-2392 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.11.0-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.11.0-1.oe2403sp3.src.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2403sp3.src.rpm', 'product_id': 'firefox-140.11.0-1.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.11.0-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-140.11.0-1.oe2403sp3.aarch64'}, 'product_reference': 'firefox-140.11.0-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64'}, 'product_reference': 'firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.11.0-1.oe2403sp3.aarch64'}, 'product_reference': 'firefox-debugsource-140.11.0-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-140.11.0-1.oe2403sp3.src'}, 'product_reference': 'firefox-140.11.0-1.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-140.11.0-1.oe2403sp3.x86_64'}, 'product_reference': 'firefox-140.11.0-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64'}, 'product_reference': 'firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.11.0-1.oe2403sp3.x86_64'}, 'product_reference': 'firefox-debugsource-140.11.0-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8388', 'notes': [{'text': 'A critical vulnerability has been discovered in Mozilla Firefox browser versions up to 150.0.2, classified as CWE-119 buffer error. The vulnerability allows the product to read from or write to memory locations outside the intended boundary of the buffer when performing operations on a memory buffer. This vulnerability affects confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8388', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:firefox-140.11.0-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.11.0-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.11.0-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:firefox-140.11.0-1.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:firefox-140.11.0-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:firefox-debuginfo-140.11.0-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:firefox-debugsource-140.11.0-1.oe2403sp3.x86_64']}}, {'cve': 'CVE-2026-8391', 'notes': [{'text': 'A vulnerability was found in Mozilla Firefox up to 150.0.2 (Web Browser). It has been declared as critical. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8391', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8401', 'notes': [{'text': 'A sandbox escape vulnerability exists in the Profile Backup component of Mozilla Firefox. This vulnerability affects Firefox versions up to 150.0.2 and was fixed in version 150.0.3. An attacker could potentially exploit this vulnerability to bypass sandbox protections, impacting the confidentiality, integrity, and availability of the system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8401', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8946', 'notes': [{'text': 'Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8946', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8947', 'notes': [{'text': 'Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8947', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8949', 'notes': [{'text': 'Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8949', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8950', 'notes': [{'text': 'Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8950', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8953', 'notes': [{'text': 'Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8953', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.6, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8954', 'notes': [{'text': 'Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8954', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8955', 'notes': [{'text': 'Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8955', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8956', 'notes': [{'text': 'Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8956', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8957', 'notes': [{'text': 'Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8957', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8958', 'notes': [{'text': 'Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8958', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8959', 'notes': [{'text': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8959', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.6, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8961', 'notes': [{'text': 'Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8961', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8962', 'notes': [{'text': 'Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8962', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8968', 'notes': [{'text': 'Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8968', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8970', 'notes': [{'text': 'Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8970', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8974', 'notes': [{'text': 'Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8974', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8975', 'notes': [{'text': 'Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8975', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2392', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
92de7d2e3423a50efb6a79785de024d5f1730a891d28a883b66039cbde1500c8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2393
An update for firefox is now available for openEuler-22.03-LTS-SP4
Critical
2026-05-22 16:22:01+03:00
2026-05-22 16:22:01+03:00
['CVE-2026-8388', 'CVE-2026-8391', 'CVE-2026-8401', 'CVE-2026-8946', 'CVE-2026-8947', 'CVE-2026-8949', 'CVE-2026-8950', 'CVE-2026-8953', 'CVE-2026-8954', 'CVE-2026-8955', 'CVE-2026-8956', 'CVE-2026-8957', 'CVE-2026-8958', 'CVE-2026-8959', 'CVE-2026-8961', 'CVE-2026-8962', 'CVE-2026-8968', 'CVE-2026-8970', 'CVE-2026-8974', 'CVE-2026-8975']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-140.11.0-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-140.11.0-1.oe2203sp4.src.rpm', 'product_id': 'firefox-140.11.0-1.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-140.11.0-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'summary': 'openEuler-SA-2026-2393', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8388&packageName=firefox', 'summary': 'CVE-2026-8388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8391&packageName=firefox', 'summary': 'CVE-2026-8391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8401&packageName=firefox', 'summary': 'CVE-2026-8401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8946&packageName=firefox', 'summary': 'CVE-2026-8946', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8947&packageName=firefox', 'summary': 'CVE-2026-8947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8949&packageName=firefox', 'summary': 'CVE-2026-8949', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8950&packageName=firefox', 'summary': 'CVE-2026-8950', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8953&packageName=firefox', 'summary': 'CVE-2026-8953', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8954&packageName=firefox', 'summary': 'CVE-2026-8954', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8955&packageName=firefox', 'summary': 'CVE-2026-8955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8956&packageName=firefox', 'summary': 'CVE-2026-8956', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8957&packageName=firefox', 'summary': 'CVE-2026-8957', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8958&packageName=firefox', 'summary': 'CVE-2026-8958', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8959&packageName=firefox', 'summary': 'CVE-2026-8959', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8961&packageName=firefox', 'summary': 'CVE-2026-8961', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8962&packageName=firefox', 'summary': 'CVE-2026-8962', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8968&packageName=firefox', 'summary': 'CVE-2026-8968', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8970&packageName=firefox', 'summary': 'CVE-2026-8970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8974&packageName=firefox', 'summary': 'CVE-2026-8974', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8975&packageName=firefox', 'summary': 'CVE-2026-8975', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8391', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8401', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8946', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8949', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8950', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8953', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8954', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8956', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8957', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8958', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8959', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8961', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8962', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8968', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8974', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8975', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2393.json', 'summary': 'openEuler-SA-2026-2393 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nA critical vulnerability has been discovered in Mozilla Firefox browser versions up to 150.0.2, classified as CWE-119 buffer error. The vulnerability allows the product to read from or write to memory locations outside the intended boundary of the buffer when performing operations on a memory buffer. This vulnerability affects confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.(CVE-2026-8388)\n\nA vulnerability was found in Mozilla Firefox up to 150.0.2 (Web Browser). It has been declared as critical. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.(CVE-2026-8391)\n\nA sandbox escape vulnerability exists in the Profile Backup component of Mozilla Firefox. This vulnerability affects Firefox versions up to 150.0.2 and was fixed in version 150.0.3. An attacker could potentially exploit this vulnerability to bypass sandbox protections, impacting the confidentiality, integrity, and availability of the system.(CVE-2026-8401)\n\nIncorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8946)\n\nUse-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8947)\n\nInteger overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8949)\n\nSame-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8950)\n\nSandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8953)\n\nIncorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8954)\n\nPrivilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8955)\n\nInteger overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8956)\n\nPrivilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8957)\n\nInformation disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8958)\n\nSandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8959)\n\nSpoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.(CVE-2026-8961)\n\nMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.(CVE-2026-8962)\n\nDenial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8968)\n\nPrivilege escalation in the Security component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8970)\n\nMemory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8974)\n\nMemory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8975)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2393', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:01+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:01+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:01+08:00', 'initial_release_date': '2026-05-22T21:22:01+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'summary': 'openEuler-SA-2026-2393', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8388&packageName=firefox', 'summary': 'CVE-2026-8388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8391&packageName=firefox', 'summary': 'CVE-2026-8391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8401&packageName=firefox', 'summary': 'CVE-2026-8401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8946&packageName=firefox', 'summary': 'CVE-2026-8946', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8947&packageName=firefox', 'summary': 'CVE-2026-8947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8949&packageName=firefox', 'summary': 'CVE-2026-8949', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8950&packageName=firefox', 'summary': 'CVE-2026-8950', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8953&packageName=firefox', 'summary': 'CVE-2026-8953', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8954&packageName=firefox', 'summary': 'CVE-2026-8954', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8955&packageName=firefox', 'summary': 'CVE-2026-8955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8956&packageName=firefox', 'summary': 'CVE-2026-8956', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8957&packageName=firefox', 'summary': 'CVE-2026-8957', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8958&packageName=firefox', 'summary': 'CVE-2026-8958', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8959&packageName=firefox', 'summary': 'CVE-2026-8959', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8961&packageName=firefox', 'summary': 'CVE-2026-8961', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8962&packageName=firefox', 'summary': 'CVE-2026-8962', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8968&packageName=firefox', 'summary': 'CVE-2026-8968', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8970&packageName=firefox', 'summary': 'CVE-2026-8970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8974&packageName=firefox', 'summary': 'CVE-2026-8974', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8975&packageName=firefox', 'summary': 'CVE-2026-8975', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8391', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8401', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8946', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8949', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8950', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8953', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8954', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8956', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8957', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8958', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8959', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8961', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8962', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8968', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8974', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8975', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2393.json', 'summary': 'openEuler-SA-2026-2393 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.11.0-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.11.0-1.oe2203sp4.src.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2203sp4.src.rpm', 'product_id': 'firefox-140.11.0-1.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.11.0-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-140.11.0-1.oe2203sp4.aarch64'}, 'product_reference': 'firefox-140.11.0-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64'}, 'product_reference': 'firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.11.0-1.oe2203sp4.aarch64'}, 'product_reference': 'firefox-debugsource-140.11.0-1.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-140.11.0-1.oe2203sp4.src'}, 'product_reference': 'firefox-140.11.0-1.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-140.11.0-1.oe2203sp4.x86_64'}, 'product_reference': 'firefox-140.11.0-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64'}, 'product_reference': 'firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.11.0-1.oe2203sp4.x86_64'}, 'product_reference': 'firefox-debugsource-140.11.0-1.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8388', 'notes': [{'text': 'A critical vulnerability has been discovered in Mozilla Firefox browser versions up to 150.0.2, classified as CWE-119 buffer error. The vulnerability allows the product to read from or write to memory locations outside the intended boundary of the buffer when performing operations on a memory buffer. This vulnerability affects confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8388', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:firefox-140.11.0-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.11.0-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.11.0-1.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:firefox-140.11.0-1.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:firefox-140.11.0-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:firefox-debuginfo-140.11.0-1.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:firefox-debugsource-140.11.0-1.oe2203sp4.x86_64']}}, {'cve': 'CVE-2026-8391', 'notes': [{'text': 'A vulnerability was found in Mozilla Firefox up to 150.0.2 (Web Browser). It has been declared as critical. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8391', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8401', 'notes': [{'text': 'A sandbox escape vulnerability exists in the Profile Backup component of Mozilla Firefox. This vulnerability affects Firefox versions up to 150.0.2 and was fixed in version 150.0.3. An attacker could potentially exploit this vulnerability to bypass sandbox protections, impacting the confidentiality, integrity, and availability of the system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8401', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8946', 'notes': [{'text': 'Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8946', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8947', 'notes': [{'text': 'Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8947', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8949', 'notes': [{'text': 'Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8949', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8950', 'notes': [{'text': 'Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8950', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8953', 'notes': [{'text': 'Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8953', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.6, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8954', 'notes': [{'text': 'Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8954', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8955', 'notes': [{'text': 'Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8955', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8956', 'notes': [{'text': 'Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8956', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8957', 'notes': [{'text': 'Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8957', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8958', 'notes': [{'text': 'Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8958', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8959', 'notes': [{'text': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8959', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.6, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8961', 'notes': [{'text': 'Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8961', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8962', 'notes': [{'text': 'Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8962', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8968', 'notes': [{'text': 'Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8968', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8970', 'notes': [{'text': 'Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8970', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8974', 'notes': [{'text': 'Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8974', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8975', 'notes': [{'text': 'Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8975', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2393', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
01514f678beda29eeb2eaf9b85da18f26a61746c303aeae482ac64c2c71e2ccf
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2394
An update for firefox is now available for openEuler-24.03-LTS
Critical
2026-05-22 16:22:01+03:00
2026-05-22 16:22:01+03:00
['CVE-2026-8388', 'CVE-2026-8391', 'CVE-2026-8401', 'CVE-2026-8946', 'CVE-2026-8947', 'CVE-2026-8949', 'CVE-2026-8950', 'CVE-2026-8953', 'CVE-2026-8954', 'CVE-2026-8955', 'CVE-2026-8956', 'CVE-2026-8957', 'CVE-2026-8958', 'CVE-2026-8959', 'CVE-2026-8961', 'CVE-2026-8962', 'CVE-2026-8968', 'CVE-2026-8970', 'CVE-2026-8974', 'CVE-2026-8975']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-140.11.0-1.oe2403.aarch64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debugsource-140.11.0-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-140.11.0-1.oe2403.src.rpm', 'product_id': 'firefox-140.11.0-1.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-140.11.0-1.oe2403.x86_64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'firefox-debugsource-140.11.0-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'summary': 'openEuler-SA-2026-2394', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8388&packageName=firefox', 'summary': 'CVE-2026-8388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8391&packageName=firefox', 'summary': 'CVE-2026-8391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8401&packageName=firefox', 'summary': 'CVE-2026-8401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8946&packageName=firefox', 'summary': 'CVE-2026-8946', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8947&packageName=firefox', 'summary': 'CVE-2026-8947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8949&packageName=firefox', 'summary': 'CVE-2026-8949', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8950&packageName=firefox', 'summary': 'CVE-2026-8950', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8953&packageName=firefox', 'summary': 'CVE-2026-8953', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8954&packageName=firefox', 'summary': 'CVE-2026-8954', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8955&packageName=firefox', 'summary': 'CVE-2026-8955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8956&packageName=firefox', 'summary': 'CVE-2026-8956', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8957&packageName=firefox', 'summary': 'CVE-2026-8957', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8958&packageName=firefox', 'summary': 'CVE-2026-8958', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8959&packageName=firefox', 'summary': 'CVE-2026-8959', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8961&packageName=firefox', 'summary': 'CVE-2026-8961', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8962&packageName=firefox', 'summary': 'CVE-2026-8962', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8968&packageName=firefox', 'summary': 'CVE-2026-8968', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8970&packageName=firefox', 'summary': 'CVE-2026-8970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8974&packageName=firefox', 'summary': 'CVE-2026-8974', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8975&packageName=firefox', 'summary': 'CVE-2026-8975', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8391', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8401', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8946', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8949', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8950', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8953', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8954', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8956', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8957', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8958', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8959', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8961', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8962', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8968', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8974', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8975', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2394.json', 'summary': 'openEuler-SA-2026-2394 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'firefox security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for firefox is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo\n\nSecurity Fix(es):\n\nA critical vulnerability has been discovered in Mozilla Firefox browser versions up to 150.0.2, classified as CWE-119 buffer error. The vulnerability allows the product to read from or write to memory locations outside the intended boundary of the buffer when performing operations on a memory buffer. This vulnerability affects confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.(CVE-2026-8388)\n\nA vulnerability was found in Mozilla Firefox up to 150.0.2 (Web Browser). It has been declared as critical. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.(CVE-2026-8391)\n\nA sandbox escape vulnerability exists in the Profile Backup component of Mozilla Firefox. This vulnerability affects Firefox versions up to 150.0.2 and was fixed in version 150.0.3. An attacker could potentially exploit this vulnerability to bypass sandbox protections, impacting the confidentiality, integrity, and availability of the system.(CVE-2026-8401)\n\nIncorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8946)\n\nUse-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8947)\n\nInteger overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8949)\n\nSame-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8950)\n\nSandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8953)\n\nIncorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8954)\n\nPrivilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8955)\n\nInteger overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8956)\n\nPrivilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8957)\n\nInformation disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8958)\n\nSandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8959)\n\nSpoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.(CVE-2026-8961)\n\nMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.(CVE-2026-8962)\n\nDenial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8968)\n\nPrivilege escalation in the Security component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8970)\n\nMemory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.(CVE-2026-8974)\n\nMemory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.(CVE-2026-8975)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'firefox', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for firefox is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2394', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:01+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:01+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:01+08:00', 'initial_release_date': '2026-05-22T21:22:01+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'summary': 'openEuler-SA-2026-2394', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8388&packageName=firefox', 'summary': 'CVE-2026-8388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8391&packageName=firefox', 'summary': 'CVE-2026-8391', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8401&packageName=firefox', 'summary': 'CVE-2026-8401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8946&packageName=firefox', 'summary': 'CVE-2026-8946', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8947&packageName=firefox', 'summary': 'CVE-2026-8947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8949&packageName=firefox', 'summary': 'CVE-2026-8949', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8950&packageName=firefox', 'summary': 'CVE-2026-8950', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8953&packageName=firefox', 'summary': 'CVE-2026-8953', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8954&packageName=firefox', 'summary': 'CVE-2026-8954', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8955&packageName=firefox', 'summary': 'CVE-2026-8955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8956&packageName=firefox', 'summary': 'CVE-2026-8956', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8957&packageName=firefox', 'summary': 'CVE-2026-8957', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8958&packageName=firefox', 'summary': 'CVE-2026-8958', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8959&packageName=firefox', 'summary': 'CVE-2026-8959', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8961&packageName=firefox', 'summary': 'CVE-2026-8961', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8962&packageName=firefox', 'summary': 'CVE-2026-8962', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8968&packageName=firefox', 'summary': 'CVE-2026-8968', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8970&packageName=firefox', 'summary': 'CVE-2026-8970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8974&packageName=firefox', 'summary': 'CVE-2026-8974', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8975&packageName=firefox', 'summary': 'CVE-2026-8975', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8391', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8401', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8946', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8949', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8950', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8953', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8954', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8956', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8957', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8958', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8959', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8961', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8962', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8968', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8974', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-8975', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2394.json', 'summary': 'openEuler-SA-2026-2394 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'firefox-140.11.0-1.oe2403.aarch64.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2403.aarch64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64.rpm', 'product': {'name': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.11.0-1.oe2403.aarch64.rpm', 'product': {'name': 'firefox-debugsource-140.11.0-1.oe2403.aarch64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'firefox-140.11.0-1.oe2403.src.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2403.src.rpm', 'product_id': 'firefox-140.11.0-1.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'firefox-140.11.0-1.oe2403.x86_64.rpm', 'product': {'name': 'firefox-140.11.0-1.oe2403.x86_64.rpm', 'product_id': 'firefox-140.11.0-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64.rpm', 'product': {'name': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'firefox-debugsource-140.11.0-1.oe2403.x86_64.rpm', 'product': {'name': 'firefox-debugsource-140.11.0-1.oe2403.x86_64.rpm', 'product_id': 'firefox-debugsource-140.11.0-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-140.11.0-1.oe2403.aarch64'}, 'product_reference': 'firefox-140.11.0-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debuginfo-140.11.0-1.oe2403.aarch64'}, 'product_reference': 'firefox-debuginfo-140.11.0-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.11.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debugsource-140.11.0-1.oe2403.aarch64'}, 'product_reference': 'firefox-debugsource-140.11.0-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-140.11.0-1.oe2403.src'}, 'product_reference': 'firefox-140.11.0-1.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-140.11.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-140.11.0-1.oe2403.x86_64'}, 'product_reference': 'firefox-140.11.0-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debuginfo-140.11.0-1.oe2403.x86_64'}, 'product_reference': 'firefox-debuginfo-140.11.0-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'firefox-debugsource-140.11.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:firefox-debugsource-140.11.0-1.oe2403.x86_64'}, 'product_reference': 'firefox-debugsource-140.11.0-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-8388', 'notes': [{'text': 'A critical vulnerability has been discovered in Mozilla Firefox browser versions up to 150.0.2, classified as CWE-119 buffer error. The vulnerability allows the product to read from or write to memory locations outside the intended boundary of the buffer when performing operations on a memory buffer. This vulnerability affects confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8388', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:firefox-140.11.0-1.oe2403.aarch64', 'openEuler-24.03-LTS:firefox-debuginfo-140.11.0-1.oe2403.aarch64', 'openEuler-24.03-LTS:firefox-debugsource-140.11.0-1.oe2403.aarch64', 'openEuler-24.03-LTS:firefox-140.11.0-1.oe2403.src', 'openEuler-24.03-LTS:firefox-140.11.0-1.oe2403.x86_64', 'openEuler-24.03-LTS:firefox-debuginfo-140.11.0-1.oe2403.x86_64', 'openEuler-24.03-LTS:firefox-debugsource-140.11.0-1.oe2403.x86_64']}}, {'cve': 'CVE-2026-8391', 'notes': [{'text': 'A vulnerability was found in Mozilla Firefox up to 150.0.2 (Web Browser). It has been declared as critical. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 150.0.3 eliminates this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8391', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8401', 'notes': [{'text': 'A sandbox escape vulnerability exists in the Profile Backup component of Mozilla Firefox. This vulnerability affects Firefox versions up to 150.0.2 and was fixed in version 150.0.3. An attacker could potentially exploit this vulnerability to bypass sandbox protections, impacting the confidentiality, integrity, and availability of the system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8401', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8946', 'notes': [{'text': 'Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8946', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8947', 'notes': [{'text': 'Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8947', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8949', 'notes': [{'text': 'Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8949', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8950', 'notes': [{'text': 'Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8950', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8953', 'notes': [{'text': 'Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8953', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.6, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8954', 'notes': [{'text': 'Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8954', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8955', 'notes': [{'text': 'Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8955', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8956', 'notes': [{'text': 'Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8956', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8957', 'notes': [{'text': 'Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8957', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8958', 'notes': [{'text': 'Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8958', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8959', 'notes': [{'text': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8959', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.6, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8961', 'notes': [{'text': 'Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8961', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8962', 'notes': [{'text': 'Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8962', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8968', 'notes': [{'text': 'Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8968', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8970', 'notes': [{'text': 'Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8970', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8974', 'notes': [{'text': 'Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8974', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-8975', 'notes': [{'text': 'Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-8975', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2394', 'details': 'firefox security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
acbaa8aa165e1c4d9df504a37ebc2106f00f5f866fa9ee0e82e21989b75c62b8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2395
An update for mariadb is now available for openEuler-24.03-LTS-SP1
Medium
2026-05-22 16:22:01+03:00
2026-05-22 16:22:01+03:00
['CVE-2026-3494']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-10.5.29-4.oe2403sp1.src.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2395', 'summary': 'openEuler-SA-2026-2395', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3494&packageName=mariadb', 'summary': 'CVE-2026-3494', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3494', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2395.json', 'summary': 'openEuler-SA-2026-2395 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'mariadb security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for mariadb is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.\n\nSecurity Fix(es):\n\nIn MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.(CVE-2026-3494)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for mariadb is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'mariadb', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for mariadb is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2395', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:01+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:01+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:01+08:00', 'initial_release_date': '2026-05-22T21:22:01+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2395', 'summary': 'openEuler-SA-2026-2395', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3494&packageName=mariadb', 'summary': 'CVE-2026-3494', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3494', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2395.json', 'summary': 'openEuler-SA-2026-2395 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64.rpm', 'product': {'name': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403sp1.src.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403sp1.src.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64.rpm', 'product': {'name': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-backup-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-backup-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-common-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-common-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-config-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-config-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-devel-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-embedded-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-embedded-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-pam-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-pam-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-server-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-server-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-test-10.5.29-4.oe2403sp1.aarch64'}, 'product_reference': 'mariadb-test-10.5.29-4.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-10.5.29-4.oe2403sp1.src'}, 'product_reference': 'mariadb-10.5.29-4.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-backup-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-backup-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-common-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-common-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-config-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-config-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-devel-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-embedded-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-embedded-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-pam-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-pam-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-server-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-server-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mariadb-test-10.5.29-4.oe2403sp1.x86_64'}, 'product_reference': 'mariadb-test-10.5.29-4.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3494', 'notes': [{'text': 'In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3494', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2395', 'details': 'mariadb security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:mariadb-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-backup-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-common-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-config-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-debuginfo-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-debugsource-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-devel-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-embedded-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-embedded-devel-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-errmsg-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-gssapi-server-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-pam-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-rocksdb-engine-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-server-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-server-galera-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-server-utils-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-test-10.5.29-4.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mariadb-10.5.29-4.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:mariadb-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-backup-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-common-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-config-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-debuginfo-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-debugsource-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-devel-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-embedded-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-embedded-devel-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-errmsg-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-gssapi-server-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-oqgraph-engine-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-pam-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-server-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-server-galera-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-server-utils-10.5.29-4.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mariadb-test-10.5.29-4.oe2403sp1.x86_64']}}]}
2c4d2894e166ab7ebecda439622c84f82bea7e936a16bd57ef5b25b816102c3d
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2396
An update for mariadb is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-22 16:22:02+03:00
2026-05-22 16:22:02+03:00
['CVE-2026-3494']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-10.5.29-4.oe2403sp3.src.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2396', 'summary': 'openEuler-SA-2026-2396', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3494&packageName=mariadb', 'summary': 'CVE-2026-3494', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3494', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2396.json', 'summary': 'openEuler-SA-2026-2396 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'mariadb security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for mariadb is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.\n\nSecurity Fix(es):\n\nIn MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.(CVE-2026-3494)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for mariadb is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'mariadb', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for mariadb is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2396', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:02+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:02+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:02+08:00', 'initial_release_date': '2026-05-22T21:22:02+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2396', 'summary': 'openEuler-SA-2026-2396', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3494&packageName=mariadb', 'summary': 'CVE-2026-3494', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3494', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2396.json', 'summary': 'openEuler-SA-2026-2396 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403sp3.src.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403sp3.src.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-backup-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-backup-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-common-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-common-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-config-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-config-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-devel-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-embedded-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-embedded-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-pam-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-pam-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-server-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-server-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-test-10.5.29-4.oe2403sp3.aarch64'}, 'product_reference': 'mariadb-test-10.5.29-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-10.5.29-4.oe2403sp3.src'}, 'product_reference': 'mariadb-10.5.29-4.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-backup-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-backup-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-common-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-common-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-config-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-config-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-devel-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-embedded-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-embedded-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-pam-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-pam-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-server-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-server-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mariadb-test-10.5.29-4.oe2403sp3.x86_64'}, 'product_reference': 'mariadb-test-10.5.29-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3494', 'notes': [{'text': 'In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3494', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2396', 'details': 'mariadb security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:mariadb-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-backup-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-common-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-config-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-debuginfo-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-debugsource-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-devel-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-embedded-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-embedded-devel-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-errmsg-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-gssapi-server-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-pam-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-rocksdb-engine-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-server-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-server-galera-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-server-utils-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-test-10.5.29-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mariadb-10.5.29-4.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:mariadb-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-backup-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-common-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-config-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-debuginfo-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-debugsource-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-devel-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-embedded-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-embedded-devel-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-errmsg-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-gssapi-server-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-oqgraph-engine-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-pam-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-server-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-server-galera-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-server-utils-10.5.29-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mariadb-test-10.5.29-4.oe2403sp3.x86_64']}}]}
d151bcf5544692bca56e7c82c90ce1c35949509bcb6f139466001046abc6f108
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2397
An update for mariadb is now available for openEuler-24.03-LTS
High
2026-05-22 16:22:02+03:00
2026-05-22 16:22:02+03:00
['CVE-2025-13699', 'CVE-2026-3494']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-backup-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-common-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-config-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-devel-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-embedded-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-pam-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-server-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-test-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-10.5.29-4.oe2403.src.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-backup-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-common-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-config-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-devel-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-embedded-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-pam-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-server-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mariadb-test-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2397', 'summary': 'openEuler-SA-2026-2397', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-13699&packageName=mariadb', 'summary': 'CVE-2025-13699', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3494&packageName=mariadb', 'summary': 'CVE-2026-3494', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-13699', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3494', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2397.json', 'summary': 'openEuler-SA-2026-2397 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'mariadb security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for mariadb is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded\nSQL database server. It is a client/server implementation consisting of\na server daemon (mariadbd) and many different client programs and libraries.\nThe base package contains the standard MariaDB/MySQL client programs and\nutilities.\n\nSecurity Fix(es):\n\nMariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may vary depending on the implementation.\n\nThe specific flaw exists within the handling of view names. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27000.(CVE-2025-13699)\n\nIn MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.(CVE-2026-3494)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for mariadb is now available for openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP3/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'mariadb', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for mariadb is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2397', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:02+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:02+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:02+08:00', 'initial_release_date': '2026-05-22T21:22:02+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2397', 'summary': 'openEuler-SA-2026-2397', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-13699&packageName=mariadb', 'summary': 'CVE-2025-13699', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3494&packageName=mariadb', 'summary': 'CVE-2026-3494', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-13699', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3494', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2397.json', 'summary': 'openEuler-SA-2026-2397 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-backup-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-backup-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-common-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-common-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-config-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-config-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-devel-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-devel-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-embedded-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-pam-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-pam-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-server-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-server-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-test-10.5.29-4.oe2403.aarch64.rpm', 'product': {'name': 'mariadb-test-10.5.29-4.oe2403.aarch64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403.src.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403.src.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'mariadb-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-backup-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-backup-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-backup-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-common-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-common-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-common-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-config-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-config-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-config-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-devel-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-devel-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-devel-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-embedded-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-embedded-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-pam-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-pam-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-pam-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-server-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-server-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-server-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mariadb-test-10.5.29-4.oe2403.x86_64.rpm', 'product': {'name': 'mariadb-test-10.5.29-4.oe2403.x86_64.rpm', 'product_id': 'mariadb-test-10.5.29-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-backup-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-backup-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-backup-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-common-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-common-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-common-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-config-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-config-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-config-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-debuginfo-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-debuginfo-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-debugsource-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-debugsource-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-devel-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-devel-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-devel-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-embedded-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-embedded-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-embedded-devel-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-embedded-devel-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-errmsg-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-errmsg-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-gssapi-server-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-gssapi-server-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-pam-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-pam-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-pam-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-server-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-server-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-server-galera-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-server-galera-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-server-utils-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-server-utils-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-test-10.5.29-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-test-10.5.29-4.oe2403.aarch64'}, 'product_reference': 'mariadb-test-10.5.29-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-10.5.29-4.oe2403.src'}, 'product_reference': 'mariadb-10.5.29-4.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-backup-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-backup-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-backup-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-common-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-common-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-common-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-config-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-config-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-config-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-debuginfo-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-debuginfo-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-debugsource-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-debugsource-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-devel-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-devel-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-devel-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-embedded-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-embedded-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-embedded-devel-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-embedded-devel-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-errmsg-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-errmsg-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-gssapi-server-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-gssapi-server-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-pam-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-pam-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-pam-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-server-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-server-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-server-galera-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-server-galera-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-server-utils-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-server-utils-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mariadb-test-10.5.29-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mariadb-test-10.5.29-4.oe2403.x86_64'}, 'product_reference': 'mariadb-test-10.5.29-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-13699', 'notes': [{'text': 'MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may vary depending on the implementation.\n\nThe specific flaw exists within the handling of view names. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27000.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-13699', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2397', 'details': 'mariadb security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:mariadb-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-backup-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-common-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-config-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-debuginfo-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-debugsource-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-devel-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-embedded-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-embedded-devel-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-errmsg-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-gssapi-server-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-oqgraph-engine-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-pam-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-rocksdb-engine-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-server-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-server-galera-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-server-utils-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-test-10.5.29-4.oe2403.aarch64', 'openEuler-24.03-LTS:mariadb-10.5.29-4.oe2403.src', 'openEuler-24.03-LTS:mariadb-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-backup-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-common-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-config-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-debuginfo-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-debugsource-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-devel-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-embedded-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-embedded-devel-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-errmsg-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-gssapi-server-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-oqgraph-engine-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-pam-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-server-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-server-galera-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-server-utils-10.5.29-4.oe2403.x86_64', 'openEuler-24.03-LTS:mariadb-test-10.5.29-4.oe2403.x86_64']}}, {'cve': 'CVE-2026-3494', 'notes': [{'text': 'In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3494', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2397', 'details': 'mariadb security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
b199c2e1ae4285cc516acf37ac8f582334434f58f469e5103d3b11322e949201
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2398
An update for httpd is now available for openEuler-24.03-LTS
Medium
2026-05-22 16:22:02+03:00
2026-05-22 16:22:02+03:00
['CVE-2026-33007', 'CVE-2026-33523', 'CVE-2026-33857', 'CVE-2026-34032']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-filesystem-2.4.58-15.oe2403.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.58-15.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-help-2.4.58-15.oe2403.noarch.rpm', 'product_id': 'httpd-help-2.4.58-15.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-debugsource-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-devel-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-tools-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_ldap-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_md-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_proxy_html-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_session-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_ssl-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-2.4.58-15.oe2403.src.rpm', 'product_id': 'httpd-2.4.58-15.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-debugsource-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-devel-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'httpd-tools-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_ldap-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_md-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_proxy_html-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_session-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'mod_ssl-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2398', 'summary': 'openEuler-SA-2026-2398', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2398.json', 'summary': 'openEuler-SA-2026-2398 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'httpd security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.\n\nSecurity Fix(es):\n\nA NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-33007)\n\nHTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33523)\n\nOut-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33857)\n\nImproper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-34032)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'httpd', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for httpd is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2398', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:02+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:02+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:02+08:00', 'initial_release_date': '2026-05-22T21:22:02+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2398', 'summary': 'openEuler-SA-2026-2398', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2398.json', 'summary': 'openEuler-SA-2026-2398 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'httpd-filesystem-2.4.58-15.oe2403.noarch.rpm', 'product': {'name': 'httpd-filesystem-2.4.58-15.oe2403.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.58-15.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-help-2.4.58-15.oe2403.noarch.rpm', 'product': {'name': 'httpd-help-2.4.58-15.oe2403.noarch.rpm', 'product_id': 'httpd-help-2.4.58-15.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'httpd-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'httpd-debugsource-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'httpd-devel-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'httpd-tools-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'mod_ldap-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'mod_md-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'mod_proxy_html-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'mod_session-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.58-15.oe2403.aarch64.rpm', 'product': {'name': 'mod_ssl-2.4.58-15.oe2403.aarch64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'httpd-2.4.58-15.oe2403.src.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403.src.rpm', 'product_id': 'httpd-2.4.58-15.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'httpd-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'httpd-debugsource-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'httpd-devel-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'httpd-tools-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'mod_ldap-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'mod_md-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'mod_proxy_html-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'mod_session-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.58-15.oe2403.x86_64.rpm', 'product': {'name': 'mod_ssl-2.4.58-15.oe2403.x86_64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'httpd-filesystem-2.4.58-15.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-filesystem-2.4.58-15.oe2403.noarch'}, 'product_reference': 'httpd-filesystem-2.4.58-15.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-help-2.4.58-15.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-help-2.4.58-15.oe2403.noarch'}, 'product_reference': 'httpd-help-2.4.58-15.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'httpd-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-debuginfo-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'httpd-debuginfo-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-debugsource-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'httpd-debugsource-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-devel-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'httpd-devel-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-tools-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'httpd-tools-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_ldap-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'mod_ldap-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_md-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'mod_md-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_proxy_html-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'mod_proxy_html-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_session-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'mod_session-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.58-15.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_ssl-2.4.58-15.oe2403.aarch64'}, 'product_reference': 'mod_ssl-2.4.58-15.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-2.4.58-15.oe2403.src'}, 'product_reference': 'httpd-2.4.58-15.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'httpd-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-debuginfo-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'httpd-debuginfo-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-debugsource-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'httpd-debugsource-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-devel-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'httpd-devel-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:httpd-tools-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'httpd-tools-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_ldap-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'mod_ldap-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_md-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'mod_md-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_proxy_html-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'mod_proxy_html-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_session-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'mod_session-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.58-15.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:mod_ssl-2.4.58-15.oe2403.x86_64'}, 'product_reference': 'mod_ssl-2.4.58-15.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33007', 'notes': [{'text': 'A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33007', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2398', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:httpd-filesystem-2.4.58-15.oe2403.noarch', 'openEuler-24.03-LTS:httpd-help-2.4.58-15.oe2403.noarch', 'openEuler-24.03-LTS:httpd-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:httpd-debuginfo-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:httpd-debugsource-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:httpd-devel-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:httpd-tools-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:mod_ldap-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:mod_md-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:mod_proxy_html-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:mod_session-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:mod_ssl-2.4.58-15.oe2403.aarch64', 'openEuler-24.03-LTS:httpd-2.4.58-15.oe2403.src', 'openEuler-24.03-LTS:httpd-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:httpd-debuginfo-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:httpd-debugsource-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:httpd-devel-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:httpd-tools-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:mod_ldap-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:mod_md-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:mod_proxy_html-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:mod_session-2.4.58-15.oe2403.x86_64', 'openEuler-24.03-LTS:mod_ssl-2.4.58-15.oe2403.x86_64']}}, {'cve': 'CVE-2026-33523', 'notes': [{'text': 'HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2398', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33857', 'notes': [{'text': 'Out-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33857', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2398', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-34032', 'notes': [{'text': 'Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34032', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2398', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
41c8af7f7da68ee16f1fc2ca4f9794a6f6495607cf787e58001590e5a13636c2
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2399
An update for httpd is now available for openEuler-24.03-LTS-SP1
Medium
2026-05-22 16:22:02+03:00
2026-05-22 16:22:02+03:00
['CVE-2026-34032']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_md-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_session-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-2.4.58-15.oe2403sp1.src.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp1.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_md-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_session-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'httpd-help-2.4.58-15.oe2403sp1.noarch.rpm', 'product_id': 'httpd-help-2.4.58-15.oe2403sp1.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2399', 'summary': 'openEuler-SA-2026-2399', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2399.json', 'summary': 'openEuler-SA-2026-2399 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'httpd security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.\n\nSecurity Fix(es):\n\nImproper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-34032)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'httpd', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for httpd is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2399', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:02+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:02+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:02+08:00', 'initial_release_date': '2026-05-22T21:22:02+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2399', 'summary': 'openEuler-SA-2026-2399', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2399.json', 'summary': 'openEuler-SA-2026-2399 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'httpd-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'mod_md-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'mod_session-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64.rpm', 'product': {'name': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'httpd-2.4.58-15.oe2403sp1.src.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403sp1.src.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'httpd-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'mod_md-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'mod_session-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64.rpm', 'product': {'name': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch.rpm', 'product': {'name': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'httpd-help-2.4.58-15.oe2403sp1.noarch.rpm', 'product': {'name': 'httpd-help-2.4.58-15.oe2403sp1.noarch.rpm', 'product_id': 'httpd-help-2.4.58-15.oe2403sp1.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'httpd-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-debugsource-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'httpd-debugsource-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-devel-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'httpd-devel-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-tools-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'httpd-tools-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_ldap-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'mod_ldap-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_md-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'mod_md-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_proxy_html-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'mod_proxy_html-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_session-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'mod_session-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_ssl-2.4.58-15.oe2403sp1.aarch64'}, 'product_reference': 'mod_ssl-2.4.58-15.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-2.4.58-15.oe2403sp1.src'}, 'product_reference': 'httpd-2.4.58-15.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'httpd-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-debugsource-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'httpd-debugsource-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-devel-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'httpd-devel-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-tools-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'httpd-tools-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_ldap-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'mod_ldap-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_md-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'mod_md-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_proxy_html-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'mod_proxy_html-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_session-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'mod_session-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:mod_ssl-2.4.58-15.oe2403sp1.x86_64'}, 'product_reference': 'mod_ssl-2.4.58-15.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-filesystem-2.4.58-15.oe2403sp1.noarch'}, 'product_reference': 'httpd-filesystem-2.4.58-15.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-help-2.4.58-15.oe2403sp1.noarch as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:httpd-help-2.4.58-15.oe2403sp1.noarch'}, 'product_reference': 'httpd-help-2.4.58-15.oe2403sp1.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34032', 'notes': [{'text': 'Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34032', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2399', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:httpd-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:httpd-debuginfo-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:httpd-debugsource-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:httpd-devel-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:httpd-tools-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mod_ldap-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mod_md-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mod_proxy_html-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mod_session-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:mod_ssl-2.4.58-15.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:httpd-2.4.58-15.oe2403sp1.src', 'openEuler-24.03-LTS-SP1:httpd-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:httpd-debuginfo-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:httpd-debugsource-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:httpd-devel-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:httpd-tools-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mod_ldap-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mod_md-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mod_proxy_html-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mod_session-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:mod_ssl-2.4.58-15.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:httpd-filesystem-2.4.58-15.oe2403sp1.noarch', 'openEuler-24.03-LTS-SP1:httpd-help-2.4.58-15.oe2403sp1.noarch']}}]}
505122cec2c1fb0f1173647ff73670c23997756e99351f7093ed5b967326cff9
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2400
An update for httpd is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-22 16:22:02+03:00
2026-05-22 16:22:02+03:00
['CVE-2026-33007', 'CVE-2026-33523', 'CVE-2026-33857', 'CVE-2026-34032']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_md-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_session-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-help-2.4.58-15.oe2403sp3.noarch.rpm', 'product_id': 'httpd-help-2.4.58-15.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_md-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_session-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'httpd-2.4.58-15.oe2403sp3.src.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp3.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2400', 'summary': 'openEuler-SA-2026-2400', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2400.json', 'summary': 'openEuler-SA-2026-2400 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'httpd security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.\n\nSecurity Fix(es):\n\nA NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-33007)\n\nHTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33523)\n\nOut-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33857)\n\nImproper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-34032)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'httpd', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for httpd is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2400', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:02+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:02+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:02+08:00', 'initial_release_date': '2026-05-22T21:22:02+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2400', 'summary': 'openEuler-SA-2026-2400', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2400.json', 'summary': 'openEuler-SA-2026-2400 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'httpd-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'mod_md-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'mod_session-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64.rpm', 'product': {'name': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch.rpm', 'product': {'name': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-help-2.4.58-15.oe2403sp3.noarch.rpm', 'product': {'name': 'httpd-help-2.4.58-15.oe2403sp3.noarch.rpm', 'product_id': 'httpd-help-2.4.58-15.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'httpd-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'mod_md-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_md-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'mod_session-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_session-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64.rpm', 'product': {'name': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_id': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'httpd-2.4.58-15.oe2403sp3.src.rpm', 'product': {'name': 'httpd-2.4.58-15.oe2403sp3.src.rpm', 'product_id': 'httpd-2.4.58-15.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'httpd-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-debugsource-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'httpd-debugsource-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-devel-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'httpd-devel-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-tools-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'httpd-tools-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_ldap-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'mod_ldap-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_md-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'mod_md-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_proxy_html-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'mod_proxy_html-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_session-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'mod_session-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_ssl-2.4.58-15.oe2403sp3.x86_64'}, 'product_reference': 'mod_ssl-2.4.58-15.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-filesystem-2.4.58-15.oe2403sp3.noarch'}, 'product_reference': 'httpd-filesystem-2.4.58-15.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-help-2.4.58-15.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-help-2.4.58-15.oe2403sp3.noarch'}, 'product_reference': 'httpd-help-2.4.58-15.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'httpd-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-debugsource-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'httpd-debugsource-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-devel-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'httpd-devel-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-tools-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'httpd-tools-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_ldap-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'mod_ldap-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_md-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'mod_md-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_proxy_html-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'mod_proxy_html-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_session-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'mod_session-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:mod_ssl-2.4.58-15.oe2403sp3.aarch64'}, 'product_reference': 'mod_ssl-2.4.58-15.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.58-15.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:httpd-2.4.58-15.oe2403sp3.src'}, 'product_reference': 'httpd-2.4.58-15.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33007', 'notes': [{'text': 'A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33007', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2400', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:httpd-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:httpd-debuginfo-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:httpd-debugsource-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:httpd-devel-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:httpd-tools-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mod_ldap-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mod_md-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mod_proxy_html-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mod_session-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:mod_ssl-2.4.58-15.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:httpd-filesystem-2.4.58-15.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:httpd-help-2.4.58-15.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:httpd-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:httpd-debuginfo-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:httpd-debugsource-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:httpd-devel-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:httpd-tools-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mod_ldap-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mod_md-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mod_proxy_html-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mod_session-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:mod_ssl-2.4.58-15.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:httpd-2.4.58-15.oe2403sp3.src']}}, {'cve': 'CVE-2026-33523', 'notes': [{'text': 'HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2400', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33857', 'notes': [{'text': 'Out-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33857', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2400', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-34032', 'notes': [{'text': 'Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34032', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2400', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
e93101c4e369fa20a620c0506c5f967c9f9213faa9860e15b686fdba697dccde
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2401
An update for httpd is now available for openEuler-20.03-LTS-SP4
High
2026-05-22 16:22:02+03:00
2026-05-22 16:22:02+03:00
['CVE-2026-24072', 'CVE-2026-29168', 'CVE-2026-29169', 'CVE-2026-33006', 'CVE-2026-33007', 'CVE-2026-33523', 'CVE-2026-33857', 'CVE-2026-34032', 'CVE-2026-34059']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-help-2.4.43-35.oe2003sp4.noarch.rpm', 'product_id': 'httpd-help-2.4.43-35.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_md-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_md-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_session-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_session-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-2.4.43-35.oe2003sp4.src.rpm', 'product_id': 'httpd-2.4.43-35.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_md-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_md-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_session-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_session-2.4.43-35.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'summary': 'openEuler-SA-2026-2401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-24072&packageName=httpd', 'summary': 'CVE-2026-24072', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-29168&packageName=httpd', 'summary': 'CVE-2026-29168', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-29169&packageName=httpd', 'summary': 'CVE-2026-29169', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33006&packageName=httpd', 'summary': 'CVE-2026-33006', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34059&packageName=httpd', 'summary': 'CVE-2026-34059', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-24072', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-29168', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-29169', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33006', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34059', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2401.json', 'summary': 'openEuler-SA-2026-2401 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'httpd security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.\n\nSecurity Fix(es):\n\nAn escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)\n\nAllocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's\xa0 mod_md via OCSP response data.\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)\n\nA NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.\n\nThe only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.\n\nUsers are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.(CVE-2026-29169)\n\nA timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-33006)\n\nA NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-33007)\n\nHTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33523)\n\nOut-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33857)\n\nImproper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-34032)\n\nBuffer Over-read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-34059)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'httpd', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for httpd is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2401', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:02+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:02+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:02+08:00', 'initial_release_date': '2026-05-22T21:22:02+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'summary': 'openEuler-SA-2026-2401', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-24072&packageName=httpd', 'summary': 'CVE-2026-24072', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-29168&packageName=httpd', 'summary': 'CVE-2026-29168', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-29169&packageName=httpd', 'summary': 'CVE-2026-29169', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33006&packageName=httpd', 'summary': 'CVE-2026-33006', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34059&packageName=httpd', 'summary': 'CVE-2026-34059', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-24072', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-29168', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-29169', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33006', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34059', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2401.json', 'summary': 'openEuler-SA-2026-2401 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch.rpm', 'product': {'name': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-help-2.4.43-35.oe2003sp4.noarch.rpm', 'product': {'name': 'httpd-help-2.4.43-35.oe2003sp4.noarch.rpm', 'product_id': 'httpd-help-2.4.43-35.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'httpd-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'httpd-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'mod_md-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_md-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'mod_session-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_session-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64.rpm', 'product': {'name': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_id': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'httpd-2.4.43-35.oe2003sp4.src.rpm', 'product': {'name': 'httpd-2.4.43-35.oe2003sp4.src.rpm', 'product_id': 'httpd-2.4.43-35.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'httpd-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'httpd-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'mod_md-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_md-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'mod_session-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_session-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64.rpm', 'product': {'name': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_id': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-filesystem-2.4.43-35.oe2003sp4.noarch'}, 'product_reference': 'httpd-filesystem-2.4.43-35.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-help-2.4.43-35.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-help-2.4.43-35.oe2003sp4.noarch'}, 'product_reference': 'httpd-help-2.4.43-35.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'httpd-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-debugsource-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'httpd-debugsource-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-devel-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'httpd-devel-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-tools-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'httpd-tools-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_ldap-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'mod_ldap-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_md-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'mod_md-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_proxy_html-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'mod_proxy_html-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_session-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'mod_session-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_ssl-2.4.43-35.oe2003sp4.aarch64'}, 'product_reference': 'mod_ssl-2.4.43-35.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.43-35.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-2.4.43-35.oe2003sp4.src'}, 'product_reference': 'httpd-2.4.43-35.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'httpd-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-debugsource-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'httpd-debugsource-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-devel-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'httpd-devel-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:httpd-tools-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'httpd-tools-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_ldap-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'mod_ldap-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_md-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'mod_md-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_proxy_html-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'mod_proxy_html-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_session-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'mod_session-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:mod_ssl-2.4.43-35.oe2003sp4.x86_64'}, 'product_reference': 'mod_ssl-2.4.43-35.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-24072', 'notes': [{'text': 'An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-24072', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:httpd-filesystem-2.4.43-35.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:httpd-help-2.4.43-35.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:httpd-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:httpd-debuginfo-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:httpd-debugsource-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:httpd-devel-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:httpd-tools-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:mod_ldap-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:mod_md-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:mod_proxy_html-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:mod_session-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:mod_ssl-2.4.43-35.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:httpd-2.4.43-35.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:httpd-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:httpd-debuginfo-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:httpd-debugsource-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:httpd-devel-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:httpd-tools-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:mod_ldap-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:mod_md-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:mod_proxy_html-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:mod_session-2.4.43-35.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:mod_ssl-2.4.43-35.oe2003sp4.x86_64']}}, {'cve': 'CVE-2026-29168', 'notes': [{'text': "Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's\xa0 mod_md via OCSP response data.\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-29168', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-29169', 'notes': [{'text': 'A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.\n\nThe only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.\n\nUsers are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-29169', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33006', 'notes': [{'text': 'A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33006', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33007', 'notes': [{'text': 'A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33007', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33523', 'notes': [{'text': 'HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33857', 'notes': [{'text': 'Out-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33857', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-34032', 'notes': [{'text': 'Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34032', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-34059', 'notes': [{'text': 'Buffer Over-read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34059', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2401', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
2015eb9f207503f701a7b53e223ba1498788ab9f29b0ee75ef33b9323bc3c6ca
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2402
An update for httpd is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-22 16:22:03+03:00
2026-05-22 16:22:03+03:00
['CVE-2026-33007', 'CVE-2026-33523', 'CVE-2026-33857', 'CVE-2026-34032']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_md-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_md-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_session-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_session-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-help-2.4.51-30.oe2203sp4.noarch.rpm', 'product_id': 'httpd-help-2.4.51-30.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_md-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_md-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_session-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_session-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'httpd-2.4.51-30.oe2203sp4.src.rpm', 'product_id': 'httpd-2.4.51-30.oe2203sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2402', 'summary': 'openEuler-SA-2026-2402', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2402.json', 'summary': 'openEuler-SA-2026-2402 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'httpd security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.\n\nSecurity Fix(es):\n\nA NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-33007)\n\nHTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33523)\n\nOut-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-33857)\n\nImproper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-34032)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for httpd is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'httpd', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for httpd is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2402', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:03+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:03+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:03+08:00', 'initial_release_date': '2026-05-22T21:22:03+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2402', 'summary': 'openEuler-SA-2026-2402', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33007&packageName=httpd', 'summary': 'CVE-2026-33007', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33523&packageName=httpd', 'summary': 'CVE-2026-33523', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-33857&packageName=httpd', 'summary': 'CVE-2026-33857', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-34032&packageName=httpd', 'summary': 'CVE-2026-34032', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33007', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33523', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-33857', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-34032', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2402.json', 'summary': 'openEuler-SA-2026-2402 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'httpd-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'httpd-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'mod_md-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_md-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'mod_session-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_session-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64.rpm', 'product': {'name': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_id': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch.rpm', 'product': {'name': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch.rpm', 'product_id': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-help-2.4.51-30.oe2203sp4.noarch.rpm', 'product': {'name': 'httpd-help-2.4.51-30.oe2203sp4.noarch.rpm', 'product_id': 'httpd-help-2.4.51-30.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'httpd-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'httpd-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_md-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'mod_md-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_md-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_session-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'mod_session-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_session-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64.rpm', 'product': {'name': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_id': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'httpd-2.4.51-30.oe2203sp4.src.rpm', 'product': {'name': 'httpd-2.4.51-30.oe2203sp4.src.rpm', 'product_id': 'httpd-2.4.51-30.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'httpd-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-debugsource-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'httpd-debugsource-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-devel-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'httpd-devel-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-tools-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'httpd-tools-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_ldap-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'mod_ldap-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_md-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'mod_md-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_proxy_html-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'mod_proxy_html-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_session-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'mod_session-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_ssl-2.4.51-30.oe2203sp4.x86_64'}, 'product_reference': 'mod_ssl-2.4.51-30.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-filesystem-2.4.51-30.oe2203sp4.noarch'}, 'product_reference': 'httpd-filesystem-2.4.51-30.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-help-2.4.51-30.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-help-2.4.51-30.oe2203sp4.noarch'}, 'product_reference': 'httpd-help-2.4.51-30.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'httpd-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-debugsource-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'httpd-debugsource-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-devel-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'httpd-devel-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-tools-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'httpd-tools-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_ldap-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'mod_ldap-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_md-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_md-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'mod_md-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_proxy_html-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'mod_proxy_html-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_session-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_session-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'mod_session-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:mod_ssl-2.4.51-30.oe2203sp4.aarch64'}, 'product_reference': 'mod_ssl-2.4.51-30.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'httpd-2.4.51-30.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:httpd-2.4.51-30.oe2203sp4.src'}, 'product_reference': 'httpd-2.4.51-30.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33007', 'notes': [{'text': 'A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33007', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2402', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:httpd-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:httpd-debuginfo-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:httpd-debugsource-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:httpd-devel-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:httpd-tools-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:mod_ldap-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:mod_md-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:mod_proxy_html-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:mod_session-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:mod_ssl-2.4.51-30.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:httpd-filesystem-2.4.51-30.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:httpd-help-2.4.51-30.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:httpd-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:httpd-debuginfo-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:httpd-debugsource-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:httpd-devel-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:httpd-tools-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:mod_ldap-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:mod_md-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:mod_proxy_html-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:mod_session-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:mod_ssl-2.4.51-30.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:httpd-2.4.51-30.oe2203sp4.src']}}, {'cve': 'CVE-2026-33523', 'notes': [{'text': 'HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\n\nThis issue affects Apache HTTP Server: from through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33523', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2402', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-33857', 'notes': [{'text': 'Out-of-bounds Read vulnerability in mod_proxy_ajp of \n\nApache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-33857', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2402', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-34032', 'notes': [{'text': 'Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-34032', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2402', 'details': 'httpd security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
ab9c61c1863ef564a6a127c013bc6e4579a213c85915bddeb9b22e63b4e267ea
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2403
An update for gnutls is now available for openEuler-20.03-LTS-SP4
Critical
2026-05-22 16:22:03+03:00
2026-05-22 16:22:03+03:00
['CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-3.6.14-22.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-3.6.14-22.oe2003sp4.src.rpm', 'product_id': 'gnutls-3.6.14-22.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-3.6.14-22.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'gnutls-help-3.6.14-22.oe2003sp4.noarch.rpm', 'product_id': 'gnutls-help-3.6.14-22.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'summary': 'openEuler-SA-2026-2403', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2403.json', 'summary': 'openEuler-SA-2026-2403 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.(CVE-2026-42009)\n\nA flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.(CVE-2026-42010)\n\n(CVE-2026-42013)\n\n(CVE-2026-42014)\n\n(CVE-2026-42015)\n\n(CVE-2026-5260)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2403', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:03+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:03+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:03+08:00', 'initial_release_date': '2026-05-22T21:22:03+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'summary': 'openEuler-SA-2026-2403', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2403.json', 'summary': 'openEuler-SA-2026-2403 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.6.14-22.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.6.14-22.oe2003sp4.src.rpm', 'product': {'name': 'gnutls-3.6.14-22.oe2003sp4.src.rpm', 'product_id': 'gnutls-3.6.14-22.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.6.14-22.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.6.14-22.oe2003sp4.noarch.rpm', 'product': {'name': 'gnutls-help-3.6.14-22.oe2003sp4.noarch.rpm', 'product_id': 'gnutls-help-3.6.14-22.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.6.14-22.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-22.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-3.6.14-22.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-22.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-devel-3.6.14-22.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-22.oe2003sp4.aarch64'}, 'product_reference': 'gnutls-utils-3.6.14-22.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.6.14-22.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-22.oe2003sp4.src'}, 'product_reference': 'gnutls-3.6.14-22.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.6.14-22.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-22.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-3.6.14-22.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-22.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-devel-3.6.14-22.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-22.oe2003sp4.x86_64'}, 'product_reference': 'gnutls-utils-3.6.14-22.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.6.14-22.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:gnutls-help-3.6.14-22.oe2003sp4.noarch'}, 'product_reference': 'gnutls-help-3.6.14-22.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42009', 'notes': [{'text': 'A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:gnutls-3.6.14-22.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-22.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-22.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-22.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-22.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-22.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:gnutls-3.6.14-22.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-debuginfo-3.6.14-22.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-debugsource-3.6.14-22.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-devel-3.6.14-22.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-utils-3.6.14-22.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:gnutls-help-3.6.14-22.oe2003sp4.noarch']}}, {'cve': 'CVE-2026-42010', 'notes': [{'text': 'A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42013', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42013', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42014', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42015', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42015', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5260', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2403', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
77cac94b87ac74a10517e0835df67d38de20dd1849643754d13ad1483f8520d7
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2404
An update for gnutls is now available for openEuler-22.03-LTS-SP4
Critical
2026-05-22 16:22:03+03:00
2026-05-22 16:22:03+03:00
['CVE-2026-3833', 'CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-3.7.2-23.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-23.oe2203sp4.src.rpm', 'product_id': 'gnutls-3.7.2-23.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-3.7.2-23.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'gnutls-help-3.7.2-23.oe2203sp4.noarch.rpm', 'product_id': 'gnutls-help-3.7.2-23.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'summary': 'openEuler-SA-2026-2404', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2404.json', 'summary': 'openEuler-SA-2026-2404 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'gnutls security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.(CVE-2026-3833)\n\nA flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.(CVE-2026-42009)\n\nA flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.(CVE-2026-42010)\n\n(CVE-2026-42013)\n\n(CVE-2026-42014)\n\n(CVE-2026-42015)\n\n(CVE-2026-5260)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for gnutls is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'gnutls', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for gnutls is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2404', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:03+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:03+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:03+08:00', 'initial_release_date': '2026-05-22T21:22:03+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'summary': 'openEuler-SA-2026-2404', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3833&packageName=gnutls', 'summary': 'CVE-2026-3833', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42009&packageName=gnutls', 'summary': 'CVE-2026-42009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42010&packageName=gnutls', 'summary': 'CVE-2026-42010', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42013&packageName=gnutls', 'summary': 'CVE-2026-42013', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42014&packageName=gnutls', 'summary': 'CVE-2026-42014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42015&packageName=gnutls', 'summary': 'CVE-2026-42015', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5260&packageName=gnutls', 'summary': 'CVE-2026-5260', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-3833', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42010', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42015', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2404.json', 'summary': 'openEuler-SA-2026-2404 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'gnutls-3.7.2-23.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64.rpm', 'product': {'name': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_id': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'gnutls-3.7.2-23.oe2203sp4.src.rpm', 'product': {'name': 'gnutls-3.7.2-23.oe2203sp4.src.rpm', 'product_id': 'gnutls-3.7.2-23.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'gnutls-3.7.2-23.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64.rpm', 'product': {'name': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_id': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'gnutls-help-3.7.2-23.oe2203sp4.noarch.rpm', 'product': {'name': 'gnutls-help-3.7.2-23.oe2203sp4.noarch.rpm', 'product_id': 'gnutls-help-3.7.2-23.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-23.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-23.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-3.7.2-23.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-23.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-devel-3.7.2-23.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-23.oe2203sp4.aarch64'}, 'product_reference': 'gnutls-utils-3.7.2-23.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-23.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-23.oe2203sp4.src'}, 'product_reference': 'gnutls-3.7.2-23.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-3.7.2-23.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-23.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-3.7.2-23.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-23.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-devel-3.7.2-23.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-23.oe2203sp4.x86_64'}, 'product_reference': 'gnutls-utils-3.7.2-23.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'gnutls-help-3.7.2-23.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:gnutls-help-3.7.2-23.oe2203sp4.noarch'}, 'product_reference': 'gnutls-help-3.7.2-23.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-3833', 'notes': [{'text': 'A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-3833', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:gnutls-3.7.2-23.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-23.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-23.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-23.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-23.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-23.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:gnutls-3.7.2-23.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-debuginfo-3.7.2-23.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-debugsource-3.7.2-23.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-devel-3.7.2-23.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-utils-3.7.2-23.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:gnutls-help-3.7.2-23.oe2203sp4.noarch']}}, {'cve': 'CVE-2026-42009', 'notes': [{'text': 'A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42010', 'notes': [{'text': 'A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42010', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42013', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42013', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42014', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.0, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-42015', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42015', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-5260', 'notes': [{'text': '', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2404', 'details': 'gnutls security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
bdba1bba9386cc37ee15115d2d654ebf94b91c8c7fd496c2385041d2a9e9d8c5
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2405
An update for nginx is now available for openEuler-20.03-LTS-SP4
High
2026-05-22 16:22:03+03:00
2026-05-22 16:22:03+03:00
['CVE-2026-42945']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-1.21.5-11.oe2003sp4.src.rpm', 'product_id': 'nginx-1.21.5-11.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch.rpm', 'product_id': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch.rpm', 'product_id': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2405', 'summary': 'openEuler-SA-2026-2405', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2405.json', 'summary': 'openEuler-SA-2026-2405 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'nginx security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.\n\nSecurity Fix(es):\n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'nginx', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for nginx is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2405', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:03+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:03+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:03+08:00', 'initial_release_date': '2026-05-22T21:22:03+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2405', 'summary': 'openEuler-SA-2026-2405', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2405.json', 'summary': 'openEuler-SA-2026-2405 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'nginx-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'nginx-1.21.5-11.oe2003sp4.src.rpm', 'product': {'name': 'nginx-1.21.5-11.oe2003sp4.src.rpm', 'product_id': 'nginx-1.21.5-11.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'nginx-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch.rpm', 'product': {'name': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch.rpm', 'product_id': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch.rpm', 'product': {'name': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch.rpm', 'product_id': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-debugsource-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-debugsource-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64'}, 'product_reference': 'nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.21.5-11.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-1.21.5-11.oe2003sp4.src'}, 'product_reference': 'nginx-1.21.5-11.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-debugsource-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-debugsource-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64'}, 'product_reference': 'nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-all-modules-1.21.5-11.oe2003sp4.noarch'}, 'product_reference': 'nginx-all-modules-1.21.5-11.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nginx-filesystem-1.21.5-11.oe2003sp4.noarch'}, 'product_reference': 'nginx-filesystem-1.21.5-11.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42945', 'notes': [{'text': 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2405', 'details': 'nginx security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:nginx-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-debuginfo-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-debugsource-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-mod-devel-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-mod-http-perl-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-mod-mail-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-mod-stream-1.21.5-11.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nginx-1.21.5-11.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:nginx-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-debuginfo-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-debugsource-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-mod-devel-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-mod-http-perl-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-mod-mail-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-mod-stream-1.21.5-11.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nginx-all-modules-1.21.5-11.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:nginx-filesystem-1.21.5-11.oe2003sp4.noarch']}}]}
68144389de43705f13d527af6806991df829d4a810870482d470193786be14c8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2406
An update for nginx is now available for openEuler-22.03-LTS-SP4
High
2026-05-22 16:22:04+03:00
2026-05-22 16:22:04+03:00
['CVE-2026-42945']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-1.21.5-13.oe2203sp4.src.rpm', 'product_id': 'nginx-1.21.5-13.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch.rpm', 'product_id': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch.rpm', 'product_id': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nginx-help-1.21.5-13.oe2203sp4.noarch.rpm', 'product_id': 'nginx-help-1.21.5-13.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2406', 'summary': 'openEuler-SA-2026-2406', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2406.json', 'summary': 'openEuler-SA-2026-2406 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'nginx security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.\n\nSecurity Fix(es):\n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'nginx', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for nginx is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2406', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:04+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:04+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:04+08:00', 'initial_release_date': '2026-05-22T21:22:04+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2406', 'summary': 'openEuler-SA-2026-2406', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2406.json', 'summary': 'openEuler-SA-2026-2406 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'nginx-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'nginx-1.21.5-13.oe2203sp4.src.rpm', 'product': {'name': 'nginx-1.21.5-13.oe2203sp4.src.rpm', 'product_id': 'nginx-1.21.5-13.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'nginx-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch.rpm', 'product': {'name': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch.rpm', 'product_id': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch.rpm', 'product': {'name': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch.rpm', 'product_id': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nginx-help-1.21.5-13.oe2203sp4.noarch.rpm', 'product': {'name': 'nginx-help-1.21.5-13.oe2203sp4.noarch.rpm', 'product_id': 'nginx-help-1.21.5-13.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-debugsource-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-debugsource-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64'}, 'product_reference': 'nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.21.5-13.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-1.21.5-13.oe2203sp4.src'}, 'product_reference': 'nginx-1.21.5-13.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-debugsource-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-debugsource-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64'}, 'product_reference': 'nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-all-modules-1.21.5-13.oe2203sp4.noarch'}, 'product_reference': 'nginx-all-modules-1.21.5-13.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-filesystem-1.21.5-13.oe2203sp4.noarch'}, 'product_reference': 'nginx-filesystem-1.21.5-13.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-help-1.21.5-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nginx-help-1.21.5-13.oe2203sp4.noarch'}, 'product_reference': 'nginx-help-1.21.5-13.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42945', 'notes': [{'text': 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2406', 'details': 'nginx security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:nginx-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-debuginfo-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-debugsource-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-mod-devel-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-mod-http-perl-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-mod-mail-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-mod-stream-1.21.5-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nginx-1.21.5-13.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:nginx-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-debuginfo-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-debugsource-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-mod-devel-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-mod-http-image-filter-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-mod-http-perl-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-mod-http-xslt-filter-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-mod-mail-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-mod-stream-1.21.5-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nginx-all-modules-1.21.5-13.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:nginx-filesystem-1.21.5-13.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:nginx-help-1.21.5-13.oe2203sp4.noarch']}}]}
75e17fa62caa46e38806fdfc30fc9cd467c5024fc986522fd69ae9e2988fa255
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2407
An update for nginx is now available for openEuler-24.03-LTS
High
2026-05-22 16:22:04+03:00
2026-05-22 16:22:04+03:00
['CVE-2026-42945']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-debugsource-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-all-modules-1.24.0-9.oe2403.noarch.rpm', 'product_id': 'nginx-all-modules-1.24.0-9.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-filesystem-1.24.0-9.oe2403.noarch.rpm', 'product_id': 'nginx-filesystem-1.24.0-9.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-help-1.24.0-9.oe2403.noarch.rpm', 'product_id': 'nginx-help-1.24.0-9.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-debugsource-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nginx-1.24.0-9.oe2403.src.rpm', 'product_id': 'nginx-1.24.0-9.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2407', 'summary': 'openEuler-SA-2026-2407', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2407.json', 'summary': 'openEuler-SA-2026-2407 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'nginx security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.\n\nSecurity Fix(es):\n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'nginx', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for nginx is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2407', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:04+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:04+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:04+08:00', 'initial_release_date': '2026-05-22T21:22:04+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2407', 'summary': 'openEuler-SA-2026-2407', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2407.json', 'summary': 'openEuler-SA-2026-2407 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'nginx-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-debugsource-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64.rpm', 'product': {'name': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'nginx-all-modules-1.24.0-9.oe2403.noarch.rpm', 'product': {'name': 'nginx-all-modules-1.24.0-9.oe2403.noarch.rpm', 'product_id': 'nginx-all-modules-1.24.0-9.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-filesystem-1.24.0-9.oe2403.noarch.rpm', 'product': {'name': 'nginx-filesystem-1.24.0-9.oe2403.noarch.rpm', 'product_id': 'nginx-filesystem-1.24.0-9.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-help-1.24.0-9.oe2403.noarch.rpm', 'product': {'name': 'nginx-help-1.24.0-9.oe2403.noarch.rpm', 'product_id': 'nginx-help-1.24.0-9.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'nginx-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-debugsource-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64.rpm', 'product': {'name': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'nginx-1.24.0-9.oe2403.src.rpm', 'product': {'name': 'nginx-1.24.0-9.oe2403.src.rpm', 'product_id': 'nginx-1.24.0-9.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-debuginfo-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-debuginfo-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-debugsource-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-debugsource-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-devel-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-mod-devel-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-http-perl-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-mod-http-perl-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-mail-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-mod-mail-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-stream-1.24.0-9.oe2403.x86_64'}, 'product_reference': 'nginx-mod-stream-1.24.0-9.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-all-modules-1.24.0-9.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-all-modules-1.24.0-9.oe2403.noarch'}, 'product_reference': 'nginx-all-modules-1.24.0-9.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-filesystem-1.24.0-9.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-filesystem-1.24.0-9.oe2403.noarch'}, 'product_reference': 'nginx-filesystem-1.24.0-9.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-help-1.24.0-9.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-help-1.24.0-9.oe2403.noarch'}, 'product_reference': 'nginx-help-1.24.0-9.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-debuginfo-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-debuginfo-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-debugsource-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-debugsource-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-devel-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-mod-devel-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-http-perl-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-mod-http-perl-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-mail-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-mod-mail-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-mod-stream-1.24.0-9.oe2403.aarch64'}, 'product_reference': 'nginx-mod-stream-1.24.0-9.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.24.0-9.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nginx-1.24.0-9.oe2403.src'}, 'product_reference': 'nginx-1.24.0-9.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42945', 'notes': [{'text': 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2407', 'details': 'nginx security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:nginx-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-debuginfo-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-debugsource-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-mod-devel-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-mod-http-image-filter-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-mod-http-perl-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-mod-http-xslt-filter-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-mod-mail-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-mod-stream-1.24.0-9.oe2403.x86_64', 'openEuler-24.03-LTS:nginx-all-modules-1.24.0-9.oe2403.noarch', 'openEuler-24.03-LTS:nginx-filesystem-1.24.0-9.oe2403.noarch', 'openEuler-24.03-LTS:nginx-help-1.24.0-9.oe2403.noarch', 'openEuler-24.03-LTS:nginx-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-debuginfo-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-debugsource-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-mod-devel-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-mod-http-image-filter-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-mod-http-perl-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-mod-http-xslt-filter-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-mod-mail-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-mod-stream-1.24.0-9.oe2403.aarch64', 'openEuler-24.03-LTS:nginx-1.24.0-9.oe2403.src']}}]}
4614e20e67c34b25e03352420baca18d0d97cc03022b475fa0705f3a45a035a8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2408
An update for nginx is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:22:04+03:00
2026-05-22 16:22:04+03:00
['CVE-2026-42945']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch.rpm', 'product_id': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch.rpm', 'product_id': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-help-1.24.0-9.oe2403sp3.noarch.rpm', 'product_id': 'nginx-help-1.24.0-9.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-1.24.0-9.oe2403sp3.src.rpm', 'product_id': 'nginx-1.24.0-9.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2408', 'summary': 'openEuler-SA-2026-2408', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2408.json', 'summary': 'openEuler-SA-2026-2408 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'nginx security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.\n\nSecurity Fix(es):\n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for nginx is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'nginx', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for nginx is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2408', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:04+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:04+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:04+08:00', 'initial_release_date': '2026-05-22T21:22:04+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2408', 'summary': 'openEuler-SA-2026-2408', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42945&packageName=nginx', 'summary': 'CVE-2026-42945', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2408.json', 'summary': 'openEuler-SA-2026-2408 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch.rpm', 'product': {'name': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch.rpm', 'product_id': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch.rpm', 'product': {'name': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch.rpm', 'product_id': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-help-1.24.0-9.oe2403sp3.noarch.rpm', 'product': {'name': 'nginx-help-1.24.0-9.oe2403sp3.noarch.rpm', 'product_id': 'nginx-help-1.24.0-9.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'nginx-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64.rpm', 'product': {'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'nginx-1.24.0-9.oe2403sp3.src.rpm', 'product': {'name': 'nginx-1.24.0-9.oe2403sp3.src.rpm', 'product_id': 'nginx-1.24.0-9.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'nginx-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64.rpm', 'product': {'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_id': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-all-modules-1.24.0-9.oe2403sp3.noarch'}, 'product_reference': 'nginx-all-modules-1.24.0-9.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-filesystem-1.24.0-9.oe2403sp3.noarch'}, 'product_reference': 'nginx-filesystem-1.24.0-9.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-help-1.24.0-9.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-help-1.24.0-9.oe2403sp3.noarch'}, 'product_reference': 'nginx-help-1.24.0-9.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-debugsource-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-debugsource-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64'}, 'product_reference': 'nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.24.0-9.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-1.24.0-9.oe2403sp3.src'}, 'product_reference': 'nginx-1.24.0-9.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-debugsource-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-debugsource-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64'}, 'product_reference': 'nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42945', 'notes': [{'text': 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\xa0module. This vulnerability exists when the rewrite\xa0directive is followed by a rewrite, if, or set\xa0directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.\xa0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42945', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2408', 'details': 'nginx security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:nginx-all-modules-1.24.0-9.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:nginx-filesystem-1.24.0-9.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:nginx-help-1.24.0-9.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:nginx-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-debuginfo-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-debugsource-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-mod-devel-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-mod-http-perl-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-mod-mail-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-mod-stream-1.24.0-9.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nginx-1.24.0-9.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:nginx-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-debuginfo-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-debugsource-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-mod-devel-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-mod-http-image-filter-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-mod-http-perl-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-mod-http-xslt-filter-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-mod-mail-1.24.0-9.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nginx-mod-stream-1.24.0-9.oe2403sp3.x86_64']}}]}
0026b0025d9d82c28e830c1f7de3c5351e979f5151f1a466d0c7fe772fe906ac
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2409
An update for glibc is now available for openEuler-20.03-LTS-SP4
Critical
2026-05-22 16:22:04+03:00
2026-05-22 16:22:04+03:00
['CVE-2026-5450', 'CVE-2026-5928']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-common-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-common-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-devel-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libnsl-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'libnsl-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nscd-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'nscd-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nss_modules-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'nss_modules-2.28-124.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-2.28-124.oe2003sp4.src.rpm', 'product_id': 'glibc-2.28-124.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-common-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-common-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-devel-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'libnsl-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'libnsl-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nscd-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'nscd-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'nss_modules-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'nss_modules-2.28-124.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'glibc-help-2.28-124.oe2003sp4.noarch.rpm', 'product_id': 'glibc-help-2.28-124.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2409', 'summary': 'openEuler-SA-2026-2409', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2409.json', 'summary': 'openEuler-SA-2026-2409 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'glibc security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt, login, exit and more.\n\nSecurity Fix(es):\n\nCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.(CVE-2026-5450)\n\nCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.(CVE-2026-5928)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'glibc', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for glibc is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2409', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:04+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:04+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:04+08:00', 'initial_release_date': '2026-05-22T21:22:04+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2409', 'summary': 'openEuler-SA-2026-2409', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2409.json', 'summary': 'openEuler-SA-2026-2409 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'glibc-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-common-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-common-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libnsl-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'libnsl-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'libnsl-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nscd-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'nscd-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'nscd-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.28-124.oe2003sp4.aarch64.rpm', 'product': {'name': 'nss_modules-2.28-124.oe2003sp4.aarch64.rpm', 'product_id': 'nss_modules-2.28-124.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'glibc-2.28-124.oe2003sp4.src.rpm', 'product': {'name': 'glibc-2.28-124.oe2003sp4.src.rpm', 'product_id': 'glibc-2.28-124.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'glibc-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-common-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-common-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libnsl-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'libnsl-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'libnsl-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nscd-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'nscd-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'nscd-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.28-124.oe2003sp4.x86_64.rpm', 'product': {'name': 'nss_modules-2.28-124.oe2003sp4.x86_64.rpm', 'product_id': 'nss_modules-2.28-124.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'glibc-help-2.28-124.oe2003sp4.noarch.rpm', 'product': {'name': 'glibc-help-2.28-124.oe2003sp4.noarch.rpm', 'product_id': 'glibc-help-2.28-124.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-all-langpacks-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-all-langpacks-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-benchtests-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-benchtests-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-common-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-common-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-compat-2.17-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-compat-2.17-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-debuginfo-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-debuginfo-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-debugsource-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-debugsource-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-debugutils-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-debugutils-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-devel-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-devel-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-locale-source-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-locale-source-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-nss-devel-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'glibc-nss-devel-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libnsl-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'libnsl-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nscd-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'nscd-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.28-124.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nss_modules-2.28-124.oe2003sp4.aarch64'}, 'product_reference': 'nss_modules-2.28-124.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.28-124.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-2.28-124.oe2003sp4.src'}, 'product_reference': 'glibc-2.28-124.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-all-langpacks-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-all-langpacks-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-benchtests-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-benchtests-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-common-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-common-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-compat-2.17-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-compat-2.17-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-debuginfo-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-debuginfo-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-debugsource-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-debugsource-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-debugutils-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-debugutils-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-devel-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-devel-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-locale-source-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-locale-source-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-nss-devel-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'glibc-nss-devel-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:libnsl-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'libnsl-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nscd-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'nscd-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.28-124.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:nss_modules-2.28-124.oe2003sp4.x86_64'}, 'product_reference': 'nss_modules-2.28-124.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-help-2.28-124.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:glibc-help-2.28-124.oe2003sp4.noarch'}, 'product_reference': 'glibc-help-2.28-124.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-5450', 'notes': [{'text': "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5450', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2409', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:glibc-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-all-langpacks-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-benchtests-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-common-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-compat-2.17-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-debuginfo-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-debugsource-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-debugutils-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-devel-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-locale-source-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-nss-devel-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:libnsl-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nscd-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:nss_modules-2.28-124.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:glibc-2.28-124.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:glibc-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-all-langpacks-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-benchtests-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-common-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-compat-2.17-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-debuginfo-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-debugsource-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-debugutils-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-devel-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-locale-source-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-nss-devel-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:libnsl-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nscd-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:nss_modules-2.28-124.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:glibc-help-2.28-124.oe2003sp4.noarch']}}, {'cve': 'CVE-2026-5928', 'notes': [{'text': 'Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5928', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2409', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
65c5aa9c7b9d60c2ce54960487b1be12bd303bca2d9c69279d32fa58dcdc12e7
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2410
An update for glibc is now available for openEuler-22.03-LTS-SP4
Critical
2026-05-22 16:22:04+03:00
2026-05-22 16:22:04+03:00
['CVE-2026-5450', 'CVE-2026-5928']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-common-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-common-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-devel-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libnsl-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'libnsl-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nscd-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'nscd-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nss_modules-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'nss_modules-2.34-176.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-2.34-176.oe2203sp4.src.rpm', 'product_id': 'glibc-2.34-176.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-common-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-common-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-devel-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'libnsl-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'libnsl-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nscd-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'nscd-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'nss_modules-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'nss_modules-2.34-176.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'glibc-help-2.34-176.oe2203sp4.noarch.rpm', 'product_id': 'glibc-help-2.34-176.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2410', 'summary': 'openEuler-SA-2026-2410', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2410.json', 'summary': 'openEuler-SA-2026-2410 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'glibc security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt, login, exit and more.\n\nSecurity Fix(es):\n\nCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.(CVE-2026-5450)\n\nCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.(CVE-2026-5928)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'glibc', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for glibc is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2410', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:04+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:04+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:04+08:00', 'initial_release_date': '2026-05-22T21:22:04+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2410', 'summary': 'openEuler-SA-2026-2410', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2410.json', 'summary': 'openEuler-SA-2026-2410 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'glibc-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-common-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-common-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libnsl-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'libnsl-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'libnsl-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nscd-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'nscd-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'nscd-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.34-176.oe2203sp4.aarch64.rpm', 'product': {'name': 'nss_modules-2.34-176.oe2203sp4.aarch64.rpm', 'product_id': 'nss_modules-2.34-176.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'glibc-2.34-176.oe2203sp4.src.rpm', 'product': {'name': 'glibc-2.34-176.oe2203sp4.src.rpm', 'product_id': 'glibc-2.34-176.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'glibc-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-common-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-common-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'libnsl-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'libnsl-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'libnsl-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nscd-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'nscd-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'nscd-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.34-176.oe2203sp4.x86_64.rpm', 'product': {'name': 'nss_modules-2.34-176.oe2203sp4.x86_64.rpm', 'product_id': 'nss_modules-2.34-176.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'glibc-help-2.34-176.oe2203sp4.noarch.rpm', 'product': {'name': 'glibc-help-2.34-176.oe2203sp4.noarch.rpm', 'product_id': 'glibc-help-2.34-176.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-all-langpacks-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-all-langpacks-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-common-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-common-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-compat-2.17-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-compat-2.17-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-debuginfo-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-debuginfo-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-debugsource-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-debugsource-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-debugutils-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-debugutils-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-devel-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-devel-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-locale-archive-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-locale-archive-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-locale-source-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-locale-source-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-nss-devel-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'glibc-nss-devel-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libnsl-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'libnsl-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nscd-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'nscd-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.34-176.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nss_modules-2.34-176.oe2203sp4.aarch64'}, 'product_reference': 'nss_modules-2.34-176.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.34-176.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-2.34-176.oe2203sp4.src'}, 'product_reference': 'glibc-2.34-176.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-all-langpacks-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-all-langpacks-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-common-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-common-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-compat-2.17-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-compat-2.17-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-debuginfo-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-debuginfo-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-debugsource-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-debugsource-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-debugutils-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-debugutils-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-devel-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-devel-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-locale-archive-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-locale-archive-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-locale-source-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-locale-source-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-nss-devel-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'glibc-nss-devel-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:libnsl-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'libnsl-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nscd-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'nscd-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.34-176.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:nss_modules-2.34-176.oe2203sp4.x86_64'}, 'product_reference': 'nss_modules-2.34-176.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-help-2.34-176.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:glibc-help-2.34-176.oe2203sp4.noarch'}, 'product_reference': 'glibc-help-2.34-176.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-5450', 'notes': [{'text': "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5450', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2410', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:glibc-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-all-langpacks-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-common-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-compat-2.17-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-debuginfo-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-debugsource-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-debugutils-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-devel-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-locale-archive-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-locale-source-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-nss-devel-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:libnsl-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nscd-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:nss_modules-2.34-176.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:glibc-2.34-176.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:glibc-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-all-langpacks-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-common-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-compat-2.17-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-debuginfo-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-debugsource-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-debugutils-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-devel-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-locale-archive-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-locale-source-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-nss-devel-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:libnsl-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nscd-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:nss_modules-2.34-176.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:glibc-help-2.34-176.oe2203sp4.noarch']}}, {'cve': 'CVE-2026-5928', 'notes': [{'text': 'Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5928', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2410', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
c5a866ea1e649c20b020e13ee9cda5997d9ed7a457aa82b88d99d09ddd2ef85e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2411
An update for glibc is now available for openEuler-24.03-LTS
Critical
2026-05-22 16:22:04+03:00
2026-05-22 16:22:04+03:00
['CVE-2026-5450', 'CVE-2026-5928']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-all-langpacks-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-common-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-debuginfo-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-debugsource-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-debugutils-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-devel-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-locale-archive-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-locale-source-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-nss-devel-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libnsl-2.38-105.oe2403.x86_64.rpm', 'product_id': 'libnsl-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nscd-2.38-105.oe2403.x86_64.rpm', 'product_id': 'nscd-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nss_modules-2.38-105.oe2403.x86_64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-help-2.38-105.oe2403.noarch.rpm', 'product_id': 'glibc-help-2.38-105.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-all-langpacks-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-common-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-debuginfo-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-debugsource-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-debugutils-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-devel-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-locale-archive-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-locale-source-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-nss-devel-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'libnsl-2.38-105.oe2403.aarch64.rpm', 'product_id': 'libnsl-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nscd-2.38-105.oe2403.aarch64.rpm', 'product_id': 'nscd-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'nss_modules-2.38-105.oe2403.aarch64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'glibc-2.38-105.oe2403.src.rpm', 'product_id': 'glibc-2.38-105.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2411', 'summary': 'openEuler-SA-2026-2411', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2411.json', 'summary': 'openEuler-SA-2026-2411 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'glibc security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': "The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt, login, exit and more.\n\nSecurity Fix(es):\n\nCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.(CVE-2026-5450)\n\nCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.(CVE-2026-5928)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'glibc', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for glibc is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2411', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:04+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:04+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:04+08:00', 'initial_release_date': '2026-05-22T21:22:04+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2411', 'summary': 'openEuler-SA-2026-2411', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2411.json', 'summary': 'openEuler-SA-2026-2411 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'glibc-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-all-langpacks-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-common-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-debuginfo-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-debugsource-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-debugutils-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-devel-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-locale-archive-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-locale-archive-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-locale-source-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'glibc-nss-devel-2.38-105.oe2403.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libnsl-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'libnsl-2.38-105.oe2403.x86_64.rpm', 'product_id': 'libnsl-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nscd-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'nscd-2.38-105.oe2403.x86_64.rpm', 'product_id': 'nscd-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.38-105.oe2403.x86_64.rpm', 'product': {'name': 'nss_modules-2.38-105.oe2403.x86_64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'glibc-help-2.38-105.oe2403.noarch.rpm', 'product': {'name': 'glibc-help-2.38-105.oe2403.noarch.rpm', 'product_id': 'glibc-help-2.38-105.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'glibc-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-all-langpacks-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-common-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-debuginfo-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-debugsource-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-debugutils-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-devel-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-locale-archive-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-locale-archive-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-locale-source-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'glibc-nss-devel-2.38-105.oe2403.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'libnsl-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'libnsl-2.38-105.oe2403.aarch64.rpm', 'product_id': 'libnsl-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nscd-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'nscd-2.38-105.oe2403.aarch64.rpm', 'product_id': 'nscd-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.38-105.oe2403.aarch64.rpm', 'product': {'name': 'nss_modules-2.38-105.oe2403.aarch64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'glibc-2.38-105.oe2403.src.rpm', 'product': {'name': 'glibc-2.38-105.oe2403.src.rpm', 'product_id': 'glibc-2.38-105.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-all-langpacks-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-all-langpacks-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-common-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-common-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-debuginfo-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-debuginfo-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-debugsource-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-debugsource-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-debugutils-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-debugutils-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-devel-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-devel-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-archive-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-locale-archive-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-locale-archive-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-locale-source-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-locale-source-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-nss-devel-2.38-105.oe2403.x86_64'}, 'product_reference': 'glibc-nss-devel-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libnsl-2.38-105.oe2403.x86_64'}, 'product_reference': 'libnsl-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nscd-2.38-105.oe2403.x86_64'}, 'product_reference': 'nscd-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.38-105.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nss_modules-2.38-105.oe2403.x86_64'}, 'product_reference': 'nss_modules-2.38-105.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-help-2.38-105.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-help-2.38-105.oe2403.noarch'}, 'product_reference': 'glibc-help-2.38-105.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-all-langpacks-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-all-langpacks-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-common-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-common-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-debuginfo-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-debuginfo-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-debugsource-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-debugsource-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-debugutils-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-debugutils-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-devel-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-devel-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-archive-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-locale-archive-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-locale-archive-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-locale-source-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-locale-source-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-nss-devel-2.38-105.oe2403.aarch64'}, 'product_reference': 'glibc-nss-devel-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:libnsl-2.38-105.oe2403.aarch64'}, 'product_reference': 'libnsl-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nscd-2.38-105.oe2403.aarch64'}, 'product_reference': 'nscd-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.38-105.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:nss_modules-2.38-105.oe2403.aarch64'}, 'product_reference': 'nss_modules-2.38-105.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.38-105.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:glibc-2.38-105.oe2403.src'}, 'product_reference': 'glibc-2.38-105.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-5450', 'notes': [{'text': "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5450', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2411', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:glibc-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-all-langpacks-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-common-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-debuginfo-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-debugsource-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-debugutils-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-devel-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-locale-archive-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-locale-source-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-nss-devel-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:libnsl-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:nscd-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:nss_modules-2.38-105.oe2403.x86_64', 'openEuler-24.03-LTS:glibc-help-2.38-105.oe2403.noarch', 'openEuler-24.03-LTS:glibc-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-all-langpacks-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-common-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-debuginfo-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-debugsource-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-debugutils-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-devel-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-locale-archive-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-locale-source-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-nss-devel-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:libnsl-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:nscd-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:nss_modules-2.38-105.oe2403.aarch64', 'openEuler-24.03-LTS:glibc-2.38-105.oe2403.src']}}, {'cve': 'CVE-2026-5928', 'notes': [{'text': 'Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5928', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2411', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
005b572ab8e166931a465b4dc9c97b0951a289ba0d2dd7bcad4e170d3bc589e0
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2412
An update for glibc is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-22 16:22:05+03:00
2026-05-22 16:22:05+03:00
['CVE-2026-5450', 'CVE-2026-5928']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-common-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libnsl-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'libnsl-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nscd-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'nscd-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nss_modules-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-2.38-105.oe2403sp3.src.rpm', 'product_id': 'glibc-2.38-105.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-common-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'libnsl-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'libnsl-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nscd-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'nscd-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'nss_modules-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'glibc-help-2.38-105.oe2403sp3.noarch.rpm', 'product_id': 'glibc-help-2.38-105.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2412', 'summary': 'openEuler-SA-2026-2412', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2412.json', 'summary': 'openEuler-SA-2026-2412 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'glibc security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': "The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt, login, exit and more.\n\nSecurity Fix(es):\n\nCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.(CVE-2026-5450)\n\nCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.(CVE-2026-5928)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for glibc is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'glibc', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for glibc is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2412', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:05+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:05+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:05+08:00', 'initial_release_date': '2026-05-22T21:22:05+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2412', 'summary': 'openEuler-SA-2026-2412', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5450&packageName=glibc', 'summary': 'CVE-2026-5450', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-5928&packageName=glibc', 'summary': 'CVE-2026-5928', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5450', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-5928', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2412.json', 'summary': 'openEuler-SA-2026-2412 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'glibc-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-common-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libnsl-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'libnsl-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'libnsl-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nscd-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'nscd-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'nscd-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.38-105.oe2403sp3.aarch64.rpm', 'product': {'name': 'nss_modules-2.38-105.oe2403sp3.aarch64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'glibc-2.38-105.oe2403sp3.src.rpm', 'product': {'name': 'glibc-2.38-105.oe2403sp3.src.rpm', 'product_id': 'glibc-2.38-105.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'glibc-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-common-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-common-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-common-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'libnsl-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'libnsl-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'libnsl-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nscd-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'nscd-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'nscd-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'nss_modules-2.38-105.oe2403sp3.x86_64.rpm', 'product': {'name': 'nss_modules-2.38-105.oe2403sp3.x86_64.rpm', 'product_id': 'nss_modules-2.38-105.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'glibc-help-2.38-105.oe2403sp3.noarch.rpm', 'product': {'name': 'glibc-help-2.38-105.oe2403sp3.noarch.rpm', 'product_id': 'glibc-help-2.38-105.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-all-langpacks-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-all-langpacks-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-common-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-common-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-debuginfo-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-debuginfo-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-debugsource-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-debugsource-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-debugutils-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-debugutils-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-devel-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-devel-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-locale-archive-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-locale-archive-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-locale-source-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-locale-source-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-nss-devel-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'glibc-nss-devel-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libnsl-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'libnsl-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nscd-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'nscd-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.38-105.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nss_modules-2.38-105.oe2403sp3.aarch64'}, 'product_reference': 'nss_modules-2.38-105.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.38-105.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-2.38-105.oe2403sp3.src'}, 'product_reference': 'glibc-2.38-105.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-all-langpacks-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-all-langpacks-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-common-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-common-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-common-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-debuginfo-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-debuginfo-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-debugsource-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-debugsource-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-debugutils-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-debugutils-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-devel-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-devel-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-devel-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-locale-archive-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-locale-archive-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-locale-source-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-locale-source-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-nss-devel-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'glibc-nss-devel-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'libnsl-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:libnsl-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'libnsl-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nscd-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nscd-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'nscd-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'nss_modules-2.38-105.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:nss_modules-2.38-105.oe2403sp3.x86_64'}, 'product_reference': 'nss_modules-2.38-105.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'glibc-help-2.38-105.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:glibc-help-2.38-105.oe2403sp3.noarch'}, 'product_reference': 'glibc-help-2.38-105.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-5450', 'notes': [{'text': "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5450', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2412', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:glibc-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-all-langpacks-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-common-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-debuginfo-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-debugsource-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-debugutils-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-devel-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-locale-archive-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-locale-source-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-nss-devel-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:libnsl-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nscd-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:nss_modules-2.38-105.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:glibc-2.38-105.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:glibc-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-all-langpacks-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-common-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-debuginfo-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-debugsource-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-debugutils-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-devel-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-locale-archive-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-locale-source-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-nss-devel-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:libnsl-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nscd-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:nss_modules-2.38-105.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:glibc-help-2.38-105.oe2403sp3.noarch']}}, {'cve': 'CVE-2026-5928', 'notes': [{'text': 'Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-5928', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2412', 'details': 'glibc security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
ad4c02087a1a4e6919d4fef84f5f25a17cff98dacbf0f976a1f6f5728254bca8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2413
An update for postgresql is now available for openEuler-24.03-LTS
High
2026-05-22 16:22:05+03:00
2026-05-22 16:22:05+03:00
['CVE-2026-6472', 'CVE-2026-6473', 'CVE-2026-6474', 'CVE-2026-6475', 'CVE-2026-6477', 'CVE-2026-6478', 'CVE-2026-6479', 'CVE-2026-6637']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-15.18-1.oe2403.src.rpm', 'product_id': 'postgresql-15.18-1.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-contrib-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-debugsource-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-docs-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-llvmjit-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-plperl-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-plpython3-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-pltcl-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-private-devel-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-private-libs-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-server-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-server-devel-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-static-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-test-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-test-rpm-macros-15.18-1.oe2403.noarch.rpm', 'product_id': 'postgresql-test-rpm-macros-15.18-1.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-contrib-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-debugsource-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-docs-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-llvmjit-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-plperl-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-plpython3-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-pltcl-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-private-devel-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-private-libs-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-server-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-server-devel-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-static-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'postgresql-test-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'summary': 'openEuler-SA-2026-2413', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=postgresql', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=postgresql', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=postgresql', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=postgresql', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=postgresql', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=postgresql', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=postgresql', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=postgresql', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2413.json', 'summary': 'openEuler-SA-2026-2413 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'postgresql security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for postgresql is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&apos;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.\n\nSecurity Fix(es):\n\nMissing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker\'s choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6472)\n\nInteger wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6473)\n\nExternally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6474)\n\nSymlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6475)\n\nUse of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6477)\n\nCovert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6478)\n\nUncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6479)\n\nStack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6637)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for postgresql is now available for openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'postgresql', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for postgresql is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2413', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:05+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:05+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:05+08:00', 'initial_release_date': '2026-05-22T21:22:05+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'summary': 'openEuler-SA-2026-2413', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=postgresql', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=postgresql', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=postgresql', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=postgresql', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=postgresql', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=postgresql', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=postgresql', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=postgresql', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2413.json', 'summary': 'openEuler-SA-2026-2413 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'postgresql-15.18-1.oe2403.src.rpm', 'product': {'name': 'postgresql-15.18-1.oe2403.src.rpm', 'product_id': 'postgresql-15.18-1.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'postgresql-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-contrib-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-contrib-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-debugsource-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-debugsource-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-docs-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-docs-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-llvmjit-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-llvmjit-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-plperl-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-plperl-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-plpython3-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-plpython3-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-pltcl-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-pltcl-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-private-devel-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-private-devel-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-private-libs-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-private-libs-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-server-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-server-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-server-devel-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-server-devel-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-static-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-static-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-test-15.18-1.oe2403.x86_64.rpm', 'product': {'name': 'postgresql-test-15.18-1.oe2403.x86_64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'postgresql-test-rpm-macros-15.18-1.oe2403.noarch.rpm', 'product': {'name': 'postgresql-test-rpm-macros-15.18-1.oe2403.noarch.rpm', 'product_id': 'postgresql-test-rpm-macros-15.18-1.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'postgresql-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-contrib-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-contrib-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-debugsource-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-debugsource-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-docs-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-docs-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-llvmjit-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-llvmjit-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-plperl-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-plperl-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-plpython3-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-plpython3-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-pltcl-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-pltcl-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-private-devel-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-private-devel-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-private-libs-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-private-libs-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-server-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-server-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-server-devel-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-server-devel-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-static-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-static-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'postgresql-test-15.18-1.oe2403.aarch64.rpm', 'product': {'name': 'postgresql-test-15.18-1.oe2403.aarch64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-15.18-1.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-15.18-1.oe2403.src'}, 'product_reference': 'postgresql-15.18-1.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-contrib-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-contrib-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-contrib-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debuginfo-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-debuginfo-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-debuginfo-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debugsource-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-debugsource-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-debugsource-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-docs-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-docs-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-docs-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-llvmjit-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-llvmjit-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-llvmjit-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plperl-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-plperl-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-plperl-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plpython3-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-plpython3-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-plpython3-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-pltcl-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-pltcl-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-pltcl-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-devel-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-private-devel-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-private-devel-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-libs-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-private-libs-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-private-libs-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-server-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-server-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-devel-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-server-devel-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-server-devel-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-static-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-static-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-static-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-test-15.18-1.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-test-15.18-1.oe2403.x86_64'}, 'product_reference': 'postgresql-test-15.18-1.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-test-macros-15.18-1.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-test-macros-15.18-1.oe2403.noarch'}, 'product_reference': 'postgresql-test-rpm-macros-15.18-1.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-contrib-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-contrib-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-contrib-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debuginfo-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-debuginfo-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-debuginfo-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debugsource-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-debugsource-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-debugsource-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-docs-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-docs-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-docs-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-llvmjit-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-llvmjit-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-llvmjit-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plperl-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-plperl-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-plperl-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plpython3-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-plpython3-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-plpython3-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-pltcl-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-pltcl-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-pltcl-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-devel-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-private-devel-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-private-devel-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-libs-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-private-libs-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-private-libs-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-server-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-server-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-devel-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-server-devel-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-server-devel-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-static-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-static-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-static-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-test-15.18-1.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:postgresql-test-15.18-1.oe2403.aarch64'}, 'product_reference': 'postgresql-test-15.18-1.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-6472', 'notes': [{'text': "Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6472', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:postgresql-15.18-1.oe2403.src', 'openEuler-24.03-LTS:postgresql-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-contrib-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-debuginfo-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-debugsource-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-docs-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-llvmjit-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-plperl-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-plpython3-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-pltcl-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-private-devel-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-private-libs-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-server-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-server-devel-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-static-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-test-15.18-1.oe2403.x86_64', 'openEuler-24.03-LTS:postgresql-test-macros-15.18-1.oe2403.noarch', 'openEuler-24.03-LTS:postgresql-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-contrib-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-debuginfo-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-debugsource-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-docs-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-llvmjit-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-plperl-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-plpython3-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-pltcl-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-private-devel-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-private-libs-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-server-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-server-devel-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-static-15.18-1.oe2403.aarch64', 'openEuler-24.03-LTS:postgresql-test-15.18-1.oe2403.aarch64']}}, {'cve': 'CVE-2026-6473', 'notes': [{'text': 'Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6473', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6474', 'notes': [{'text': 'Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6474', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6475', 'notes': [{'text': 'Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6475', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6477', 'notes': [{'text': 'Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6477', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6478', 'notes': [{'text': 'Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6478', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6479', 'notes': [{'text': 'Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6479', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6637', 'notes': [{'text': 'Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6637', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2413', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
bb9185b075e22e916cad264d69c525faadbf6e3ee6dffb8e2b714c912e82cf6e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2414
An update for postgresql is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:22:05+03:00
2026-05-22 16:22:05+03:00
['CVE-2026-6472', 'CVE-2026-6473', 'CVE-2026-6474', 'CVE-2026-6475', 'CVE-2026-6477', 'CVE-2026-6478', 'CVE-2026-6479', 'CVE-2026-6637']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-docs-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-server-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-static-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-test-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-15.18-1.oe2403sp3.src.rpm', 'product_id': 'postgresql-15.18-1.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-docs-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-server-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-static-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-test-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'postgresql-test-rpm-macros-15.18-1.oe2403sp3.noarch.rpm', 'product_id': 'postgresql-test-rpm-macros-15.18-1.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'summary': 'openEuler-SA-2026-2414', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=postgresql', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=postgresql', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=postgresql', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=postgresql', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=postgresql', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=postgresql', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=postgresql', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=postgresql', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2414.json', 'summary': 'openEuler-SA-2026-2414 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'postgresql security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for postgresql is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&apos;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.\n\nSecurity Fix(es):\n\nMissing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker\'s choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6472)\n\nInteger wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6473)\n\nExternally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6474)\n\nSymlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6475)\n\nUse of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6477)\n\nCovert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6478)\n\nUncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6479)\n\nStack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6637)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for postgresql is now available for openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'postgresql', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for postgresql is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2414', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:05+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:05+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:05+08:00', 'initial_release_date': '2026-05-22T21:22:05+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'summary': 'openEuler-SA-2026-2414', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6472&packageName=postgresql', 'summary': 'CVE-2026-6472', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6473&packageName=postgresql', 'summary': 'CVE-2026-6473', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6474&packageName=postgresql', 'summary': 'CVE-2026-6474', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6475&packageName=postgresql', 'summary': 'CVE-2026-6475', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6477&packageName=postgresql', 'summary': 'CVE-2026-6477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6478&packageName=postgresql', 'summary': 'CVE-2026-6478', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6479&packageName=postgresql', 'summary': 'CVE-2026-6479', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6637&packageName=postgresql', 'summary': 'CVE-2026-6637', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6472', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6473', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6474', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6475', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6478', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6479', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6637', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2414.json', 'summary': 'openEuler-SA-2026-2414 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'postgresql-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-docs-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-docs-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-server-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-server-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-static-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-static-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-test-15.18-1.oe2403sp3.aarch64.rpm', 'product': {'name': 'postgresql-test-15.18-1.oe2403sp3.aarch64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'postgresql-15.18-1.oe2403sp3.src.rpm', 'product': {'name': 'postgresql-15.18-1.oe2403sp3.src.rpm', 'product_id': 'postgresql-15.18-1.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'postgresql-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-docs-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-docs-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-docs-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-server-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-server-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-server-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-static-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-static-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-static-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'postgresql-test-15.18-1.oe2403sp3.x86_64.rpm', 'product': {'name': 'postgresql-test-15.18-1.oe2403sp3.x86_64.rpm', 'product_id': 'postgresql-test-15.18-1.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'postgresql-test-rpm-macros-15.18-1.oe2403sp3.noarch.rpm', 'product': {'name': 'postgresql-test-rpm-macros-15.18-1.oe2403sp3.noarch.rpm', 'product_id': 'postgresql-test-rpm-macros-15.18-1.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-contrib-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-contrib-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-debuginfo-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-debuginfo-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-debugsource-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-debugsource-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-docs-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-docs-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-docs-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-llvmjit-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-llvmjit-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-plperl-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-plperl-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-plpython3-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-plpython3-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-pltcl-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-pltcl-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-private-devel-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-private-devel-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-private-libs-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-private-libs-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-server-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-server-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-server-devel-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-server-devel-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-static-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-static-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-static-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-test-15.18-1.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-test-15.18-1.oe2403sp3.aarch64'}, 'product_reference': 'postgresql-test-15.18-1.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-15.18-1.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-15.18-1.oe2403sp3.src'}, 'product_reference': 'postgresql-15.18-1.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-contrib-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-contrib-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-debuginfo-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-debuginfo-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-debugsource-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-debugsource-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-docs-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-docs-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-docs-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-llvmjit-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-llvmjit-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-plperl-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-plperl-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-plpython3-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-plpython3-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-pltcl-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-pltcl-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-private-devel-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-private-devel-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-private-libs-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-private-libs-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-server-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-server-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-server-devel-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-server-devel-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-static-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-static-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-static-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-test-15.18-1.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-test-15.18-1.oe2403sp3.x86_64'}, 'product_reference': 'postgresql-test-15.18-1.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'postgresql-test-macros-15.18-1.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:postgresql-test-macros-15.18-1.oe2403sp3.noarch'}, 'product_reference': 'postgresql-test-rpm-macros-15.18-1.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-6472', 'notes': [{'text': "Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6472', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:postgresql-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-contrib-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-debuginfo-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-debugsource-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-docs-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-llvmjit-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-plperl-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-plpython3-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-pltcl-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-private-devel-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-private-libs-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-server-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-server-devel-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-static-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-test-15.18-1.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:postgresql-15.18-1.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:postgresql-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-contrib-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-debuginfo-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-debugsource-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-docs-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-llvmjit-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-plperl-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-plpython3-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-pltcl-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-private-devel-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-private-libs-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-server-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-server-devel-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-static-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-test-15.18-1.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:postgresql-test-macros-15.18-1.oe2403sp3.noarch']}}, {'cve': 'CVE-2026-6473', 'notes': [{'text': 'Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6473', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6474', 'notes': [{'text': 'Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6474', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6475', 'notes': [{'text': 'Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6475', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6477', 'notes': [{'text': 'Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6477', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6478', 'notes': [{'text': 'Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6478', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6479', 'notes': [{'text': 'Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6479', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-6637', 'notes': [{'text': 'Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6637', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2414', 'details': 'postgresql security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
d580763c1ef9a3831cbb6922d2e56f29ffb0de6aee93ee98fb99393031053726
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2415
An update for kernel is now available for openEuler-20.03-LTS-SP4
High
2026-05-22 16:22:05+03:00
2026-05-22 16:22:05+03:00
['CVE-2026-31527', 'CVE-2026-31698', 'CVE-2026-31699', 'CVE-2026-43047', 'CVE-2026-43048', 'CVE-2026-46333']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src.rpm', 'product_id': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'summary': 'openEuler-SA-2026-2415', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31527&packageName=kernel', 'summary': 'CVE-2026-31527', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31698&packageName=kernel', 'summary': 'CVE-2026-31698', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31699&packageName=kernel', 'summary': 'CVE-2026-31699', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46333&packageName=kernel', 'summary': 'CVE-2026-46333', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31527', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31698', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31699', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2415.json', 'summary': 'openEuler-SA-2026-2415 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'kernel security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'The Linux Kernel, the operating system core itself.\n\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: platform: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus\' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1](CVE-2026-31527)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don\'t attempt to copy PDH cert to userspace if PSP command failed\n\nWhen retrieving the PDH cert, don\'t attempt to copy the blobs to userspace\nif the firmware command failed. If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033\n\n CPU: 51 UID: 0 PID: 21033 Comm: syz.0.186 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY\n Tainted: [U]=USER, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.84.12-0 11/17/2025\n Call Trace:\n <TASK>\n dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120\n print_address_description ../mm/kasan/report.c:378 [inline]\n print_report+0xbc/0x260 ../mm/kasan/report.c:482\n kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595\n check_region_inline ../mm/kasan/generic.c:-1 [inline]\n kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200\n instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n copy_to_user ../include/linux/uaccess.h:236 [inline]\n sev_ioctl_do_pdh_export+0x3d3/0x7c0 ../drivers/crypto/ccp/sev-dev.c:2347\n sev_ioctl+0x2a2/0x490 ../drivers/crypto/ccp/sev-dev.c:2568\n vfs_ioctl ../fs/ioctl.c:51 [inline]\n __do_sys_ioctl ../fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583\n do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\nWARN if the driver says the command succeeded, but the firmware error code\nsays otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any\nfirwmware error.(CVE-2026-31698)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don\'t attempt to copy CSR to userspace if PSP command failed\n\nWhen retrieving the PEK CSR, don\'t attempt to copy the blob to userspace\nif the firmware command failed. If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n Read of size 2084 at addr ffff898144612e20 by task syz.9.219/21405\n\n CPU: 14 UID: 0 PID: 21405 Comm: syz.9.219 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY\n Tainted: [U]=USER, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025\n Call Trace:\n <TASK>\n dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120\n print_address_description ../mm/kasan/report.c:378 [inline]\n print_report+0xbc/0x260 ../mm/kasan/report.c:482\n kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595\n check_region_inline ../mm/kasan/generic.c:-1 [inline]\n kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200\n instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n copy_to_user ../include/linux/uaccess.h:236 [inline]\n sev_ioctl_do_pek_csr+0x31f/0x590 ../drivers/crypto/ccp/sev-dev.c:1872\n sev_ioctl+0x3a4/0x490 ../drivers/crypto/ccp/sev-dev.c:2562\n vfs_ioctl ../fs/ioctl.c:51 [inline]\n __do_sys_ioctl ../fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583\n do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\nWARN if the driver says the command succeeded, but the firmware error code\nsays otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any\nfirwmware error.(CVE-2026-31699)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report\'s feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn\'t, omit reporting the raw event and\nreturn early.(CVE-2026-43047)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <(CVE-2026-43048)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nptrace: slightly saner \'get_dumpable()\' logic\n\nThe \'dumpability\' of a task is fundamentally about the memory image of\nthe task - the concept comes from whether it can core dump or not - and\nmakes no sense when you don\'t have an associated mm.\n\nAnd almost all users do in fact use it only for the case where the task\nhas a mm pointer.\n\nBut we have one odd special case: ptrace_may_access() uses \'dumpable\' to\ncheck various other things entirely independently of the MM (typically\nexplicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for\nthreads that no longer have a VM (and maybe never did, like most kernel\nthreads).\n\nIt\'s not what this flag was designed for, but it is what it is.\n\nThe ptrace code does check that the uid/gid matches, so you do have to\nbe uid-0 to see kernel thread details, but this means that the\ntraditional "drop capabilities" model doesn\'t make any difference for\nthis all.\n\nMake it all make a *bit* more sense by saying that if you don\'t have a\nMM pointer, we\'ll use a cached "last dumpability" flag if the thread\never had a MM (it will be zero for kernel threads since it is never\nset), and require a proper CAP_SYS_PTRACE capability to override.(CVE-2026-46333)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP3/openEuler-24.03-LTS-SP2.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'kernel', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for kernel is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2415', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:05+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:05+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:05+08:00', 'initial_release_date': '2026-05-22T21:22:05+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'summary': 'openEuler-SA-2026-2415', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31527&packageName=kernel', 'summary': 'CVE-2026-31527', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31698&packageName=kernel', 'summary': 'CVE-2026-31698', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31699&packageName=kernel', 'summary': 'CVE-2026-31699', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46333&packageName=kernel', 'summary': 'CVE-2026-46333', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31527', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31698', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31699', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2415.json', 'summary': 'openEuler-SA-2026-2415 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product': {'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product': {'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src.rpm', 'product': {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src.rpm', 'product_id': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64'}, 'product_reference': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64'}, 'product_reference': 'python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:kernel-4.19.90-2605.4.0.0373.oe2003sp4.src'}, 'product_reference': 'kernel-4.19.90-2605.4.0.0373.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31527', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: platform: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31527', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:bpftool-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:bpftool-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:bpftool-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-debugsource-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-source-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-tools-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-tools-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-tools-devel-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:python2-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:python2-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:python3-perf-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:python3-perf-debuginfo-4.19.90-2605.4.0.0373.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:kernel-4.19.90-2605.4.0.0373.oe2003sp4.src']}}, {'cve': 'CVE-2026-31698', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed\n\nWhen retrieving the PDH cert, don't attempt to copy the blobs to userspace\nif the firmware command failed. If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033\n\n CPU: 51 UID: 0 PID: 21033 Comm: syz.0.186 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY\n Tainted: [U]=USER, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.84.12-0 11/17/2025\n Call Trace:\n <TASK>\n dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120\n print_address_description ../mm/kasan/report.c:378 [inline]\n print_report+0xbc/0x260 ../mm/kasan/report.c:482\n kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595\n check_region_inline ../mm/kasan/generic.c:-1 [inline]\n kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200\n instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n copy_to_user ../include/linux/uaccess.h:236 [inline]\n sev_ioctl_do_pdh_export+0x3d3/0x7c0 ../drivers/crypto/ccp/sev-dev.c:2347\n sev_ioctl+0x2a2/0x490 ../drivers/crypto/ccp/sev-dev.c:2568\n vfs_ioctl ../fs/ioctl.c:51 [inline]\n __do_sys_ioctl ../fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583\n do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\nWARN if the driver says the command succeeded, but the firmware error code\nsays otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any\nfirwmware error.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31698', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31699', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed\n\nWhen retrieving the PEK CSR, don't attempt to copy the blob to userspace\nif the firmware command failed. If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n Read of size 2084 at addr ffff898144612e20 by task syz.9.219/21405\n\n CPU: 14 UID: 0 PID: 21405 Comm: syz.9.219 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY\n Tainted: [U]=USER, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025\n Call Trace:\n <TASK>\n dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120\n print_address_description ../mm/kasan/report.c:378 [inline]\n print_report+0xbc/0x260 ../mm/kasan/report.c:482\n kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595\n check_region_inline ../mm/kasan/generic.c:-1 [inline]\n kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200\n instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n copy_to_user ../include/linux/uaccess.h:236 [inline]\n sev_ioctl_do_pek_csr+0x31f/0x590 ../drivers/crypto/ccp/sev-dev.c:1872\n sev_ioctl+0x3a4/0x490 ../drivers/crypto/ccp/sev-dev.c:2562\n vfs_ioctl ../fs/ioctl.c:51 [inline]\n __do_sys_ioctl ../fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583\n do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\nWARN if the driver says the command succeeded, but the firmware error code\nsays otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any\nfirwmware error.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31699', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43047', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report's feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn't, omit reporting the raw event and\nreturn early.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43047', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43048', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43048', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46333', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nptrace: slightly saner \'get_dumpable()\' logic\n\nThe \'dumpability\' of a task is fundamentally about the memory image of\nthe task - the concept comes from whether it can core dump or not - and\nmakes no sense when you don\'t have an associated mm.\n\nAnd almost all users do in fact use it only for the case where the task\nhas a mm pointer.\n\nBut we have one odd special case: ptrace_may_access() uses \'dumpable\' to\ncheck various other things entirely independently of the MM (typically\nexplicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for\nthreads that no longer have a VM (and maybe never did, like most kernel\nthreads).\n\nIt\'s not what this flag was designed for, but it is what it is.\n\nThe ptrace code does check that the uid/gid matches, so you do have to\nbe uid-0 to see kernel thread details, but this means that the\ntraditional "drop capabilities" model doesn\'t make any difference for\nthis all.\n\nMake it all make a *bit* more sense by saying that if you don\'t have a\nMM pointer, we\'ll use a cached "last dumpability" flag if the thread\never had a MM (it will be zero for kernel threads since it is never\nset), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2415', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
eb2bfb4eebab033a66518768b8939e540741ed00cd4d5e2fd5652527ed0015dd
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2416
An update for kernel is now available for openEuler-22.03-LTS-SP4
High
2026-05-22 16:22:06+03:00
2026-05-22 16:22:06+03:00
['CVE-2025-38488', 'CVE-2025-39841', 'CVE-2025-40261', 'CVE-2025-40324', 'CVE-2025-68185', 'CVE-2025-68214', 'CVE-2025-68288', 'CVE-2025-68820', 'CVE-2025-71064', 'CVE-2026-23273', 'CVE-2026-31393', 'CVE-2026-31447', 'CVE-2026-31477', 'CVE-2026-31527', 'CVE-2026-31611', 'CVE-2026-31612', 'CVE-2026-31704', 'CVE-2026-31708', 'CVE-2026-31754', 'CVE-2026-31755', 'CVE-2026-31771', 'CVE-2026-43047', 'CVE-2026-43048', 'CVE-2026-43171', 'CVE-2026-43212', 'CVE-2026-43261', 'CVE-2026-43428', 'CVE-2026-43488', 'CVE-2026-46333']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src.rpm', 'product_id': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'summary': 'openEuler-SA-2026-2416', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38488&packageName=kernel', 'summary': 'CVE-2025-38488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39841&packageName=kernel', 'summary': 'CVE-2025-39841', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40261&packageName=kernel', 'summary': 'CVE-2025-40261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40324&packageName=kernel', 'summary': 'CVE-2025-40324', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68185&packageName=kernel', 'summary': 'CVE-2025-68185', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68214&packageName=kernel', 'summary': 'CVE-2025-68214', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68288&packageName=kernel', 'summary': 'CVE-2025-68288', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68820&packageName=kernel', 'summary': 'CVE-2025-68820', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-71064&packageName=kernel', 'summary': 'CVE-2025-71064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23273&packageName=kernel', 'summary': 'CVE-2026-23273', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31393&packageName=kernel', 'summary': 'CVE-2026-31393', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31477&packageName=kernel', 'summary': 'CVE-2026-31477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31527&packageName=kernel', 'summary': 'CVE-2026-31527', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31611&packageName=kernel', 'summary': 'CVE-2026-31611', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31612&packageName=kernel', 'summary': 'CVE-2026-31612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31704&packageName=kernel', 'summary': 'CVE-2026-31704', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31708&packageName=kernel', 'summary': 'CVE-2026-31708', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31754&packageName=kernel', 'summary': 'CVE-2026-31754', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31755&packageName=kernel', 'summary': 'CVE-2026-31755', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31771&packageName=kernel', 'summary': 'CVE-2026-31771', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43171&packageName=kernel', 'summary': 'CVE-2026-43171', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43212&packageName=kernel', 'summary': 'CVE-2026-43212', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43261&packageName=kernel', 'summary': 'CVE-2026-43261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43428&packageName=kernel', 'summary': 'CVE-2026-43428', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43488&packageName=kernel', 'summary': 'CVE-2026-43488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46333&packageName=kernel', 'summary': 'CVE-2026-46333', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39841', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40324', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68185', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68214', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68288', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68820', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-71064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23273', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31393', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31527', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31611', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31704', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31708', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31754', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31755', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31771', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43171', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43212', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43428', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2416.json', 'summary': 'openEuler-SA-2026-2416 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'kernel security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': 'The Linux Kernel, the operating system core itself.\n\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in crypt_message when using async crypto\n\nThe CVE-2024-50047 fix removed asynchronous crypto handling from\ncrypt_message(), assuming all crypto operations are synchronous.\nHowever, when hardware crypto accelerators are used, this can cause\nuse-after-free crashes:\n\n crypt_message()\n // Allocate the creq buffer containing the req\n creq = smb2_get_aead_req(..., &req);\n\n // Async encryption returns -EINPROGRESS immediately\n rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);\n\n // Free creq while async operation is still in progress\n kvfree_sensitive(creq, ...);\n\nHardware crypto modules often implement async AEAD operations for\nperformance. When crypto_aead_encrypt/decrypt() returns -EINPROGRESS,\nthe operation completes asynchronously. Without crypto_wait_req(),\nthe function immediately frees the request buffer, leading to crashes\nwhen the driver later accesses the freed memory.\n\nThis results in a use-after-free condition when the hardware crypto\ndriver later accesses the freed request structure, leading to kernel\ncrashes with NULL pointer dereferences.\n\nThe issue occurs because crypto_alloc_aead() with mask=0 doesn\'t\nguarantee synchronous operation. Even without CRYPTO_ALG_ASYNC in\nthe mask, async implementations can be selected.\n\nFix by restoring the async crypto handling:\n- DECLARE_CRYPTO_WAIT(wait) for completion tracking\n- aead_request_set_callback() for async completion notification\n- crypto_wait_req() to wait for operation completion\n\nThis ensures the request buffer isn\'t freed until the crypto operation\ncompletes, whether synchronous or asynchronous, while preserving the\nCVE-2024-50047 fix.(CVE-2025-38488)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix buffer free/clear order in deferred receive path\n\nFix a use-after-free window by correcting the buffer release sequence in\nthe deferred receive path. The code freed the RQ buffer first and only\nthen cleared the context pointer under the lock. Concurrent paths (e.g.,\nABTS and the repost path) also inspect and release the same pointer under\nthe lock, so the old order could lead to double-free/UAF.\n\nNote that the repost path already uses the correct pattern: detach the\npointer under the lock, then free it after dropping the lock. The\ndeferred path should do the same.(CVE-2025-39841)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()\n\nnvme_fc_delete_assocation() waits for pending I/O to complete before\nreturning, and an error can cause ->ioerr_work to be queued after\ncancel_work_sync() had been called. Move the call to cancel_work_sync() to\nbe after nvme_fc_delete_association() to ensure ->ioerr_work is not running\nwhen the nvme_fc_ctrl object is freed. Otherwise the following can occur:\n\n[ 1135.911754] list_del corruption, ff2d24c8093f31f8->next is NULL\n[ 1135.917705] ------------[ cut here ]------------\n[ 1135.922336] kernel BUG at lib/list_debug.c:52!\n[ 1135.926784] Oops: invalid opcode: 0000 [#1] SMP NOPTI\n[ 1135.931851] CPU: 48 UID: 0 PID: 726 Comm: kworker/u449:23 Kdump: loaded Not tainted 6.12.0 #1 PREEMPT(voluntary)\n[ 1135.943490] Hardware name: Dell Inc. PowerEdge R660/0HGTK9, BIOS 2.5.4 01/16/2025\n[ 1135.950969] Workqueue: 0x0 (nvme-wq)\n[ 1135.954673] RIP: 0010:__list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1135.961041] Code: c7 c7 98 68 72 94 e8 26 45 fe ff 0f 0b 48 c7 c7 70 68 72 94 e8 18 45 fe ff 0f 0b 48 89 fe 48 c7 c7 80 69 72 94 e8 07 45 fe ff <0f> 0b 48 89 d1 48 c7 c7 a0 6a 72 94 48 89 c2 e8 f3 44 fe ff 0f 0b\n[ 1135.979788] RSP: 0018:ff579b19482d3e50 EFLAGS: 00010046\n[ 1135.985015] RAX: 0000000000000033 RBX: ff2d24c8093f31f0 RCX: 0000000000000000\n[ 1135.992148] RDX: 0000000000000000 RSI: ff2d24d6bfa1d0c0 RDI: ff2d24d6bfa1d0c0\n[ 1135.999278] RBP: ff2d24c8093f31f8 R08: 0000000000000000 R09: ffffffff951e2b08\n[ 1136.006413] R10: ffffffff95122ac8 R11: 0000000000000003 R12: ff2d24c78697c100\n[ 1136.013546] R13: fffffffffffffff8 R14: 0000000000000000 R15: ff2d24c78697c0c0\n[ 1136.020677] FS: 0000000000000000(0000) GS:ff2d24d6bfa00000(0000) knlGS:0000000000000000\n[ 1136.028765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 1136.034510] CR2: 00007fd207f90b80 CR3: 000000163ea22003 CR4: 0000000000f73ef0\n[ 1136.041641] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 1136.048776] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 1136.055910] PKRU: 55555554\n[ 1136.058623] Call Trace:\n[ 1136.061074] <TASK>\n[ 1136.063179] ? show_trace_log_lvl+0x1b0/0x2f0\n[ 1136.067540] ? show_trace_log_lvl+0x1b0/0x2f0\n[ 1136.071898] ? move_linked_works+0x4a/0xa0\n[ 1136.075998] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.081744] ? __die_body.cold+0x8/0x12\n[ 1136.085584] ? die+0x2e/0x50\n[ 1136.088469] ? do_trap+0xca/0x110\n[ 1136.091789] ? do_error_trap+0x65/0x80\n[ 1136.095543] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.101289] ? exc_invalid_op+0x50/0x70\n[ 1136.105127] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.110874] ? asm_exc_invalid_op+0x1a/0x20\n[ 1136.115059] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.120806] move_linked_works+0x4a/0xa0\n[ 1136.124733] worker_thread+0x216/0x3a0\n[ 1136.128485] ? __pfx_worker_thread+0x10/0x10\n[ 1136.132758] kthread+0xfa/0x240\n[ 1136.135904] ? __pfx_kthread+0x10/0x10\n[ 1136.139657] ret_from_fork+0x31/0x50\n[ 1136.143236] ? __pfx_kthread+0x10/0x10\n[ 1136.146988] ret_from_fork_asm+0x1a/0x30\n[ 1136.150915] </TASK>(CVE-2025-40261)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix crash in nfsd4_read_release()\n\nWhen tracing is enabled, the trace_nfsd_read_done trace point\ncrashes during the pynfs read.testNoFh test.(CVE-2025-40324)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing\n\nTheoretically it\'s an oopsable race, but I don\'t believe one can manage\nto hit it on real hardware; might become doable on a KVM, but it still\nwon\'t be easy to attack.\n\nAnyway, it\'s easy to deal with - since xdr_encode_hyper() is just a call of\nput_unaligned_be64(), we can put that under ->d_lock and be done with that.(CVE-2025-68185)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntimers: Fix NULL function pointer race in timer_shutdown_sync()\n\nThere is a race condition between timer_shutdown_sync() and timer\nexpiration that can lead to hitting a WARN_ON in expire_timers().\n\nThe issue occurs when timer_shutdown_sync() clears the timer function\nto NULL while the timer is still running on another CPU. The race\nscenario looks like this:\n\nCPU0\t\t\t\t\tCPU1\n\t\t\t\t\t<SOFTIRQ>\n\t\t\t\t\tlock_timer_base()\n\t\t\t\t\texpire_timers()\n\t\t\t\t\tbase->running_timer = timer;\n\t\t\t\t\tunlock_timer_base()\n\t\t\t\t\t[call_timer_fn enter]\n\t\t\t\t\tmod_timer()\n\t\t\t\t\t...\ntimer_shutdown_sync()\nlock_timer_base()\n// For now, will not detach the timer but only clear its function to NULL\nif (base->running_timer != timer)\n\tret = detach_if_pending(timer, base, true);\nif (shutdown)\n\ttimer->function = NULL;\nunlock_timer_base()\n\t\t\t\t\t[call_timer_fn exit]\n\t\t\t\t\tlock_timer_base()\n\t\t\t\t\tbase->running_timer = NULL;\n\t\t\t\t\tunlock_timer_base()\n\t\t\t\t\t...\n\t\t\t\t\t// Now timer is pending while its function set to NULL.\n\t\t\t\t\t// next timer trigger\n\t\t\t\t\t<SOFTIRQ>\n\t\t\t\t\texpire_timers()\n\t\t\t\t\tWARN_ON_ONCE(!fn) // hit\n\t\t\t\t\t...\nlock_timer_base()\n// Now timer will detach\nif (base->running_timer != timer)\n\tret = detach_if_pending(timer, base, true);\nif (shutdown)\n\ttimer->function = NULL;\nunlock_timer_base()\n\nThe problem is that timer_shutdown_sync() clears the timer function\nregardless of whether the timer is currently running. This can leave a\npending timer with a NULL function pointer, which triggers the\nWARN_ON_ONCE(!fn) check in expire_timers().\n\nFix this by only clearing the timer function when actually detaching the\ntimer. If the timer is running, leave the function pointer intact, which is\nsafe because the timer will be properly detached when it finishes running.(CVE-2025-68214)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: storage: Fix memory leak in USB bulk transport\n\nA kernel memory leak was identified by the \'ioctl_sg01\' test from Linux\nTest Project (LTP). The following bytes were mainly observed: 0x53425355.\n\nWhen USB storage devices incorrectly skip the data phase with status data,\nthe code extracts/validates the CSW from the sg buffer, but fails to clear\nit afterwards. This leaves status protocol data in srb\'s transfer buffer,\nsuch as the US_BULK_CS_SIGN \'USBS\' signature observed here. Thus, this can\nlead to USB protocols leaks to user space through SCSI generic (/dev/sg*)\ninterfaces, such as the one seen here when the LTP test requested 512 KiB.\n\nFix the leak by zeroing the CSW data in srb\'s transfer buffer immediately\nafter the validation of devices that skip data phase.\n\nNote: Differently from CVE-2018-1000204, which fixed a big leak by zero-\ning pages at allocation time, this leak occurs after allocation, when USB\nprotocol data is written to already-allocated sg pages.(CVE-2025-68288)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: xattr: fix null pointer deref in ext4_raw_inode()\n\nIf ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),\niloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()\nlacks error checking, this will lead to a null pointer dereference\nin ext4_raw_inode(), called right after ext4_get_inode_loc().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-68820)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.(CVE-2025-71064)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: observe an RCU grace period in macvlan_common_newlink() error path\n\nvalis reported that a race condition still happens after my prior patch.\n\nmacvlan_common_newlink() might have made @dev visible before\ndetecting an error, and its caller will directly call free_netdev(dev).\n\nWe must respect an RCU period, either in macvlan or the core networking\nstack.\n\nAfter adding a temporary mdelay(1000) in macvlan_forward_source_one()\nto open the race window, valis repro was:\n\nip link add p1 type veth peer p2\nip link set address 00:00:00:00:00:20 dev p1\nip link set up dev p1\nip link set up dev p2\nip link add mv0 link p2 type macvlan mode source\n\n(ip link add invalid% link p2 type macvlan mode source macaddr add\n00:00:00:00:00:20 &) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4\nPING 1.2.3.4 (1.2.3.4): 56 data bytes\nRTNETLINK answers: Invalid argument\n\nBUG: KASAN: slab-use-after-free in macvlan_forward_source\n(drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nRead of size 8 at addr ffff888016bb89c0 by task e/175\n\nCPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n<IRQ>\ndump_stack_lvl (lib/dump_stack.c:123)\nprint_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nkasan_report (mm/kasan/report.c:597)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nmacvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\n? tasklet_init (kernel/softirq.c:983)\nmacvlan_handle_frame (drivers/net/macvlan.c:501)\n\nAllocated by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\n__kasan_kmalloc (mm/kasan/common.c:419)\n__kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657\nmm/slub.c:7140)\nalloc_netdev_mqs (net/core/dev.c:12012)\nrtnl_create_link (net/core/rtnetlink.c:3648)\nrtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)\n\nFreed by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\nkasan_save_free_info (mm/kasan/generic.c:587)\n__kasan_slab_free (mm/kasan/common.c:287)\nkfree (mm/slub.c:6674 mm/slub.c:6882)\nrtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)(CVE-2026-23273)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access\n\nl2cap_information_rsp() checks that cmd_len covers the fixed\nl2cap_info_rsp header (type + result, 4 bytes) but then reads\nrsp->data without verifying that the payload is present:\n\n - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads\n 4 bytes past the header (needs cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header\n (needs cmd_len >= 5).\n\nA truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an\nout-of-bounds read of adjacent skb data.\n\nGuard each data access with the required payload length check. If the\npayload is too short, skip the read and let the state machine complete\nwith safe defaults (feat_mask and remote_fixed_chan remain zero from\nkzalloc), so the info timer cleanup and l2cap_conn_start() still run\nand the connection is not stalled.(CVE-2026-31393)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.(CVE-2026-31447)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix memory leaks and NULL deref in smb2_lock()\n\nsmb2_lock() has three error handling issues after list_del() detaches\nsmb_lock from lock_list at no_check_cl:\n\n1) If vfs_lock_file() returns an unexpected error in the non-UNLOCK\n path, goto out leaks smb_lock and its flock because the out:\n handler only iterates lock_list and rollback_list, neither of\n which contains the detached smb_lock.\n\n2) If vfs_lock_file() returns -ENOENT in the UNLOCK path, goto out\n leaks smb_lock and flock for the same reason. The error code\n returned to the dispatcher is also stale.\n\n3) In the rollback path, smb_flock_init() can return NULL on\n allocation failure. The result is dereferenced unconditionally,\n causing a kernel NULL pointer dereference. Add a NULL check to\n prevent the crash and clean up the bookkeeping; the VFS lock\n itself cannot be rolled back without the allocation and will be\n released at file or connection teardown.\n\nFix cases 1 and 2 by hoisting the locks_free_lock()/kfree() to before\nthe if(!rc) check in the UNLOCK branch so all exit paths share one\nfree site, and by freeing smb_lock and flock before goto out in the\nnon-UNLOCK branch. Propagate the correct error code in both cases.\nFix case 3 by wrapping the VFS unlock in an if(rlock) guard and adding\na NULL check for locks_free_lock(rlock) in the shared cleanup.\n\nFound via call-graph analysis using sqry.(CVE-2026-31477)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: platform: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus\' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1](CVE-2026-31527)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: require 3 sub-authorities before reading sub_auth[2]\n\nparse_dacl() compares each ACE SID against sid_unix_NFS_mode and on\nmatch reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is\nthe prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares\nonly min(num_subauth, 2) sub-authorities so a client SID with\nnum_subauth = 2 and sub_auth = {88, 3} will match.\n\nIf num_subauth = 2 and the ACE is placed at the very end of the security\ndescriptor, sub_auth[2] will be 4 bytes past end_of_acl. The\nout-of-band bytes will then be masked to the low 9 bits and applied as\nthe file\'s POSIX mode, probably not something that is good to have\nhappen.\n\nFix this up by forcing the SID to actually carry a third sub-authority\nbefore reading it at all.(CVE-2026-31611)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate EaNameLength in smb2_get_ea()\n\nsmb2_get_ea() reads ea_req->EaNameLength from the client request and\npasses it directly to strncmp() as the comparison length without\nverifying that the length of the name really is the size of the input\nbuffer received.\n\nFix this up by properly checking the size of the name based on the value\nreceived and the overall size of the request, to prevent a later\nstrncmp() call to use the length as a "trusted" size of the buffer.\nWithout this check, uninitialized heap values might be slowly leaked to\nthe client.(CVE-2026-31612)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use check_add_overflow() to prevent u16 DACL size overflow\n\nset_posix_acl_entries_dacl() and set_ntacl_dacl() accumulate ACE sizes\nin u16 variables. When a file has many POSIX ACL entries, the\naccumulated size can wrap past 65535, causing the pointer arithmetic\n(char *)pndace + *size to land within already-written ACEs. Subsequent\nwrites then overwrite earlier entries, and pndacl->size gets a\ntruncated value.\n\nUse check_add_overflow() at each accumulation point to detect the\nwrap before it corrupts the buffer, consistent with existing\ncheck_mul_overflow() usage elsewhere in smbacl.c.(CVE-2026-31704)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path\n\nsmb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL\nand the default QUERY_INFO path. The QUERY_INFO branch clamps\nqi.input_buffer_length to the server-reported OutputBufferLength and then\ncopies qi.input_buffer_length bytes from qi_rsp->Buffer to userspace, but\nit never verifies that the flexible-array payload actually fits within\nrsp_iov[1].iov_len.\n\nA malicious server can return OutputBufferLength larger than the actual\nQUERY_INFO response, causing copy_to_user() to walk past the response\nbuffer and expose adjacent kernel heap to userspace.\n\nGuard the QUERY_INFO copy with a bounds check on the actual Buffer\npayload. Use struct_size(qi_rsp, Buffer, qi.input_buffer_length)\nrather than an open-coded addition so the guard cannot overflow on\n32-bit builds.(CVE-2026-31708)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: gadget: fix state inconsistency on gadget init failure\n\nWhen cdns3_gadget_start() fails, the DRD hardware is left in gadget mode\nwhile software state remains INACTIVE, creating hardware/software state\ninconsistency.\n\nWhen switching to host mode via sysfs:\n echo host > /sys/class/usb_role/13180000.usb-role-switch/role\n\nThe role state is not set to CDNS_ROLE_STATE_ACTIVE due to the error,\nso cdns_role_stop() skips cleanup because state is still INACTIVE.\nThis violates the DRD controller design specification (Figure22),\nwhich requires returning to idle state before switching roles.\n\nThis leads to a synchronous external abort in xhci_gen_setup() when\nsetting up the host controller:\n\n[ 516.440698] configfs-gadget 13180000.usb: failed to start g1: -19\n[ 516.442035] cdns-usb3 13180000.usb: Failed to add gadget\n[ 516.443278] cdns-usb3 13180000.usb: set role 2 has failed\n...\n[ 1301.375722] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller\n[ 1301.377716] Internal error: synchronous external abort: 96000010 [#1] PREEMPT SMP\n[ 1301.382485] pc : xhci_gen_setup+0xa4/0x408\n[ 1301.393391] backtrace:\n ...\n xhci_gen_setup+0xa4/0x408 <-- CRASH\n xhci_plat_setup+0x44/0x58\n usb_add_hcd+0x284/0x678\n ...\n cdns_role_set+0x9c/0xbc <-- Role switch\n\nFix by calling cdns_drd_gadget_off() in the error path to properly\nclean up the DRD gadget state.(CVE-2026-31754)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: gadget: fix NULL pointer dereference in ep_queue\n\nWhen the gadget endpoint is disabled or not yet configured, the ep->desc\npointer can be NULL. This leads to a NULL pointer dereference when\n__cdns3_gadget_ep_queue() is called, causing a kernel crash.\n\nAdd a check to return -ESHUTDOWN if ep->desc is NULL, which is the\nstandard return code for unconfigured endpoints.\n\nThis prevents potential crashes when ep_queue is called on endpoints\nthat are not ready.(CVE-2026-31755)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: move wake reason storage into validated event handlers\n\nhci_store_wake_reason() is called from hci_event_packet() immediately\nafter stripping the HCI event header but before hci_event_func()\nenforces the per-event minimum payload length from hci_ev_table.\nThis means a short HCI event frame can reach bacpy() before any bounds\ncheck runs.\n\nRather than duplicating skb parsing and per-event length checks inside\nhci_store_wake_reason(), move wake-address storage into the individual\nevent handlers after their existing event-length validation has\nsucceeded. Convert hci_store_wake_reason() into a small helper that only\nstores an already-validated bdaddr while the caller holds hci_dev_lock().\nUse the same helper after hci_event_func() with a NULL address to\npreserve the existing unexpected-wake fallback semantics when no\nvalidated event handler records a wake address.\n\nAnnotate the helper with __must_hold(&hdev->lock) and add\nlockdep_assert_held(&hdev->lock) so future call paths keep the lock\ncontract explicit.\n\nCall the helper from hci_conn_request_evt(), hci_conn_complete_evt(),\nhci_sync_conn_complete_evt(), le_conn_complete_evt(),\nhci_le_adv_report_evt(), hci_le_ext_adv_report_evt(),\nhci_le_direct_adv_report_evt(), hci_le_pa_sync_established_evt(), and\nhci_le_past_received_evt().(CVE-2026-31771)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report\'s feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn\'t, omit reporting the raw event and\nreturn early.(CVE-2026-43047)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <(CVE-2026-43048)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nEFI/CPER: don\'t dump the entire memory region\n\nThe current logic at cper_print_fw_err() doesn\'t check if the\nerror record length is big enough to handle offset. On a bad firmware,\nif the ofset is above the actual record, length -= offset will\nunderflow, making it dump the entire memory.\n\nThe end result can be:\n\n - the logic taking a lot of time dumping large regions of memory;\n - data disclosure due to the memory dumps;\n - an OOPS, if it tries to dump an unmapped memory region.\n\nFix it by checking if the section length is too small before doing\na hex dump.\n\n[ rjw: Subject tweaks ](CVE-2026-43171)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Make cpumask_of_node() robust against NUMA_NO_NODE\n\nThe arch definition of cpumask_of_node() cannot handle NUMA_NO_NODE -\nwhich is a valid index - so add a check for this.(CVE-2026-43212)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\narm64: Add support for TSV110 Spectre-BHB mitigation\n\nThe TSV110 processor is vulnerable to the Spectre-BHB (Branch History\nBuffer) attack, which can be exploited to leak information through\nbranch prediction side channels. This commit adds the MIDR of TSV110\nto the list for software mitigation.(CVE-2026-43261)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nUSB: core: Limit the length of unkillable synchronous timeouts\n\nThe usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() APIs in usbcore allow unlimited timeout durations. And since they use uninterruptible waits, this leaves open the possibility of hanging a task for an indefinitely long time, with no way to kill it short of unplugging the target device.\n\nTo prevent this sort of problem, enforce a maximum limit on the length of these unkillable timeouts. The limit chosen here, somewhat arbitrarily, is 60 seconds. On many systems (although not all) this is short enough to avoid triggering the kernel\'s hung-task detector.\n\nIn addition, clear up the ambiguity of negative timeout values by treating them the same as 0, i.e., using the maximum allowed timeout.(CVE-2026-43428)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Prevent interrupt storm on host controller error (HCE)\n\nThe xHCI controller reports a Host Controller Error (HCE) in UAS Storage\nDevice plug/unplug scenarios on Android devices. HCE is checked in\nxhci_irq() function and causes an interrupt storm (since the interrupt\nisn’t cleared), leading to severe system-level faults.\n\nWhen the xHC controller reports HCE in the interrupt handler, the driver\nonly logs a warning and assumes xHC activity will stop as stated in xHCI\nspecification. An interrupt storm does however continue on some hosts\neven after HCE, and only ceases after manually disabling xHC interrupt\nand stopping the controller by calling xhci_halt().\n\nAdd xhci_halt() to xhci_irq() function where STS_HCE status is checked,\nmirroring the existing error handling pattern used for STS_FATAL errors.\n\nThis only fixes the interrupt storm. Proper HCE recovery requires resetting\nand re-initializing the xHC.(CVE-2026-43488)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nptrace: slightly saner \'get_dumpable()\' logic\n\nThe \'dumpability\' of a task is fundamentally about the memory image of\nthe task - the concept comes from whether it can core dump or not - and\nmakes no sense when you don\'t have an associated mm.\n\nAnd almost all users do in fact use it only for the case where the task\nhas a mm pointer.\n\nBut we have one odd special case: ptrace_may_access() uses \'dumpable\' to\ncheck various other things entirely independently of the MM (typically\nexplicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for\nthreads that no longer have a VM (and maybe never did, like most kernel\nthreads).\n\nIt\'s not what this flag was designed for, but it is what it is.\n\nThe ptrace code does check that the uid/gid matches, so you do have to\nbe uid-0 to see kernel thread details, but this means that the\ntraditional "drop capabilities" model doesn\'t make any difference for\nthis all.\n\nMake it all make a *bit* more sense by saying that if you don\'t have a\nMM pointer, we\'ll use a cached "last dumpability" flag if the thread\never had a MM (it will be zero for kernel threads since it is never\nset), and require a proper CAP_SYS_PTRACE capability to override.(CVE-2026-46333)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-22.03-LTS-SP4/openEuler-22.03-LTS-SP3/openEuler-24.03-LTS-SP2.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'kernel', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for kernel is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2416', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:06+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:06+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:06+08:00', 'initial_release_date': '2026-05-22T21:22:06+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'summary': 'openEuler-SA-2026-2416', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38488&packageName=kernel', 'summary': 'CVE-2025-38488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39841&packageName=kernel', 'summary': 'CVE-2025-39841', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40261&packageName=kernel', 'summary': 'CVE-2025-40261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40324&packageName=kernel', 'summary': 'CVE-2025-40324', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68185&packageName=kernel', 'summary': 'CVE-2025-68185', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68214&packageName=kernel', 'summary': 'CVE-2025-68214', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68288&packageName=kernel', 'summary': 'CVE-2025-68288', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68820&packageName=kernel', 'summary': 'CVE-2025-68820', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-71064&packageName=kernel', 'summary': 'CVE-2025-71064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23273&packageName=kernel', 'summary': 'CVE-2026-23273', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31393&packageName=kernel', 'summary': 'CVE-2026-31393', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31477&packageName=kernel', 'summary': 'CVE-2026-31477', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31527&packageName=kernel', 'summary': 'CVE-2026-31527', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31611&packageName=kernel', 'summary': 'CVE-2026-31611', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31612&packageName=kernel', 'summary': 'CVE-2026-31612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31704&packageName=kernel', 'summary': 'CVE-2026-31704', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31708&packageName=kernel', 'summary': 'CVE-2026-31708', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31754&packageName=kernel', 'summary': 'CVE-2026-31754', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31755&packageName=kernel', 'summary': 'CVE-2026-31755', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31771&packageName=kernel', 'summary': 'CVE-2026-31771', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43171&packageName=kernel', 'summary': 'CVE-2026-43171', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43212&packageName=kernel', 'summary': 'CVE-2026-43212', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43261&packageName=kernel', 'summary': 'CVE-2026-43261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43428&packageName=kernel', 'summary': 'CVE-2026-43428', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43488&packageName=kernel', 'summary': 'CVE-2026-43488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-46333&packageName=kernel', 'summary': 'CVE-2026-46333', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39841', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40324', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68185', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68214', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68288', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68820', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-71064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23273', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31393', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31477', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31527', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31611', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31704', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31708', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31754', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31755', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31771', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43171', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43212', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43428', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2416.json', 'summary': 'openEuler-SA-2026-2416 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src.rpm', 'product': {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src.rpm', 'product_id': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product': {'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product': {'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-5.10.0-315.0.0.218.oe2203sp4.src'}, 'product_reference': 'kernel-5.10.0-315.0.0.218.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64'}, 'product_reference': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64'}, 'product_reference': 'python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-38488', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in crypt_message when using async crypto\n\nThe CVE-2024-50047 fix removed asynchronous crypto handling from\ncrypt_message(), assuming all crypto operations are synchronous.\nHowever, when hardware crypto accelerators are used, this can cause\nuse-after-free crashes:\n\n crypt_message()\n // Allocate the creq buffer containing the req\n creq = smb2_get_aead_req(..., &req);\n\n // Async encryption returns -EINPROGRESS immediately\n rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);\n\n // Free creq while async operation is still in progress\n kvfree_sensitive(creq, ...);\n\nHardware crypto modules often implement async AEAD operations for\nperformance. When crypto_aead_encrypt/decrypt() returns -EINPROGRESS,\nthe operation completes asynchronously. Without crypto_wait_req(),\nthe function immediately frees the request buffer, leading to crashes\nwhen the driver later accesses the freed memory.\n\nThis results in a use-after-free condition when the hardware crypto\ndriver later accesses the freed request structure, leading to kernel\ncrashes with NULL pointer dereferences.\n\nThe issue occurs because crypto_alloc_aead() with mask=0 doesn't\nguarantee synchronous operation. Even without CRYPTO_ALG_ASYNC in\nthe mask, async implementations can be selected.\n\nFix by restoring the async crypto handling:\n- DECLARE_CRYPTO_WAIT(wait) for completion tracking\n- aead_request_set_callback() for async completion notification\n- crypto_wait_req() to wait for operation completion\n\nThis ensures the request buffer isn't freed until the crypto operation\ncompletes, whether synchronous or asynchronous, while preserving the\nCVE-2024-50047 fix.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38488', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:kernel-5.10.0-315.0.0.218.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:bpftool-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:bpftool-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-debugsource-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-headers-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-source-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:kernel-tools-devel-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-5.10.0-315.0.0.218.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:python3-perf-debuginfo-5.10.0-315.0.0.218.oe2203sp4.x86_64']}}, {'cve': 'CVE-2025-39841', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix buffer free/clear order in deferred receive path\n\nFix a use-after-free window by correcting the buffer release sequence in\nthe deferred receive path. The code freed the RQ buffer first and only\nthen cleared the context pointer under the lock. Concurrent paths (e.g.,\nABTS and the repost path) also inspect and release the same pointer under\nthe lock, so the old order could lead to double-free/UAF.\n\nNote that the repost path already uses the correct pattern: detach the\npointer under the lock, then free it after dropping the lock. The\ndeferred path should do the same.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39841', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40261', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()\n\nnvme_fc_delete_assocation() waits for pending I/O to complete before\nreturning, and an error can cause ->ioerr_work to be queued after\ncancel_work_sync() had been called. Move the call to cancel_work_sync() to\nbe after nvme_fc_delete_association() to ensure ->ioerr_work is not running\nwhen the nvme_fc_ctrl object is freed. Otherwise the following can occur:\n\n[ 1135.911754] list_del corruption, ff2d24c8093f31f8->next is NULL\n[ 1135.917705] ------------[ cut here ]------------\n[ 1135.922336] kernel BUG at lib/list_debug.c:52!\n[ 1135.926784] Oops: invalid opcode: 0000 [#1] SMP NOPTI\n[ 1135.931851] CPU: 48 UID: 0 PID: 726 Comm: kworker/u449:23 Kdump: loaded Not tainted 6.12.0 #1 PREEMPT(voluntary)\n[ 1135.943490] Hardware name: Dell Inc. PowerEdge R660/0HGTK9, BIOS 2.5.4 01/16/2025\n[ 1135.950969] Workqueue: 0x0 (nvme-wq)\n[ 1135.954673] RIP: 0010:__list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1135.961041] Code: c7 c7 98 68 72 94 e8 26 45 fe ff 0f 0b 48 c7 c7 70 68 72 94 e8 18 45 fe ff 0f 0b 48 89 fe 48 c7 c7 80 69 72 94 e8 07 45 fe ff <0f> 0b 48 89 d1 48 c7 c7 a0 6a 72 94 48 89 c2 e8 f3 44 fe ff 0f 0b\n[ 1135.979788] RSP: 0018:ff579b19482d3e50 EFLAGS: 00010046\n[ 1135.985015] RAX: 0000000000000033 RBX: ff2d24c8093f31f0 RCX: 0000000000000000\n[ 1135.992148] RDX: 0000000000000000 RSI: ff2d24d6bfa1d0c0 RDI: ff2d24d6bfa1d0c0\n[ 1135.999278] RBP: ff2d24c8093f31f8 R08: 0000000000000000 R09: ffffffff951e2b08\n[ 1136.006413] R10: ffffffff95122ac8 R11: 0000000000000003 R12: ff2d24c78697c100\n[ 1136.013546] R13: fffffffffffffff8 R14: 0000000000000000 R15: ff2d24c78697c0c0\n[ 1136.020677] FS: 0000000000000000(0000) GS:ff2d24d6bfa00000(0000) knlGS:0000000000000000\n[ 1136.028765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 1136.034510] CR2: 00007fd207f90b80 CR3: 000000163ea22003 CR4: 0000000000f73ef0\n[ 1136.041641] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 1136.048776] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 1136.055910] PKRU: 55555554\n[ 1136.058623] Call Trace:\n[ 1136.061074] <TASK>\n[ 1136.063179] ? show_trace_log_lvl+0x1b0/0x2f0\n[ 1136.067540] ? show_trace_log_lvl+0x1b0/0x2f0\n[ 1136.071898] ? move_linked_works+0x4a/0xa0\n[ 1136.075998] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.081744] ? __die_body.cold+0x8/0x12\n[ 1136.085584] ? die+0x2e/0x50\n[ 1136.088469] ? do_trap+0xca/0x110\n[ 1136.091789] ? do_error_trap+0x65/0x80\n[ 1136.095543] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.101289] ? exc_invalid_op+0x50/0x70\n[ 1136.105127] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.110874] ? asm_exc_invalid_op+0x1a/0x20\n[ 1136.115059] ? __list_del_entry_valid_or_report.cold+0xf/0x6f\n[ 1136.120806] move_linked_works+0x4a/0xa0\n[ 1136.124733] worker_thread+0x216/0x3a0\n[ 1136.128485] ? __pfx_worker_thread+0x10/0x10\n[ 1136.132758] kthread+0xfa/0x240\n[ 1136.135904] ? __pfx_kthread+0x10/0x10\n[ 1136.139657] ret_from_fork+0x31/0x50\n[ 1136.143236] ? __pfx_kthread+0x10/0x10\n[ 1136.146988] ret_from_fork_asm+0x1a/0x30\n[ 1136.150915] </TASK>', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40324', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix crash in nfsd4_read_release()\n\nWhen tracing is enabled, the trace_nfsd_read_done trace point\ncrashes during the pynfs read.testNoFh test.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40324', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68185', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing\n\nTheoretically it's an oopsable race, but I don't believe one can manage\nto hit it on real hardware; might become doable on a KVM, but it still\nwon't be easy to attack.\n\nAnyway, it's easy to deal with - since xdr_encode_hyper() is just a call of\nput_unaligned_be64(), we can put that under ->d_lock and be done with that.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68185', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68214', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntimers: Fix NULL function pointer race in timer_shutdown_sync()\n\nThere is a race condition between timer_shutdown_sync() and timer\nexpiration that can lead to hitting a WARN_ON in expire_timers().\n\nThe issue occurs when timer_shutdown_sync() clears the timer function\nto NULL while the timer is still running on another CPU. The race\nscenario looks like this:\n\nCPU0\t\t\t\t\tCPU1\n\t\t\t\t\t<SOFTIRQ>\n\t\t\t\t\tlock_timer_base()\n\t\t\t\t\texpire_timers()\n\t\t\t\t\tbase->running_timer = timer;\n\t\t\t\t\tunlock_timer_base()\n\t\t\t\t\t[call_timer_fn enter]\n\t\t\t\t\tmod_timer()\n\t\t\t\t\t...\ntimer_shutdown_sync()\nlock_timer_base()\n// For now, will not detach the timer but only clear its function to NULL\nif (base->running_timer != timer)\n\tret = detach_if_pending(timer, base, true);\nif (shutdown)\n\ttimer->function = NULL;\nunlock_timer_base()\n\t\t\t\t\t[call_timer_fn exit]\n\t\t\t\t\tlock_timer_base()\n\t\t\t\t\tbase->running_timer = NULL;\n\t\t\t\t\tunlock_timer_base()\n\t\t\t\t\t...\n\t\t\t\t\t// Now timer is pending while its function set to NULL.\n\t\t\t\t\t// next timer trigger\n\t\t\t\t\t<SOFTIRQ>\n\t\t\t\t\texpire_timers()\n\t\t\t\t\tWARN_ON_ONCE(!fn) // hit\n\t\t\t\t\t...\nlock_timer_base()\n// Now timer will detach\nif (base->running_timer != timer)\n\tret = detach_if_pending(timer, base, true);\nif (shutdown)\n\ttimer->function = NULL;\nunlock_timer_base()\n\nThe problem is that timer_shutdown_sync() clears the timer function\nregardless of whether the timer is currently running. This can leave a\npending timer with a NULL function pointer, which triggers the\nWARN_ON_ONCE(!fn) check in expire_timers().\n\nFix this by only clearing the timer function when actually detaching the\ntimer. If the timer is running, leave the function pointer intact, which is\nsafe because the timer will be properly detached when it finishes running.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68214', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68288', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: storage: Fix memory leak in USB bulk transport\n\nA kernel memory leak was identified by the 'ioctl_sg01' test from Linux\nTest Project (LTP). The following bytes were mainly observed: 0x53425355.\n\nWhen USB storage devices incorrectly skip the data phase with status data,\nthe code extracts/validates the CSW from the sg buffer, but fails to clear\nit afterwards. This leaves status protocol data in srb's transfer buffer,\nsuch as the US_BULK_CS_SIGN 'USBS' signature observed here. Thus, this can\nlead to USB protocols leaks to user space through SCSI generic (/dev/sg*)\ninterfaces, such as the one seen here when the LTP test requested 512 KiB.\n\nFix the leak by zeroing the CSW data in srb's transfer buffer immediately\nafter the validation of devices that skip data phase.\n\nNote: Differently from CVE-2018-1000204, which fixed a big leak by zero-\ning pages at allocation time, this leak occurs after allocation, when USB\nprotocol data is written to already-allocated sg pages.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68288', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68820', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: xattr: fix null pointer deref in ext4_raw_inode()\n\nIf ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),\niloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()\nlacks error checking, this will lead to a null pointer dereference\nin ext4_raw_inode(), called right after ext4_get_inode_loc().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68820', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-71064', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-71064', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23273', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: observe an RCU grace period in macvlan_common_newlink() error path\n\nvalis reported that a race condition still happens after my prior patch.\n\nmacvlan_common_newlink() might have made @dev visible before\ndetecting an error, and its caller will directly call free_netdev(dev).\n\nWe must respect an RCU period, either in macvlan or the core networking\nstack.\n\nAfter adding a temporary mdelay(1000) in macvlan_forward_source_one()\nto open the race window, valis repro was:\n\nip link add p1 type veth peer p2\nip link set address 00:00:00:00:00:20 dev p1\nip link set up dev p1\nip link set up dev p2\nip link add mv0 link p2 type macvlan mode source\n\n(ip link add invalid% link p2 type macvlan mode source macaddr add\n00:00:00:00:00:20 &) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4\nPING 1.2.3.4 (1.2.3.4): 56 data bytes\nRTNETLINK answers: Invalid argument\n\nBUG: KASAN: slab-use-after-free in macvlan_forward_source\n(drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nRead of size 8 at addr ffff888016bb89c0 by task e/175\n\nCPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n<IRQ>\ndump_stack_lvl (lib/dump_stack.c:123)\nprint_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nkasan_report (mm/kasan/report.c:597)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nmacvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\n? tasklet_init (kernel/softirq.c:983)\nmacvlan_handle_frame (drivers/net/macvlan.c:501)\n\nAllocated by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\n__kasan_kmalloc (mm/kasan/common.c:419)\n__kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657\nmm/slub.c:7140)\nalloc_netdev_mqs (net/core/dev.c:12012)\nrtnl_create_link (net/core/rtnetlink.c:3648)\nrtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)\n\nFreed by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\nkasan_save_free_info (mm/kasan/generic.c:587)\n__kasan_slab_free (mm/kasan/common.c:287)\nkfree (mm/slub.c:6674 mm/slub.c:6882)\nrtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23273', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31393', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access\n\nl2cap_information_rsp() checks that cmd_len covers the fixed\nl2cap_info_rsp header (type + result, 4 bytes) but then reads\nrsp->data without verifying that the payload is present:\n\n - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads\n 4 bytes past the header (needs cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header\n (needs cmd_len >= 5).\n\nA truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an\nout-of-bounds read of adjacent skb data.\n\nGuard each data access with the required payload length check. If the\npayload is too short, skip the read and let the state machine complete\nwith safe defaults (feat_mask and remote_fixed_chan remain zero from\nkzalloc), so the info timer cleanup and l2cap_conn_start() still run\nand the connection is not stalled.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31393', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31447', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31447', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31477', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix memory leaks and NULL deref in smb2_lock()\n\nsmb2_lock() has three error handling issues after list_del() detaches\nsmb_lock from lock_list at no_check_cl:\n\n1) If vfs_lock_file() returns an unexpected error in the non-UNLOCK\n path, goto out leaks smb_lock and its flock because the out:\n handler only iterates lock_list and rollback_list, neither of\n which contains the detached smb_lock.\n\n2) If vfs_lock_file() returns -ENOENT in the UNLOCK path, goto out\n leaks smb_lock and flock for the same reason. The error code\n returned to the dispatcher is also stale.\n\n3) In the rollback path, smb_flock_init() can return NULL on\n allocation failure. The result is dereferenced unconditionally,\n causing a kernel NULL pointer dereference. Add a NULL check to\n prevent the crash and clean up the bookkeeping; the VFS lock\n itself cannot be rolled back without the allocation and will be\n released at file or connection teardown.\n\nFix cases 1 and 2 by hoisting the locks_free_lock()/kfree() to before\nthe if(!rc) check in the UNLOCK branch so all exit paths share one\nfree site, and by freeing smb_lock and flock before goto out in the\nnon-UNLOCK branch. Propagate the correct error code in both cases.\nFix case 3 by wrapping the VFS unlock in an if(rlock) guard and adding\na NULL check for locks_free_lock(rlock) in the shared cleanup.\n\nFound via call-graph analysis using sqry.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31477', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31527', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: platform: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31527', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31611', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: require 3 sub-authorities before reading sub_auth[2]\n\nparse_dacl() compares each ACE SID against sid_unix_NFS_mode and on\nmatch reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is\nthe prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares\nonly min(num_subauth, 2) sub-authorities so a client SID with\nnum_subauth = 2 and sub_auth = {88, 3} will match.\n\nIf num_subauth = 2 and the ACE is placed at the very end of the security\ndescriptor, sub_auth[2] will be 4 bytes past end_of_acl. The\nout-of-band bytes will then be masked to the low 9 bits and applied as\nthe file's POSIX mode, probably not something that is good to have\nhappen.\n\nFix this up by forcing the SID to actually carry a third sub-authority\nbefore reading it at all.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31611', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31612', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate EaNameLength in smb2_get_ea()\n\nsmb2_get_ea() reads ea_req->EaNameLength from the client request and\npasses it directly to strncmp() as the comparison length without\nverifying that the length of the name really is the size of the input\nbuffer received.\n\nFix this up by properly checking the size of the name based on the value\nreceived and the overall size of the request, to prevent a later\nstrncmp() call to use the length as a "trusted" size of the buffer.\nWithout this check, uninitialized heap values might be slowly leaked to\nthe client.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31612', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31704', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use check_add_overflow() to prevent u16 DACL size overflow\n\nset_posix_acl_entries_dacl() and set_ntacl_dacl() accumulate ACE sizes\nin u16 variables. When a file has many POSIX ACL entries, the\naccumulated size can wrap past 65535, causing the pointer arithmetic\n(char *)pndace + *size to land within already-written ACEs. Subsequent\nwrites then overwrite earlier entries, and pndacl->size gets a\ntruncated value.\n\nUse check_add_overflow() at each accumulation point to detect the\nwrap before it corrupts the buffer, consistent with existing\ncheck_mul_overflow() usage elsewhere in smbacl.c.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31704', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31708', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path\n\nsmb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL\nand the default QUERY_INFO path. The QUERY_INFO branch clamps\nqi.input_buffer_length to the server-reported OutputBufferLength and then\ncopies qi.input_buffer_length bytes from qi_rsp->Buffer to userspace, but\nit never verifies that the flexible-array payload actually fits within\nrsp_iov[1].iov_len.\n\nA malicious server can return OutputBufferLength larger than the actual\nQUERY_INFO response, causing copy_to_user() to walk past the response\nbuffer and expose adjacent kernel heap to userspace.\n\nGuard the QUERY_INFO copy with a bounds check on the actual Buffer\npayload. Use struct_size(qi_rsp, Buffer, qi.input_buffer_length)\nrather than an open-coded addition so the guard cannot overflow on\n32-bit builds.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31708', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31754', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: gadget: fix state inconsistency on gadget init failure\n\nWhen cdns3_gadget_start() fails, the DRD hardware is left in gadget mode\nwhile software state remains INACTIVE, creating hardware/software state\ninconsistency.\n\nWhen switching to host mode via sysfs:\n echo host > /sys/class/usb_role/13180000.usb-role-switch/role\n\nThe role state is not set to CDNS_ROLE_STATE_ACTIVE due to the error,\nso cdns_role_stop() skips cleanup because state is still INACTIVE.\nThis violates the DRD controller design specification (Figure22),\nwhich requires returning to idle state before switching roles.\n\nThis leads to a synchronous external abort in xhci_gen_setup() when\nsetting up the host controller:\n\n[ 516.440698] configfs-gadget 13180000.usb: failed to start g1: -19\n[ 516.442035] cdns-usb3 13180000.usb: Failed to add gadget\n[ 516.443278] cdns-usb3 13180000.usb: set role 2 has failed\n...\n[ 1301.375722] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller\n[ 1301.377716] Internal error: synchronous external abort: 96000010 [#1] PREEMPT SMP\n[ 1301.382485] pc : xhci_gen_setup+0xa4/0x408\n[ 1301.393391] backtrace:\n ...\n xhci_gen_setup+0xa4/0x408 <-- CRASH\n xhci_plat_setup+0x44/0x58\n usb_add_hcd+0x284/0x678\n ...\n cdns_role_set+0x9c/0xbc <-- Role switch\n\nFix by calling cdns_drd_gadget_off() in the error path to properly\nclean up the DRD gadget state.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31754', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31755', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: gadget: fix NULL pointer dereference in ep_queue\n\nWhen the gadget endpoint is disabled or not yet configured, the ep->desc\npointer can be NULL. This leads to a NULL pointer dereference when\n__cdns3_gadget_ep_queue() is called, causing a kernel crash.\n\nAdd a check to return -ESHUTDOWN if ep->desc is NULL, which is the\nstandard return code for unconfigured endpoints.\n\nThis prevents potential crashes when ep_queue is called on endpoints\nthat are not ready.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31755', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31771', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: move wake reason storage into validated event handlers\n\nhci_store_wake_reason() is called from hci_event_packet() immediately\nafter stripping the HCI event header but before hci_event_func()\nenforces the per-event minimum payload length from hci_ev_table.\nThis means a short HCI event frame can reach bacpy() before any bounds\ncheck runs.\n\nRather than duplicating skb parsing and per-event length checks inside\nhci_store_wake_reason(), move wake-address storage into the individual\nevent handlers after their existing event-length validation has\nsucceeded. Convert hci_store_wake_reason() into a small helper that only\nstores an already-validated bdaddr while the caller holds hci_dev_lock().\nUse the same helper after hci_event_func() with a NULL address to\npreserve the existing unexpected-wake fallback semantics when no\nvalidated event handler records a wake address.\n\nAnnotate the helper with __must_hold(&hdev->lock) and add\nlockdep_assert_held(&hdev->lock) so future call paths keep the lock\ncontract explicit.\n\nCall the helper from hci_conn_request_evt(), hci_conn_complete_evt(),\nhci_sync_conn_complete_evt(), le_conn_complete_evt(),\nhci_le_adv_report_evt(), hci_le_ext_adv_report_evt(),\nhci_le_direct_adv_report_evt(), hci_le_pa_sync_established_evt(), and\nhci_le_past_received_evt().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31771', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43047', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report's feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn't, omit reporting the raw event and\nreturn early.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43047', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43048', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43048', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43171', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nEFI/CPER: don't dump the entire memory region\n\nThe current logic at cper_print_fw_err() doesn't check if the\nerror record length is big enough to handle offset. On a bad firmware,\nif the ofset is above the actual record, length -= offset will\nunderflow, making it dump the entire memory.\n\nThe end result can be:\n\n - the logic taking a lot of time dumping large regions of memory;\n - data disclosure due to the memory dumps;\n - an OOPS, if it tries to dump an unmapped memory region.\n\nFix it by checking if the section length is too small before doing\na hex dump.\n\n[ rjw: Subject tweaks ]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43171', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43212', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Make cpumask_of_node() robust against NUMA_NO_NODE\n\nThe arch definition of cpumask_of_node() cannot handle NUMA_NO_NODE -\nwhich is a valid index - so add a check for this.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43212', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43261', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: Add support for TSV110 Spectre-BHB mitigation\n\nThe TSV110 processor is vulnerable to the Spectre-BHB (Branch History\nBuffer) attack, which can be exploited to leak information through\nbranch prediction side channels. This commit adds the MIDR of TSV110\nto the list for software mitigation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43428', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: core: Limit the length of unkillable synchronous timeouts\n\nThe usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() APIs in usbcore allow unlimited timeout durations. And since they use uninterruptible waits, this leaves open the possibility of hanging a task for an indefinitely long time, with no way to kill it short of unplugging the target device.\n\nTo prevent this sort of problem, enforce a maximum limit on the length of these unkillable timeouts. The limit chosen here, somewhat arbitrarily, is 60 seconds. On many systems (although not all) this is short enough to avoid triggering the kernel's hung-task detector.\n\nIn addition, clear up the ambiguity of negative timeout values by treating them the same as 0, i.e., using the maximum allowed timeout.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43428', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43488', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Prevent interrupt storm on host controller error (HCE)\n\nThe xHCI controller reports a Host Controller Error (HCE) in UAS Storage\nDevice plug/unplug scenarios on Android devices. HCE is checked in\nxhci_irq() function and causes an interrupt storm (since the interrupt\nisn’t cleared), leading to severe system-level faults.\n\nWhen the xHC controller reports HCE in the interrupt handler, the driver\nonly logs a warning and assumes xHC activity will stop as stated in xHCI\nspecification. An interrupt storm does however continue on some hosts\neven after HCE, and only ceases after manually disabling xHC interrupt\nand stopping the controller by calling xhci_halt().\n\nAdd xhci_halt() to xhci_irq() function where STS_HCE status is checked,\nmirroring the existing error handling pattern used for STS_FATAL errors.\n\nThis only fixes the interrupt storm. Proper HCE recovery requires resetting\nand re-initializing the xHC.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43488', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-46333', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nptrace: slightly saner \'get_dumpable()\' logic\n\nThe \'dumpability\' of a task is fundamentally about the memory image of\nthe task - the concept comes from whether it can core dump or not - and\nmakes no sense when you don\'t have an associated mm.\n\nAnd almost all users do in fact use it only for the case where the task\nhas a mm pointer.\n\nBut we have one odd special case: ptrace_may_access() uses \'dumpable\' to\ncheck various other things entirely independently of the MM (typically\nexplicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for\nthreads that no longer have a VM (and maybe never did, like most kernel\nthreads).\n\nIt\'s not what this flag was designed for, but it is what it is.\n\nThe ptrace code does check that the uid/gid matches, so you do have to\nbe uid-0 to see kernel thread details, but this means that the\ntraditional "drop capabilities" model doesn\'t make any difference for\nthis all.\n\nMake it all make a *bit* more sense by saying that if you don\'t have a\nMM pointer, we\'ll use a cached "last dumpability" flag if the thread\never had a MM (it will be zero for kernel threads since it is never\nset), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2416', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
ba61e34fcbe3d9366f140bdbd4aa1beabf6977960674ba23fdae5fdec95de372
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2417
An update for kernel is now available for openEuler-24.03-LTS
Critical
2026-05-22 16:22:06+03:00
2026-05-22 16:22:06+03:00
['CVE-2024-56611', 'CVE-2024-56760', 'CVE-2025-21908', 'CVE-2025-21931', 'CVE-2025-21970', 'CVE-2025-21971', 'CVE-2025-21980', 'CVE-2025-21981', 'CVE-2025-21986', 'CVE-2025-21995', 'CVE-2025-22001', 'CVE-2025-22009', 'CVE-2025-22071', 'CVE-2025-22077', 'CVE-2025-23138', 'CVE-2025-23157', 'CVE-2025-37740', 'CVE-2025-37748', 'CVE-2025-37766', 'CVE-2025-37768', 'CVE-2025-37770', 'CVE-2025-37771', 'CVE-2025-37778', 'CVE-2025-37793', 'CVE-2025-37805', 'CVE-2025-37815', 'CVE-2025-37831', 'CVE-2025-37844', 'CVE-2025-37853', 'CVE-2025-37881', 'CVE-2025-37889', 'CVE-2025-37905', 'CVE-2025-37918', 'CVE-2025-37947', 'CVE-2025-37967', 'CVE-2025-38014', 'CVE-2025-38037', 'CVE-2025-38043', 'CVE-2025-38051', 'CVE-2025-38064', 'CVE-2025-38113', 'CVE-2025-38122', 'CVE-2025-38123', 'CVE-2025-38131', 'CVE-2025-38148', 'CVE-2025-38161', 'CVE-2025-38183', 'CVE-2025-38193', 'CVE-2025-38194', 'CVE-2025-38241', 'CVE-2025-38255', 'CVE-2025-38304', 'CVE-2025-38307', 'CVE-2025-38321', 'CVE-2025-38344', 'CVE-2025-38364', 'CVE-2025-38461', 'CVE-2025-38462', 'CVE-2025-38488', 'CVE-2025-38499', 'CVE-2025-38552', 'CVE-2025-38575', 'CVE-2025-38609', 'CVE-2025-38721', 'CVE-2025-39676', 'CVE-2025-39682', 'CVE-2025-39702', 'CVE-2025-39728', 'CVE-2025-39756', 'CVE-2025-39770', 'CVE-2025-39812', 'CVE-2025-39841', 'CVE-2025-39894', 'CVE-2025-39937', 'CVE-2025-39955', 'CVE-2025-39980', 'CVE-2025-40018', 'CVE-2025-40062', 'CVE-2025-40078', 'CVE-2025-40136', 'CVE-2025-40240', 'CVE-2025-40254', 'CVE-2025-40280', 'CVE-2025-40281', 'CVE-2025-40331', 'CVE-2025-68283', 'CVE-2025-68284', 'CVE-2025-68285', 'CVE-2025-68304', 'CVE-2025-68740', 'CVE-2025-68742', 'CVE-2025-68795', 'CVE-2025-68820', 'CVE-2025-71064', 'CVE-2026-22976', 'CVE-2026-22994', 'CVE-2026-23053', 'CVE-2026-23056', 'CVE-2026-23063', 'CVE-2026-23253', 'CVE-2026-23260', 'CVE-2026-23268', 'CVE-2026-23271', 'CVE-2026-23273', 'CVE-2026-31447', 'CVE-2026-43047', 'CVE-2026-43048', 'CVE-2026-43407']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-6.6.0-145.0.12.138.oe2403.src.rpm', 'product_id': 'kernel-6.6.0-145.0.12.138.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'summary': 'openEuler-SA-2026-2417', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56611&packageName=kernel', 'summary': 'CVE-2024-56611', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56760&packageName=kernel', 'summary': 'CVE-2024-56760', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21908&packageName=kernel', 'summary': 'CVE-2025-21908', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21931&packageName=kernel', 'summary': 'CVE-2025-21931', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21970&packageName=kernel', 'summary': 'CVE-2025-21970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21971&packageName=kernel', 'summary': 'CVE-2025-21971', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21980&packageName=kernel', 'summary': 'CVE-2025-21980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21981&packageName=kernel', 'summary': 'CVE-2025-21981', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21986&packageName=kernel', 'summary': 'CVE-2025-21986', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21995&packageName=kernel', 'summary': 'CVE-2025-21995', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22001&packageName=kernel', 'summary': 'CVE-2025-22001', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22009&packageName=kernel', 'summary': 'CVE-2025-22009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22071&packageName=kernel', 'summary': 'CVE-2025-22071', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22077&packageName=kernel', 'summary': 'CVE-2025-22077', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23138&packageName=kernel', 'summary': 'CVE-2025-23138', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23157&packageName=kernel', 'summary': 'CVE-2025-23157', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37740&packageName=kernel', 'summary': 'CVE-2025-37740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37748&packageName=kernel', 'summary': 'CVE-2025-37748', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37766&packageName=kernel', 'summary': 'CVE-2025-37766', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37768&packageName=kernel', 'summary': 'CVE-2025-37768', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37770&packageName=kernel', 'summary': 'CVE-2025-37770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37771&packageName=kernel', 'summary': 'CVE-2025-37771', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37778&packageName=kernel', 'summary': 'CVE-2025-37778', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37793&packageName=kernel', 'summary': 'CVE-2025-37793', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37805&packageName=kernel', 'summary': 'CVE-2025-37805', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37815&packageName=kernel', 'summary': 'CVE-2025-37815', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37831&packageName=kernel', 'summary': 'CVE-2025-37831', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37844&packageName=kernel', 'summary': 'CVE-2025-37844', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37853&packageName=kernel', 'summary': 'CVE-2025-37853', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37881&packageName=kernel', 'summary': 'CVE-2025-37881', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37889&packageName=kernel', 'summary': 'CVE-2025-37889', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37905&packageName=kernel', 'summary': 'CVE-2025-37905', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37918&packageName=kernel', 'summary': 'CVE-2025-37918', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37947&packageName=kernel', 'summary': 'CVE-2025-37947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37967&packageName=kernel', 'summary': 'CVE-2025-37967', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38014&packageName=kernel', 'summary': 'CVE-2025-38014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38037&packageName=kernel', 'summary': 'CVE-2025-38037', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38043&packageName=kernel', 'summary': 'CVE-2025-38043', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38051&packageName=kernel', 'summary': 'CVE-2025-38051', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38064&packageName=kernel', 'summary': 'CVE-2025-38064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38113&packageName=kernel', 'summary': 'CVE-2025-38113', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38122&packageName=kernel', 'summary': 'CVE-2025-38122', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38123&packageName=kernel', 'summary': 'CVE-2025-38123', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38131&packageName=kernel', 'summary': 'CVE-2025-38131', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38148&packageName=kernel', 'summary': 'CVE-2025-38148', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38161&packageName=kernel', 'summary': 'CVE-2025-38161', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38183&packageName=kernel', 'summary': 'CVE-2025-38183', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38193&packageName=kernel', 'summary': 'CVE-2025-38193', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38194&packageName=kernel', 'summary': 'CVE-2025-38194', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38241&packageName=kernel', 'summary': 'CVE-2025-38241', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38255&packageName=kernel', 'summary': 'CVE-2025-38255', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38304&packageName=kernel', 'summary': 'CVE-2025-38304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38307&packageName=kernel', 'summary': 'CVE-2025-38307', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38321&packageName=kernel', 'summary': 'CVE-2025-38321', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38344&packageName=kernel', 'summary': 'CVE-2025-38344', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38364&packageName=kernel', 'summary': 'CVE-2025-38364', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38461&packageName=kernel', 'summary': 'CVE-2025-38461', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38462&packageName=kernel', 'summary': 'CVE-2025-38462', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38488&packageName=kernel', 'summary': 'CVE-2025-38488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38499&packageName=kernel', 'summary': 'CVE-2025-38499', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38552&packageName=kernel', 'summary': 'CVE-2025-38552', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38575&packageName=kernel', 'summary': 'CVE-2025-38575', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38609&packageName=kernel', 'summary': 'CVE-2025-38609', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38721&packageName=kernel', 'summary': 'CVE-2025-38721', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39676&packageName=kernel', 'summary': 'CVE-2025-39676', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39682&packageName=kernel', 'summary': 'CVE-2025-39682', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39702&packageName=kernel', 'summary': 'CVE-2025-39702', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39728&packageName=kernel', 'summary': 'CVE-2025-39728', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39756&packageName=kernel', 'summary': 'CVE-2025-39756', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39770&packageName=kernel', 'summary': 'CVE-2025-39770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39812&packageName=kernel', 'summary': 'CVE-2025-39812', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39841&packageName=kernel', 'summary': 'CVE-2025-39841', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39894&packageName=kernel', 'summary': 'CVE-2025-39894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39937&packageName=kernel', 'summary': 'CVE-2025-39937', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39955&packageName=kernel', 'summary': 'CVE-2025-39955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39980&packageName=kernel', 'summary': 'CVE-2025-39980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40018&packageName=kernel', 'summary': 'CVE-2025-40018', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40062&packageName=kernel', 'summary': 'CVE-2025-40062', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40078&packageName=kernel', 'summary': 'CVE-2025-40078', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40136&packageName=kernel', 'summary': 'CVE-2025-40136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40240&packageName=kernel', 'summary': 'CVE-2025-40240', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40254&packageName=kernel', 'summary': 'CVE-2025-40254', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40280&packageName=kernel', 'summary': 'CVE-2025-40280', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40281&packageName=kernel', 'summary': 'CVE-2025-40281', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40331&packageName=kernel', 'summary': 'CVE-2025-40331', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68283&packageName=kernel', 'summary': 'CVE-2025-68283', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68284&packageName=kernel', 'summary': 'CVE-2025-68284', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68285&packageName=kernel', 'summary': 'CVE-2025-68285', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68304&packageName=kernel', 'summary': 'CVE-2025-68304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68740&packageName=kernel', 'summary': 'CVE-2025-68740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68742&packageName=kernel', 'summary': 'CVE-2025-68742', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68795&packageName=kernel', 'summary': 'CVE-2025-68795', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68820&packageName=kernel', 'summary': 'CVE-2025-68820', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-71064&packageName=kernel', 'summary': 'CVE-2025-71064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22976&packageName=kernel', 'summary': 'CVE-2026-22976', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22994&packageName=kernel', 'summary': 'CVE-2026-22994', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23053&packageName=kernel', 'summary': 'CVE-2026-23053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23056&packageName=kernel', 'summary': 'CVE-2026-23056', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23063&packageName=kernel', 'summary': 'CVE-2026-23063', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23253&packageName=kernel', 'summary': 'CVE-2026-23253', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23260&packageName=kernel', 'summary': 'CVE-2026-23260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23268&packageName=kernel', 'summary': 'CVE-2026-23268', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23271&packageName=kernel', 'summary': 'CVE-2026-23271', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23273&packageName=kernel', 'summary': 'CVE-2026-23273', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43407&packageName=kernel', 'summary': 'CVE-2026-43407', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56611', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56760', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21908', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21931', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21971', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21981', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21986', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21995', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22001', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22071', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22077', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23138', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23157', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37748', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37766', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37768', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37771', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37778', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37793', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37805', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37815', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37831', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37844', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37853', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37881', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37889', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37905', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37967', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38037', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38043', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38051', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38113', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38122', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38123', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38131', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38148', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38161', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38183', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38193', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38194', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38241', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38255', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38307', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38321', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38344', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38364', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38461', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38462', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38499', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38552', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38575', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38609', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38721', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39676', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39682', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39702', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39728', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39756', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39812', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39841', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39937', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40018', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40062', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40078', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40240', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40254', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40280', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40281', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40331', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68283', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68284', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68285', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68742', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68795', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68820', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-71064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22976', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22994', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23056', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23063', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23268', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23271', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23273', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43407', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2417.json', 'summary': 'openEuler-SA-2026-2417 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'kernel security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'The Linux Kernel, the operating system core itself.\n\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MMWe currently assume that there is at least one VMA in a MM, which isn ttrue.So we might end up having find_vma() return NULL, to then de-referenceNULL. So properly handle find_vma() returning NULL.This fixes the report:Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTIKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194Code: ...RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8FS: 00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400Call Trace: <TASK> kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709 __do_sys_migrate_pages mm/mempolicy.c:1727 [inline] __se_sys_migrate_pages mm/mempolicy.c:1723 [inline] __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f[akpm@linux-foundation.org: add unlikely()](CVE-2024-56611)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nPCI/MSI: Handle lack of irqdomain gracefully\n\nAlexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a\nRISCV platform which does not provide PCI/MSI support:\n\n WARNING: CPU: 1 PID: 1 at drivers/pci/msi/msi.h:121 pci_msi_setup_msi_irqs+0x2c/0x32\n __pci_enable_msix_range+0x30c/0x596\n pci_msi_setup_msi_irqs+0x2c/0x32\n pci_alloc_irq_vectors_affinity+0xb8/0xe2\n\nRISCV uses hierarchical interrupt domains and correctly does not implement\nthe legacy fallback. The warning triggers from the legacy fallback stub.\n\nThat warning is bogus as the PCI/MSI layer knows whether a PCI/MSI parent\ndomain is associated with the device or not. There is a check for MSI-X,\nwhich has a legacy assumption. But that legacy fallback assumption is only\nvalid when legacy support is enabled, but otherwise the check should simply\nreturn -ENOTSUPP.\n\nLoongarch tripped over the same problem and blindly enabled legacy support\nwithout implementing the legacy fallbacks. There are weak implementations\nwhich return an error, so the problem was papered over.\n\nCorrect pci_msi_domain_supports() to evaluate the legacy mode and add\nthe missing supported check into the MSI enable path to complete it.(CVE-2024-56760)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix nfs_release_folio() to not deadlock via kcompactd writeback\n\nAdd PF_KCOMPACTD flag and current_is_kcompactd() helper to check for it so\nnfs_release_folio() can skip calling nfs_wb_folio() from kcompactd.\n\nOtherwise NFS can deadlock waiting for kcompactd enduced writeback which\nrecurses back to NFS (which triggers writeback to NFSD via NFS loopback\nmount on the same host, NFSD blocks waiting for XFS\'s call to\n__filemap_get_folio):\n\n6070.550357] INFO: task kcompactd0:58 blocked for more than 4435 seconds.\n\n{---\n[58] "kcompactd0"\n[<0>] folio_wait_bit+0xe8/0x200\n[<0>] folio_wait_writeback+0x2b/0x80\n[<0>] nfs_wb_folio+0x80/0x1b0 [nfs]\n[<0>] nfs_release_folio+0x68/0x130 [nfs]\n[<0>] split_huge_page_to_list_to_order+0x362/0x840\n[<0>] migrate_pages_batch+0x43d/0xb90\n[<0>] migrate_pages_sync+0x9a/0x240\n[<0>] migrate_pages+0x93c/0x9f0\n[<0>] compact_zone+0x8e2/0x1030\n[<0>] compact_node+0xdb/0x120\n[<0>] kcompactd+0x121/0x2e0\n[<0>] kthread+0xcf/0x100\n[<0>] ret_from_fork+0x31/0x40\n[<0>] ret_from_fork_asm+0x1a/0x30\n---}\n\n[(CVE-2025-21908)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nhwpoison, memory_hotplug: lock folio before unmap hwpoisoned folio\n\nCommit b15c87263a69 ("hwpoison, memory_hotplug: allow hwpoisoned pages to\nbe offlined) add page poison checks in do_migrate_range in order to make\noffline hwpoisoned page possible by introducing isolate_lru_page and\ntry_to_unmap for hwpoisoned page. However folio lock must be held before\ncalling try_to_unmap. Add it to fix this problem.\n\nWarning will be produced if folio is not locked during unmap:\n\n ------------[ cut here ]------------\n kernel BUG at ./include/linux/swapops.h:400!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 4 UID: 0 PID: 411 Comm: bash Tainted: G W 6.13.0-rc1-00016-g3c434c7ee82a-dirty #41\n Tainted: [W]=WARN\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : try_to_unmap_one+0xb08/0xd3c\n lr : try_to_unmap_one+0x3dc/0xd3c\n Call trace:\n try_to_unmap_one+0xb08/0xd3c (P)\n try_to_unmap_one+0x3dc/0xd3c (L)\n rmap_walk_anon+0xdc/0x1f8\n rmap_walk+0x3c/0x58\n try_to_unmap+0x88/0x90\n unmap_poisoned_folio+0x30/0xa8\n do_migrate_range+0x4a0/0x568\n offline_pages+0x5a4/0x670\n memory_block_action+0x17c/0x374\n memory_subsys_offline+0x3c/0x78\n device_offline+0xa4/0xd0\n state_store+0x8c/0xf0\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x44/0x54\n kernfs_fop_write_iter+0x118/0x1a8\n vfs_write+0x3a8/0x4bc\n ksys_write+0x6c/0xf8\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xd0\n el0t_64_sync_handler+0xc8/0xcc\n el0t_64_sync+0x198/0x19c\n Code: f9407be0 b5fff320 d4210000 17ffff97 (d4210000)\n ---[ end trace 0000000000000000 ]---(CVE-2025-21931)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Bridge, fix the crash caused by LAG state check\n\nWhen removing LAG device from bridge, NETDEV_CHANGEUPPER event is\ntriggered. Driver finds the lower devices (PFs) to flush all the\noffloaded entries. And mlx5_lag_is_shared_fdb is checked, it returns\nfalse if one of PF is unloaded. In such case,\nmlx5_esw_bridge_lag_rep_get() and its caller return NULL, instead of\nthe alive PF, and the flush is skipped.\n\nBesides, the bridge fdb entry\'s lastuse is updated in mlx5 bridge\nevent handler. But this SWITCHDEV_FDB_ADD_TO_BRIDGE event can be\nignored in this case because the upper interface for bond is deleted,\nand the entry will never be aged because lastuse is never updated.\n\nTo make things worse, as the entry is alive, mlx5 bridge workqueue\nkeeps sending that event, which is then handled by kernel bridge\nnotifier. It causes the following crash when accessing the passed bond\nnetdev which is already destroyed.\n\nTo fix this issue, remove such checks. LAG state is already checked in\ncommit 15f8f168952f ("net/mlx5: Bridge, verify LAG state when adding\nbond to bridge"), driver still need to skip offload if LAG becomes\ninvalid state after initialization.\n\n Oops: stack segment: 0000 [#1] SMP\n CPU: 3 UID: 0 PID: 23695 Comm: kworker/u40:3 Tainted: G OE 6.11.0_mlnx #1\n Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5_bridge_wq mlx5_esw_bridge_update_work [mlx5_core]\n RIP: 0010:br_switchdev_event+0x2c/0x110 [bridge]\n Code: 44 00 00 48 8b 02 48 f7 00 00 02 00 00 74 69 41 54 55 53 48 83 ec 08 48 8b a8 08 01 00 00 48 85 ed 74 4a 48 83 fe 02 48 89 d3 <4c> 8b 65 00 74 23 76 49 48 83 fe 05 74 7e 48 83 fe 06 75 2f 0f b7\n RSP: 0018:ffffc900092cfda0 EFLAGS: 00010297\n RAX: ffff888123bfe000 RBX: ffffc900092cfe08 RCX: 00000000ffffffff\n RDX: ffffc900092cfe08 RSI: 0000000000000001 RDI: ffffffffa0c585f0\n RBP: 6669746f6e690a30 R08: 0000000000000000 R09: ffff888123ae92c8\n R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888123ae9c60\n R13: 0000000000000001 R14: ffffc900092cfe08 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff88852c980000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f15914c8734 CR3: 0000000002830005 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n <TASK>\n ? __die_body+0x1a/0x60\n ? die+0x38/0x60\n ? do_trap+0x10b/0x120\n ? do_error_trap+0x64/0xa0\n ? exc_stack_segment+0x33/0x50\n ? asm_exc_stack_segment+0x22/0x30\n ? br_switchdev_event+0x2c/0x110 [bridge]\n ? sched_balance_newidle.isra.149+0x248/0x390\n notifier_call_chain+0x4b/0xa0\n atomic_notifier_call_chain+0x16/0x20\n mlx5_esw_bridge_update+0xec/0x170 [mlx5_core]\n mlx5_esw_bridge_update_work+0x19/0x40 [mlx5_core]\n process_scheduled_works+0x81/0x390\n worker_thread+0x106/0x250\n ? bh_worker+0x110/0x110\n kthread+0xb7/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n </TASK>(CVE-2025-21970)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: Prevent creation of classes with TC_H_ROOT\n\nThe function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination\ncondition when traversing up the qdisc tree to update parent backlog\ncounters. However, if a class is created with classid TC_H_ROOT, the\ntraversal terminates prematurely at this class instead of reaching the\nactual root qdisc, causing parent statistics to be incorrectly maintained.\nIn case of DRR, this could lead to a crash as reported by Mingi Cho.\n\nPrevent the creation of any Qdisc class with classid TC_H_ROOT\n(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.(CVE-2025-21971)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsched: address a potential NULL pointer dereference in the GRED scheduler.\n\nIf kzalloc in gred_init returns a NULL pointer, the code follows the\nerror handling path, invoking gred_destroy. This, in turn, calls\ngred_offload, where memset could receive a NULL pointer as input,\npotentially leading to a kernel crash.\n\nWhen table->opt is NULL in gred_init(), gred_change_table_def()\nis not called yet, so it is not necessary to call ->ndo_setup_tc()\nin gred_offload().(CVE-2025-21980)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nice: fix memory leak in aRFS after reset\n\nFix aRFS (accelerated Receive Flow Steering) structures memory leak by\nadding a checker to verify if aRFS memory is already allocated while\nconfiguring VSI. aRFS objects are allocated in two cases:\n- as part of VSI initialization (at probe), and\n- as part of reset handling\n\nHowever, VSI reconfiguration executed during reset involves memory\nallocation one more time, without prior releasing already allocated\nresources. This led to the memory leak with the following signature:\n\n[root@os-delivery ~]# cat /sys/kernel/debug/kmemleak\nunreferenced object 0xff3c1ca7252e6000 (size 8192):\n comm "kworker/0:0", pid 8, jiffies 4296833052\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 0):\n [<ffffffff991ec485>] __kmalloc_cache_noprof+0x275/0x340\n [<ffffffffc0a6e06a>] ice_init_arfs+0x3a/0xe0 [ice]\n [<ffffffffc09f1027>] ice_vsi_cfg_def+0x607/0x850 [ice]\n [<ffffffffc09f244b>] ice_vsi_setup+0x5b/0x130 [ice]\n [<ffffffffc09c2131>] ice_init+0x1c1/0x460 [ice]\n [<ffffffffc09c64af>] ice_probe+0x2af/0x520 [ice]\n [<ffffffff994fbcd3>] local_pci_probe+0x43/0xa0\n [<ffffffff98f07103>] work_for_cpu_fn+0x13/0x20\n [<ffffffff98f0b6d9>] process_one_work+0x179/0x390\n [<ffffffff98f0c1e9>] worker_thread+0x239/0x340\n [<ffffffff98f14abc>] kthread+0xcc/0x100\n [<ffffffff98e45a6d>] ret_from_fork+0x2d/0x50\n [<ffffffff98e083ba>] ret_from_fork_asm+0x1a/0x30\n ...(CVE-2025-21981)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: switchdev: Convert blocking notification chain to a raw one\n\nA blocking notification chain uses a read-write semaphore to protect the\nintegrity of the chain. The semaphore is acquired for writing when\nadding / removing notifiers to / from the chain and acquired for reading\nwhen traversing the chain and informing notifiers about an event.\n\nIn case of the blocking switchdev notification chain, recursive\nnotifications are possible which leads to the semaphore being acquired\ntwice for reading and to lockdep warnings being generated [1].\n\nSpecifically, this can happen when the bridge driver processes a\nSWITCHDEV_BRPORT_UNOFFLOADED event which causes it to emit notifications\nabout deferred events when calling switchdev_deferred_process().\n\nFix this by converting the notification chain to a raw notification\nchain in a similar fashion to the netdev notification chain. Protect\nthe chain using the RTNL mutex by acquiring it when modifying the chain.\nEvents are always informed under the RTNL mutex, but add an assertion in\ncall_switchdev_blocking_notifiers() to make sure this is not violated in\nthe future.\n\nMaintain the "blocking" prefix as events are always emitted from process\ncontext and listeners are allowed to block.\n\n[1]:\nWARNING: possible recursive locking detected\n6.14.0-rc4-custom-g079270089484 #1 Not tainted\n--------------------------------------------\nip/52731 is trying to acquire lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nbut task is already holding lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nother info that might help us debug this:\nPossible unsafe locking scenario:\nCPU0\n----\nlock((switchdev_blocking_notif_chain).rwsem);\nlock((switchdev_blocking_notif_chain).rwsem);\n\n*** DEADLOCK ***\nMay be due to missing lock nesting notation\n3 locks held by ip/52731:\n #0: ffffffff84f795b0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x727/0x1dc0\n #1: ffffffff8731f628 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x790/0x1dc0\n #2: ffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nstack backtrace:\n...\n? __pfx_down_read+0x10/0x10\n? __pfx_mark_lock+0x10/0x10\n? __pfx_switchdev_port_attr_set_deferred+0x10/0x10\nblocking_notifier_call_chain+0x58/0xa0\nswitchdev_port_attr_notify.constprop.0+0xb3/0x1b0\n? __pfx_switchdev_port_attr_notify.constprop.0+0x10/0x10\n? mark_held_locks+0x94/0xe0\n? switchdev_deferred_process+0x11a/0x340\nswitchdev_port_attr_set_deferred+0x27/0xd0\nswitchdev_deferred_process+0x164/0x340\nbr_switchdev_port_unoffload+0xc8/0x100 [bridge]\nbr_switchdev_blocking_event+0x29f/0x580 [bridge]\nnotifier_call_chain+0xa2/0x440\nblocking_notifier_call_chain+0x6e/0xa0\nswitchdev_bridge_port_unoffload+0xde/0x1a0\n...(CVE-2025-21986)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: Fix fence reference count leak\n\nThe last_scheduled fence leaks when an entity is being killed and adding\nthe cleanup callback fails.\n\nDecrement the reference count of prev when dma_fence_add_callback()\nfails, ensuring proper balance.\n\n[phasta: add git tag info for stable kernel](CVE-2025-21995)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Fix integer overflow in qaic_validate_req()\n\nThese are u64 variables that come from the user via\nqaic_attach_slice_bo_ioctl(). Use check_add_overflow() to ensure that\nthe math doesn\'t have an integer wrapping bug.(CVE-2025-22001)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nregulator: dummy: force synchronous probing\n\nSometimes I get a NULL pointer dereference at boot time in kobject_get()\nwith the following call stack:\n\nanatop_regulator_probe()\n devm_regulator_register()\n regulator_register()\n regulator_resolve_supply()\n kobject_get()\n\nBy placing some extra BUG_ON() statements I could verify that this is\nraised because probing of the \'dummy\' regulator driver is not completed\n(\'dummy_regulator_rdev\' is still NULL).\n\nIn the JTAG debugger I can see that dummy_regulator_probe() and\nanatop_regulator_probe() can be run by different kernel threads\n(kworker/u4:*). I haven\'t further investigated whether this can be\nchanged or if there are other possibilities to force synchronization\nbetween these two probe routines. On the other hand I don\'t expect much\nboot time penalty by probing the \'dummy\' regulator synchronously.(CVE-2025-22009)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix a leak in spufs_create_context()\n\nLeak fixes back in 2008 missed one case - if we are trying to set affinity\nand spufs_mkdir() fails, we need to drop the reference to neighbor.(CVE-2025-22071)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRevert "smb: client: fix TCP timers deadlock after rmmod"\n\nThis reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.\n\nCommit e9f2517a3e18 ("smb: client: fix TCP timers deadlock after\nrmmod") is intended to fix a null-ptr-deref in LOCKDEP, which is\nmentioned as CVE-2024-54680, but is actually did not fix anything;\nThe issue can be reproduced on top of it. [0]\n\nAlso, it reverted the change by commit ef7134c7fc48 ("smb: client:\nFix use-after-free of network namespace.") and introduced a real\nissue by reviving the kernel TCP socket.\n\nWhen a reconnect happens for a CIFS connection, the socket state\ntransitions to FIN_WAIT_1. Then, inet_csk_clear_xmit_timers_sync()\nin tcp_close() stops all timers for the socket.\n\nIf an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1\nforever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.\n\nUsually, FIN can be retransmitted by the peer, but if the peer aborts\nthe connection, the issue comes into reality.\n\nI warned about this privately by pointing out the exact report [1],\nbut the bogus fix was finally merged.\n\nSo, we should not stop the timers to finally kill the connection on\nour side in that case, meaning we must not use a kernel socket for\nTCP whose sk->sk_net_refcnt is 0.\n\nThe kernel socket does not have a reference to its netns to make it\npossible to tear down netns without cleaning up every resource in it.\n\nFor example, tunnel devices use a UDP socket internally, but we can\ndestroy netns without removing such devices and let it complete\nduring exit. Otherwise, netns would be leaked when the last application\ndied.\n\nHowever, this is problematic for TCP sockets because TCP has timers to\nclose the connection gracefully even after the socket is close()d. The\nlifetime of the socket and its netns is different from the lifetime of\nthe underlying connection.\n\nIf the socket user does not maintain the netns lifetime, the timer could\nbe fired after the socket is close()d and its netns is freed up, resulting\nin use-after-free.\n\nActually, we have seen so many similar issues and converted such sockets\nto have a reference to netns.\n\nThat\'s why I converted the CIFS client socket to have a reference to\nnetns (sk->sk_net_refcnt == 1), which is somehow mentioned as out-of-scope\nof CIFS and technically wrong in e9f2517a3e18, but **is in-scope and right\nfix**.\n\nRegarding the LOCKDEP issue, we can prevent the module unload by\nbumping the module refcount when switching the LOCKDDEP key in\nsock_lock_init_class_and_name(). [2]\n\nFor a while, let\'s revert the bogus fix.\n\nNote that now we can use sk_net_refcnt_upgrade() for the socket\nconversion, but I\'ll do so later separately to make backport easy.(CVE-2025-22077)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwatch_queue: fix pipe accounting mismatch\n\nCurrently, watch_queue_set_size() modifies the pipe buffers charged to\nuser->pipe_bufs without updating the pipe->nr_accounted on the pipe\nitself, due to the if (!pipe_has_watch_queue()) test in\npipe_resize_ring(). This means that when the pipe is ultimately freed,\nwe decrement user->pipe_bufs by something other than what than we had\ncharged to it, potentially leading to an underflow. This in turn can\ncause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM.\n\nTo remedy this, explicitly account for the pipe usage in\nwatch_queue_set_size() to match the number set via account_pipe_buffers()\n\n(It\'s unclear why watch_queue_set_size() does not update nr_accounted;\nit may be due to intentional overprovisioning in watch_queue_set_size()?)(CVE-2025-23138)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: add check to avoid out of bound access\n\nThere is a possibility that init_codecs is invoked multiple times during\nmanipulated payload from video firmware. In such case, if codecs_count\ncan get incremented to value more than MAX_CODEC_NUM, there can be OOB\naccess. Reset the count so that it always starts from beginning.(CVE-2025-23157)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\njfs: add sanity check for agwidth in dbMount\n\nThe width in dmapctl of the AG is zero, it trigger a divide error when\ncalculating the control page level in dbAllocAG.\n\nTo avoid this issue, add a check for agwidth in dbAllocAG.(CVE-2025-37740)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\niommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group\n\nCurrently, mtk_iommu calls during probe iommu_device_register before\nthe hw_list from driver data is initialized. Since iommu probing issue\nfix, it leads to NULL pointer dereference in mtk_iommu_device_group when\nhw_list is accessed with list_first_entry (not null safe).\n\nSo, change the call order to ensure iommu_device_register is called\nafter the driver data are initialized.(CVE-2025-37748)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37766)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37768)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37770)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37771)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Fix dangling pointer in krb_authenticate\n\nkrb_authenticate frees sess->user and does not set the pointer\nto NULL. It calls ksmbd_krb5_authenticate to reinitialise\nsess->user but that function may return without doing so. If\nthat happens then smb2_sess_setup, which calls krb_authenticate,\nwill be accessing free\'d memory when it later uses sess->user.(CVE-2025-37778)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\navs_component_probe() does not check for this case, which results in a\nNULL pointer dereference.(CVE-2025-37793)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsound/virtio: Fix cancel_sync warnings on uninitialized work_structs\n\nBetty reported hitting the following warning:\n\n[ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182\n...\n[ 8.713282][ T221] Call trace:\n[ 8.713365][ T221] __flush_work+0x8d0/0x914\n[ 8.713468][ T221] __cancel_work_sync+0xac/0xfc\n[ 8.713570][ T221] cancel_work_sync+0x24/0x34\n[ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.714035][ T221] virtio_dev_probe+0x28c/0x390\n[ 8.714139][ T221] really_probe+0x1bc/0x4c8\n...\n\nIt seems we\'re hitting the error path in virtsnd_probe(), which\ntriggers a virtsnd_remove() which iterates over the substreams\ncalling cancel_work_sync() on the elapsed_period work_struct.\n\nLooking at the code, from earlier in:\nvirtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg()\n\nWe set snd->nsubstreams, allocate the snd->substreams, and if\nwe then hit an error on the info allocation or something in\nvirtsnd_ctl_query_info() fails, we will exit without having\ninitialized the elapsed_period work_struct.\n\nWhen that error path unwinds we then call virtsnd_remove()\nwhich as long as the substreams array is allocated, will iterate\nthrough calling cancel_work_sync() on the uninitialized work\nstruct hitting this warning.\n\nTakashi Iwai suggested this fix, which initializes the substreams\nstructure right after allocation, so that if we hit the error\npaths we avoid trying to cleanup uninitialized data.\n\nNote: I have not yet managed to reproduce the issue myself, so\nthis patch has had limited testing.\n\nFeedback or thoughts would be appreciated!(CVE-2025-37805)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration\n\nResolve kernel panic while accessing IRQ handler associated with the\ngenerated IRQ. This is done by acquiring the spinlock and storing the\ncurrent interrupt state before handling the interrupt request using\ngeneric_handle_irq.\n\nA previous fix patch was submitted where \'generic_handle_irq\' was\nreplaced with \'handle_nested_irq\'. However, this change also causes\nthe kernel panic where after determining which GPIO triggered the\ninterrupt and attempting to call handle_nested_irq with the mapped\nIRQ number, leads to a failure in locating the registered handler.(CVE-2025-37815)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check\nfor this case, which results in a NULL pointer dereference.(CVE-2025-37831)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncifs: avoid NULL pointer dereference in dbg call\n\ncifs_server_dbg() implies server to be non-NULL so\nmove call under condition to avoid NULL pointer dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37844)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: debugfs hang_hws skip GPU with MES\n\ndebugfs hang_hws is used by GPU reset test with HWS, for MES this crash\nthe kernel with NULL pointer access because dqm->packet_mgr is not setup\nfor MES path.\n\nSkip GPU with MES for now, MES hang_hws debugfs interface will be\nsupported later.(CVE-2025-37853)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()\n\nThe variable d->name, returned by devm_kasprintf(), could be NULL.\nA pointer check is added to prevent potential NULL pointer dereference.\nThis is similar to the fix in commit 3027e7b15b02\n("ice: Fix some null pointer dereference issues in ice_ptp.c").\n\nThis issue is found by our static analysis tool(CVE-2025-37881)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Consistently treat platform_max as control value\n\nThis reverts commit 9bdd10d57a88 ("ASoC: ops: Shift tested values in\nsnd_soc_put_volsw() by +min"), and makes some additional related\nupdates.\n\nThere are two ways the platform_max could be interpreted; the maximum\nregister value, or the maximum value the control can be set to. The\npatch moved from treating the value as a control value to a register\none. When the patch was applied it was technically correct as\nsnd_soc_limit_volume() also used the register interpretation. However,\neven then most of the other usages treated platform_max as a\ncontrol value, and snd_soc_limit_volume() has since been updated to\nalso do so in commit fb9ad24485087 ("ASoC: ops: add correct range\ncheck for limiting volume"). That patch however, missed updating\nsnd_soc_put_volsw() back to the control interpretation, and fixing\nsnd_soc_info_volsw_range(). The control interpretation makes more\nsense as limiting is typically done from the machine driver, so it is\nappropriate to use the customer facing representation rather than the\ninternal codec representation. Update all the code to consistently use\nthis interpretation of platform_max.\n\nFinally, also add some comments to the soc_mixer_control struct to\nhopefully avoid further patches switching between the two approaches.(CVE-2025-37889)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Balance device refcount when destroying devices\n\nUsing device_find_child() to lookup the proper SCMI device to destroy\ncauses an unbalance in device refcount, since device_find_child() calls an\nimplicit get_device(): this, in turns, inhibits the call of the provided\nrelease methods upon devices destruction.\n\nAs a consequence, one of the structures that is not freed properly upon\ndestruction is the internal struct device_private dev->p populated by the\ndrivers subsystem core.\n\nKMemleak detects this situation since loading/unloding some SCMI driver\ncauses related devices to be created/destroyed without calling any\ndevice_release method.\n\nunreferenced object 0xffff00000f583800 (size 512):\n comm "insmod", pid 227, jiffies 4294912190\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 60 36 1d 8a 00 80 ff ff ........`6......\n backtrace (crc 114e2eed):\n kmemleak_alloc+0xbc/0xd8\n __kmalloc_cache_noprof+0x2dc/0x398\n device_add+0x954/0x12d0\n device_register+0x28/0x40\n __scmi_device_create.part.0+0x1bc/0x380\n scmi_device_create+0x2d0/0x390\n scmi_create_protocol_devices+0x74/0xf8\n scmi_device_request_notifier+0x1f8/0x2a8\n notifier_call_chain+0x110/0x3b0\n blocking_notifier_call_chain+0x70/0xb0\n scmi_driver_register+0x350/0x7f0\n 0xffff80000a3b3038\n do_one_initcall+0x12c/0x730\n do_init_module+0x1dc/0x640\n load_module+0x4b20/0x5b70\n init_module_from_file+0xec/0x158\n\n$ ./scripts/faddr2line ./vmlinux device_add+0x954/0x12d0\ndevice_add+0x954/0x12d0:\nkmalloc_noprof at include/linux/slab.h:901\n(inlined by) kzalloc_noprof at include/linux/slab.h:1037\n(inlined by) device_private_init at drivers/base/core.c:3510\n(inlined by) device_add at drivers/base/core.c:3561\n\nBalance device refcount by issuing a put_device() on devices found via\ndevice_find_child().(CVE-2025-37905)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()\n\nA NULL pointer dereference can occur in skb_dequeue() when processing a\nQCA firmware crash dump on WCN7851 (0489:e0f3).\n\n[ 93.672166] Bluetooth: hci0: ACL memdump size(589824)\n\n[ 93.672475] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[ 93.672517] Workqueue: hci0 hci_devcd_rx [bluetooth]\n[ 93.672598] RIP: 0010:skb_dequeue+0x50/0x80\n\nThe issue stems from handle_dump_pkt_qca() returning 0 even when a dump\npacket is successfully processed. This is because it incorrectly\nforwards the return value of hci_devcd_init() (which returns 0 on\nsuccess). As a result, the caller (btusb_recv_acl_qca() or\nbtusb_recv_evt_qca()) assumes the packet was not handled and passes it\nto hci_recv_frame(), leading to premature kfree() of the skb.\n\nLater, hci_devcd_rx() attempts to dequeue the same skb from the dump\nqueue, resulting in a NULL pointer dereference.\n\nFix this by:\n1. Making handle_dump_pkt_qca() return 0 on success and negative errno\n on failure, consistent with kernel conventions.\n2. Splitting dump packet detection into separate functions for ACL\n and event packets for better structure and readability.\n\nThis ensures dump packets are properly identified and consumed, avoiding\ndouble handling and preventing NULL pointer access.(CVE-2025-37918)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent out-of-bounds stream writes by validating *pos\n\nksmbd_vfs_stream_write() did not validate whether the write offset\n(*pos) was within the bounds of the existing stream data length (v_len).\nIf *pos was greater than or equal to v_len, this could lead to an\nout-of-bounds memory write.\n\nThis patch adds a check to ensure *pos is less than v_len before\nproceeding. If the condition fails, -EINVAL is returned.(CVE-2025-37947)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: displayport: Fix deadlock\n\nThis patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock\nfunctions to the UCSI driver. ucsi_con_mutex_lock ensures the connector\nmutex is only locked if a connection is established and the partner pointer\nis valid. This resolves a deadlock scenario where\nucsi_displayport_remove_partner holds con->mutex waiting for\ndp_altmode_work to complete while dp_altmode_work attempts to acquire it.(CVE-2025-37967)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Refactor remove call with idxd_cleanup() helper\n\nThe idxd_cleanup() helper cleans up perfmon, interrupts, internals and\nso on. Refactor remove call with the idxd_cleanup() helper to avoid code\nduplication. Note, this also fixes the missing put_device() for idxd\ngroups, enginces and wqs.(CVE-2025-38014)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Annotate FDB data races\n\nThe \'used\' and \'updated\' fields in the FDB entry structure can be\naccessed concurrently by multiple threads, leading to reports such as\n[1]. Can be reproduced using [2].\n\nSuppress these reports by annotating these accesses using\nREAD_ONCE() / WRITE_ONCE().\n\n[1]\nBUG: KCSAN: data-race in vxlan_xmit / vxlan_xmit\n\nwrite to 0xffff942604d263a8 of 8 bytes by task 286 on cpu 0:\n vxlan_xmit+0xb29/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff942604d263a8 of 8 bytes by task 287 on cpu 2:\n vxlan_xmit+0xadf/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000000fffbac6e -> 0x00000000fffbac6f\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 2 UID: 0 PID: 287 Comm: mausezahn Not tainted 6.13.0-rc7-01544-gb4b270f11a02 #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014\n\n[2]\n #!/bin/bash\n\n set +H\n echo whitelist > /sys/kernel/debug/kcsan\n echo !vxlan_xmit > /sys/kernel/debug/kcsan\n\n ip link add name vx0 up type vxlan id 10010 dstport 4789 local 192.0.2.1\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 198.51.100.1\n taskset -c 0 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &\n taskset -c 2 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &(CVE-2025-38037)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Set dma_mask for ffa devices\n\nSet dma_mask for FFA devices, otherwise DMA allocation using the device pointer\nlead to following warning:\n\nWARNING: CPU: 1 PID: 1 at kernel/dma/mapping.c:597 dma_alloc_attrs+0xe0/0x124(CVE-2025-38043)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_fill_dirent\n\nThere is a race condition in the readdir concurrency process, which may\naccess the rsp buffer after it has been released, triggering the\nfollowing KASAN warning.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03/0xb60 [cifs]\n Read of size 4 at addr ffff8880099b819c by task a.out/342975\n\n CPU: 2 UID: 0 PID: 342975 Comm: a.out Not tainted 6.15.0-rc6+ #240 PREEMPT(full)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\n Call Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n print_report+0xce/0x640\n kasan_report+0xb8/0xf0\n cifs_fill_dirent+0xb03/0xb60 [cifs]\n cifs_readdir+0x12cb/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f996f64b9f9\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01\n f0 ff ff 0d f7 c3 0c 00 f7 d8 64 89 8\n RSP: 002b:00007f996f53de78 EFLAGS: 00000207 ORIG_RAX: 000000000000004e\n RAX: ffffffffffffffda RBX: 00007f996f53ecdc RCX: 00007f996f64b9f9\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007f996f53dea0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000207 R12: ffffffffffffff88\n R13: 0000000000000000 R14: 00007ffc8cd9a500 R15: 00007f996f51e000\n </TASK>\n\n Allocated by task 408:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x6e/0x70\n kmem_cache_alloc_noprof+0x117/0x3d0\n mempool_alloc_noprof+0xf2/0x2c0\n cifs_buf_get+0x36/0x80 [cifs]\n allocate_buffers+0x1d2/0x330 [cifs]\n cifs_demultiplex_thread+0x22b/0x2690 [cifs]\n kthread+0x394/0x720\n ret_from_fork+0x34/0x70\n ret_from_fork_asm+0x1a/0x30\n\n Freed by task 342979:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x37/0x50\n kmem_cache_free+0x2b8/0x500\n cifs_buf_release+0x3c/0x70 [cifs]\n cifs_readdir+0x1c97/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents64+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n The buggy address belongs to the object at ffff8880099b8000\n which belongs to the cache cifs_request of size 16588\n The buggy address is located 412 bytes inside of\n freed 16588-byte region [ffff8880099b8000, ffff8880099bc0cc)\n\n The buggy address belongs to the physical page:\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x99b8\n head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n anon flags: 0x80000000000040(head|node=0|zone=1)\n page_type: f5(slab)\n raw: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n raw: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n head: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000003 ffffea0000266e01 00000000ffffffff 00000000ffffffff\n head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8880099b8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8880099b8180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8880099b8200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\nPOC is available in the link [1].\n\nThe problem triggering process is as follows:\n\nProcess 1 Process 2\n-----------------------------------\n---truncated---(CVE-2025-38051)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()\n\nHongyu reported a hang on kexec in a VM. QEMU reported invalid memory\naccesses during the hang.\n\n\tInvalid read at addr 0x102877002, size 2, region \'(null)\', reason: rejected\n\tInvalid write at addr 0x102877A44, size 2, region \'(null)\', reason: rejected\n\t...\n\nIt was traced down to virtio-console. Kexec works fine if virtio-console\nis not in use.\n\nThe issue is that virtio-console continues to write to the MMIO even after\nunderlying virtio-pci device is reset.\n\nAdditionally, Eric noticed that IOMMUs are reset before devices, if\ndevices are not reset on shutdown they continue to poke at guest memory\nand get errors from the IOMMU. Some devices get wedged then.\n\nThe problem can be solved by breaking all virtio devices on virtio\nbus shutdown, then resetting them.(CVE-2025-38064)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Fix NULL pointer dereference when nosmp is used\n\nWith nosmp in cmdline, other CPUs are not brought up, leaving\ntheir cpc_desc_ptr NULL. CPU0\'s iteration via for_each_possible_cpu()\ndereferences these NULL pointers, causing panic.\n\nPanic backtrace:\n\n[ 0.401123] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b8\n...\n[ 0.403255] [<ffffffff809a5818>] cppc_allow_fast_switch+0x6a/0xd4\n...\nKernel panic - not syncing: Attempted to kill init!\n\n[ rjw: New subject ](CVE-2025-38113)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ngve: add missing NULL check for gve_alloc_pending_packet() in TX DQO\n\ngve_alloc_pending_packet() can return NULL, but gve_tx_add_skb_dqo()\ndid not check for this case before dereferencing the returned pointer.\n\nAdd a missing NULL check to prevent a potential NULL pointer\ndereference when allocation fails.\n\nThis improves robustness in low-memory scenarios.(CVE-2025-38122)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: Fix napi rx poll issue\n\nWhen driver handles the napi rx polling requests, the netdev might\nhave been released by the dellink logic triggered by the disconnect\noperation on user plane. However, in the logic of processing skb in\npolling, an invalid netdev is still being used, which causes a panic.\n\nBUG: kernel NULL pointer dereference, address: 00000000000000f1\nOops: 0000 [#1] PREEMPT SMP NOPTI\nRIP: 0010:dev_gro_receive+0x3a/0x620\n[...]\nCall Trace:\n <IRQ>\n ? __die_body+0x68/0xb0\n ? page_fault_oops+0x379/0x3e0\n ? exc_page_fault+0x4f/0xa0\n ? asm_exc_page_fault+0x22/0x30\n ? __pfx_t7xx_ccmni_recv_skb+0x10/0x10 [mtk_t7xx (HASH:1400 7)]\n ? dev_gro_receive+0x3a/0x620\n napi_gro_receive+0xad/0x170\n t7xx_ccmni_recv_skb+0x48/0x70 [mtk_t7xx (HASH:1400 7)]\n t7xx_dpmaif_napi_rx_poll+0x590/0x800 [mtk_t7xx (HASH:1400 7)]\n net_rx_action+0x103/0x470\n irq_exit_rcu+0x13a/0x310\n sysvec_apic_timer_interrupt+0x56/0x90\n </IRQ>(CVE-2025-38123)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: prevent deactivate active config while enabling the config\n\nWhile enable active config via cscfg_csdev_enable_active_config(),\nactive config could be deactivated via configfs\' sysfs interface.\nThis could make UAF issue in below scenario:\n\nCPU0 CPU1\n(sysfs enable) load module\n cscfg_load_config_sets()\n activate config. // sysfs\n (sys_active_cnt == 1)\n...\ncscfg_csdev_enable_active_config()\nlock(csdev->cscfg_csdev_lock)\n// here load config activate by CPU1\nunlock(csdev->cscfg_csdev_lock)\n\n deactivate config // sysfs\n (sys_activec_cnt == 0)\n cscfg_unload_config_sets()\n unload module\n\n// access to config_desc which freed\n// while unloading module.\ncscfg_csdev_enable_config\n\nTo address this, use cscfg_config_desc\'s active_cnt as a reference count\n which will be holded when\n - activate the config.\n - enable the activated config.\nand put the module reference when config_active_cnt == 0.(CVE-2025-38131)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: mscc: Fix memory leak when using one step timestamping\n\nFix memory leak when running one-step timestamping. When running\none-step sync timestamping, the HW is configured to insert the TX time\ninto the frame, so there is no reason to keep the skb anymore. As in\nthis case the HW will never generate an interrupt to say that the frame\nwas timestamped, then the frame will never released.\nFix this by freeing the frame in case of one-step timestamping.(CVE-2025-38148)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix error flow upon firmware failure for RQ destruction\n\nUpon RQ destruction if the firmware command fails which is the\nlast resource to be destroyed some SW resources were already cleaned\nregardless of the failure.\n\nNow properly rollback the object to its original state upon such failure.\n\nIn order to avoid a use-after free in case someone tries to destroy the\nobject again, which results in the following kernel trace:\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 0 PID: 37589 at lib/refcount.c:28 refcount_warn_saturate+0xf4/0x148\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) rfkill mlx5_core(OE) mlxdevm(OE) ib_uverbs(OE) ib_core(OE) psample mlxfw(OE) mlx_compat(OE) macsec tls pci_hyperv_intf sunrpc vfat fat virtio_net net_failover failover fuse loop nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_console virtio_gpu virtio_blk virtio_dma_buf virtio_mmio dm_mirror dm_region_hash dm_log dm_mod xpmem(OE)\nCPU: 0 UID: 0 PID: 37589 Comm: python3 Kdump: loaded Tainted: G OE ------- --- 6.12.0-54.el10.aarch64 #1\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : refcount_warn_saturate+0xf4/0x148\nlr : refcount_warn_saturate+0xf4/0x148\nsp : ffff80008b81b7e0\nx29: ffff80008b81b7e0 x28: ffff000133d51600 x27: 0000000000000001\nx26: 0000000000000000 x25: 00000000ffffffea x24: ffff00010ae80f00\nx23: ffff00010ae80f80 x22: ffff0000c66e5d08 x21: 0000000000000000\nx20: ffff0000c66e0000 x19: ffff00010ae80340 x18: 0000000000000006\nx17: 0000000000000000 x16: 0000000000000020 x15: ffff80008b81b37f\nx14: 0000000000000000 x13: 2e656572662d7265 x12: ffff80008283ef78\nx11: ffff80008257efd0 x10: ffff80008283efd0 x9 : ffff80008021ed90\nx8 : 0000000000000001 x7 : 00000000000bffe8 x6 : c0000000ffff7fff\nx5 : ffff0001fb8e3408 x4 : 0000000000000000 x3 : ffff800179993000\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000133d51600\nCall trace:\n refcount_warn_saturate+0xf4/0x148\n mlx5_core_put_rsc+0x88/0xa0 [mlx5_ib]\n mlx5_core_destroy_rq_tracked+0x64/0x98 [mlx5_ib]\n mlx5_ib_destroy_wq+0x34/0x80 [mlx5_ib]\n ib_destroy_wq_user+0x30/0xc0 [ib_core]\n uverbs_free_wq+0x28/0x58 [ib_uverbs]\n destroy_hw_idr_uobject+0x34/0x78 [ib_uverbs]\n uverbs_destroy_uobject+0x48/0x240 [ib_uverbs]\n __uverbs_cleanup_ufile+0xd4/0x1a8 [ib_uverbs]\n uverbs_destroy_ufile_hw+0x48/0x120 [ib_uverbs]\n ib_uverbs_close+0x2c/0x100 [ib_uverbs]\n __fput+0xd8/0x2f0\n __fput_sync+0x50/0x70\n __arm64_sys_close+0x40/0x90\n invoke_syscall.constprop.0+0x74/0xd0\n do_el0_svc+0x48/0xe8\n el0_svc+0x44/0x1d0\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x1a4/0x1a8(CVE-2025-38161)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()\n\nBefore calling lan743x_ptp_io_event_clock_get(), the \'channel\' value\nis checked against the maximum value of PCI11X1X_PTP_IO_MAX_CHANNELS(8).\nThis seems correct and aligns with the PTP interrupt status register\n(PTP_INT_STS) specifications.\n\nHowever, lan743x_ptp_io_event_clock_get() writes to ptp->extts[] with\nonly LAN743X_PTP_N_EXTTS(4) elements, using channel as an index:\n\n lan743x_ptp_io_event_clock_get(..., u8 channel,...)\n {\n ...\n /* Update Local timestamp */\n extts = &ptp->extts[channel];\n extts->ts.tv_sec = sec;\n ...\n }\n\nTo avoid an out-of-bounds write and utilize all the supported GPIO\ninputs, set LAN743X_PTP_N_EXTTS to 8.\n\nDetected using the static analysis tool - Svace.(CVE-2025-38183)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: reject invalid perturb period\n\nGerrard Tai reported that SFQ perturb_period has no range check yet,\nand this can be used to trigger a race condition fixed in a separate patch.\n\nWe want to make sure ctl->perturb_period * HZ will not overflow\nand is positive.\n\n\ntc qd add dev lo root sfq perturb -10 # negative value : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 1000000000 # too big : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 2000000 # acceptable value\ntc -s -d qd sh dev lo\nqdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec\n Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)\n backlog 0b 0p requeues 0(CVE-2025-38193)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\njffs2: check that raw node were preallocated before writing summary\n\nSyzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault\ninjection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn\'t\ncheck return value of jffs2_prealloc_raw_node_refs and simply lets any\nerror propagate into jffs2_sum_write_data, which eventually calls\njffs2_link_node_ref in order to link the summary to an expectedly allocated\nnode.\n\nkernel BUG at fs/jffs2/nodelist.c:592!\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:jffs2_link_node_ref+0x570/0x690 fs/jffs2/nodelist.c:592\nCall Trace:\n <TASK>\n jffs2_sum_write_data fs/jffs2/summary.c:841 [inline]\n jffs2_sum_write_sumnode+0xd1a/0x1da0 fs/jffs2/summary.c:874\n jffs2_do_reserve_space+0xa18/0xd60 fs/jffs2/nodemgmt.c:388\n jffs2_reserve_space+0x55f/0xaa0 fs/jffs2/nodemgmt.c:197\n jffs2_write_inode_range+0x246/0xb50 fs/jffs2/write.c:362\n jffs2_write_end+0x726/0x15d0 fs/jffs2/file.c:301\n generic_perform_write+0x314/0x5d0 mm/filemap.c:3856\n __generic_file_write_iter+0x2ae/0x4d0 mm/filemap.c:3973\n generic_file_write_iter+0xe3/0x350 mm/filemap.c:4005\n call_write_iter include/linux/fs.h:2265 [inline]\n do_iter_readv_writev+0x20f/0x3c0 fs/read_write.c:735\n do_iter_write+0x186/0x710 fs/read_write.c:861\n vfs_iter_write+0x70/0xa0 fs/read_write.c:902\n iter_file_splice_write+0x73b/0xc90 fs/splice.c:685\n do_splice_from fs/splice.c:763 [inline]\n direct_splice_actor+0x10c/0x170 fs/splice.c:950\n splice_direct_to_actor+0x337/0xa10 fs/splice.c:896\n do_splice_direct+0x1a9/0x280 fs/splice.c:1002\n do_sendfile+0xb13/0x12c0 fs/read_write.c:1255\n __do_sys_sendfile64 fs/read_write.c:1323 [inline]\n __se_sys_sendfile64 fs/read_write.c:1309 [inline]\n __x64_sys_sendfile64+0x1cf/0x210 fs/read_write.c:1309\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFix this issue by checking return value of jffs2_prealloc_raw_node_refs\nbefore calling jffs2_sum_write_data.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.(CVE-2025-38194)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem, swap: fix softlockup with mTHP swapin\n\nFollowing softlockup can be easily reproduced on my test machine with:\n\necho always > /sys/kernel/mm/transparent_hugepage/hugepages-64kB/enabled\nswapon /dev/zram0 # zram0 is a 48G swap device\nmkdir -p /sys/fs/cgroup/memory/test\necho 1G > /sys/fs/cgroup/test/memory.max\necho $BASHPID > /sys/fs/cgroup/test/cgroup.procs\nwhile true; do\n dd if=/dev/zero of=/tmp/test.img bs=1M count=5120\n cat /tmp/test.img > /dev/null\n rm /tmp/test.img\ndone\n\nThen after a while:\nwatchdog: BUG: soft lockup - CPU#0 stuck for 763s! [cat:5787]\nModules linked in: zram virtiofs\nCPU: 0 UID: 0 PID: 5787 Comm: cat Kdump: loaded Tainted: G L 6.15.0.orig-gf3021d9246bc-dirty #118 PREEMPT(voluntary)·\nTainted: [L]=SOFTLOCKUP\nHardware name: Red Hat KVM/RHEL-AV, BIOS 0.0.0 02/06/2015\nRIP: 0010:mpol_shared_policy_lookup+0xd/0x70\nCode: e9 b8 b4 ff ff 31 c0 c3 cc cc cc cc 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 41 54 55 53 <48> 8b 1f 48 85 db 74 41 4c 8d 67 08 48 89 fb 48 89 f5 4c 89 e7 e8\nRSP: 0018:ffffc90002b1fc28 EFLAGS: 00000202\nRAX: 00000000001c20ca RBX: 0000000000724e1e RCX: 0000000000000001\nRDX: ffff888118e214c8 RSI: 0000000000057d42 RDI: ffff888118e21518\nRBP: 000000000002bec8 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000bf4 R11: 0000000000000000 R12: 0000000000000001\nR13: 00000000001c20ca R14: 00000000001c20ca R15: 0000000000000000\nFS: 00007f03f995c740(0000) GS:ffff88a07ad9a000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f03f98f1000 CR3: 0000000144626004 CR4: 0000000000770eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n <TASK>\n shmem_alloc_folio+0x31/0xc0\n shmem_swapin_folio+0x309/0xcf0\n ? filemap_get_entry+0x117/0x1e0\n ? xas_load+0xd/0xb0\n ? filemap_get_entry+0x101/0x1e0\n shmem_get_folio_gfp+0x2ed/0x5b0\n shmem_file_read_iter+0x7f/0x2e0\n vfs_read+0x252/0x330\n ksys_read+0x68/0xf0\n do_syscall_64+0x4c/0x1c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f03f9a46991\nCode: 00 48 8b 15 81 14 10 00 f7 d8 64 89 02 b8 ff ff ff ff eb bd e8 20 ad 01 00 f3 0f 1e fa 80 3d 35 97 10 00 00 74 13 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 4f c3 66 0f 1f 44 00 00 55 48 89 e5 48 83 ec\nRSP: 002b:00007fff3c52bd28 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\nRAX: ffffffffffffffda RBX: 0000000000040000 RCX: 00007f03f9a46991\nRDX: 0000000000040000 RSI: 00007f03f98ba000 RDI: 0000000000000003\nRBP: 00007fff3c52bd50 R08: 0000000000000000 R09: 00007f03f9b9a380\nR10: 0000000000000022 R11: 0000000000000246 R12: 0000000000040000\nR13: 00007f03f98ba000 R14: 0000000000000003 R15: 0000000000000000\n </TASK>\n\nThe reason is simple, readahead brought some order 0 folio in swap cache,\nand the swapin mTHP folio being allocated is in conflict with it, so\nswapcache_prepare fails and causes shmem_swap_alloc_folio to return\n-EEXIST, and shmem simply retries again and again causing this loop.\n\nFix it by applying a similar fix for anon mTHP swapin.\n\nThe performance change is very slight, time of swapin 10g zero folios\nwith shmem (test for 12 times):\nBefore: 2.47s\nAfter: 2.48s\n\n[(CVE-2025-38241)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()\n\nWhile testing null_blk with configfs, echo 0 > poll_queues will trigger\nfollowing panic:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000010\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 27 UID: 0 PID: 920 Comm: bash Not tainted 6.15.0-02023-gadbdb95c8696-dirty #1238 PREEMPT(undef)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\nRIP: 0010:__bitmap_or+0x48/0x70\nCall Trace:\n <TASK>\n __group_cpus_evenly+0x822/0x8c0\n group_cpus_evenly+0x2d9/0x490\n blk_mq_map_queues+0x1e/0x110\n null_map_queues+0xc9/0x170 [null_blk]\n blk_mq_update_queue_map+0xdb/0x160\n blk_mq_update_nr_hw_queues+0x22b/0x560\n nullb_update_nr_hw_queues+0x71/0xf0 [null_blk]\n nullb_device_poll_queues_store+0xa4/0x130 [null_blk]\n configfs_write_iter+0x109/0x1d0\n vfs_write+0x26e/0x6f0\n ksys_write+0x79/0x180\n __x64_sys_write+0x1d/0x30\n x64_sys_call+0x45c4/0x45f0\n do_syscall_64+0xa5/0x240\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nRoot cause is that numgrps is set to 0, and ZERO_SIZE_PTR is returned from\nkcalloc(), and later ZERO_SIZE_PTR will be deferenced.\n\nFix the problem by checking numgrps first in group_cpus_evenly(), and\nreturn NULL directly if numgrps is zero.\n\n[(CVE-2025-38255)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix NULL pointer deference on eir_get_service_data\n\nThe len parameter is considered optional so it can be NULL so it cannot\nbe used for skipping to next entry of EIR_SERVICE_DATA.(CVE-2025-38304)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Verify content returned by parse_int_array()\n\nThe first element of the returned array stores its length. If it is 0,\nany manipulation beyond the element at index 0 ends with null-ptr-deref.(CVE-2025-38307)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can\'t move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a "Dentry still in use" error, so add an error\nmessage that makes it clear this is what happened:\n\n[ 495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[ 495.281595] ------------[ cut here ]------------\n[ 495.281887] BUG: Dentry ffff888115531138{i=78,n=/} still in use (2) [unmount of cifs cifs]\n[ 495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we\'re already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did.(CVE-2025-38321)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: fix acpi parse and parseext cache leaks\n\nACPICA commit 8829e70e1360c81e7a5a901b5d4f48330e021ea5\n\nI\'m Seunghun Han, and I work for National Security Research Institute of\nSouth Korea.\n\nI have been doing a research on ACPI and found an ACPI cache leak in ACPI\nearly abort cases.\n\nBoot log of ACPI cache leak is as follows:\n[ 0.352414] ACPI: Added _OSI(Module Device)\n[ 0.353182] ACPI: Added _OSI(Processor Device)\n[ 0.353182] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.353182] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.356028] ACPI: Unable to start the ACPI Interpreter\n[ 0.356799] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.360215] kmem_cache_destroy Acpi-State: Slab cache still has objects\n[ 0.360648] CPU: 0 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #10\n[ 0.361273] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.361873] Call Trace:\n[ 0.362243] ? dump_stack+0x5c/0x81\n[ 0.362591] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.362944] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.363296] ? acpi_os_delete_cache+0xa/0x10\n[ 0.363646] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.364000] ? acpi_terminate+0xa/0x14\n[ 0.364000] ? acpi_init+0x2af/0x34f\n[ 0.364000] ? __class_create+0x4c/0x80\n[ 0.364000] ? video_setup+0x7f/0x7f\n[ 0.364000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.364000] ? do_one_initcall+0x4e/0x1a0\n[ 0.364000] ? kernel_init_freeable+0x189/0x20a\n[ 0.364000] ? rest_init+0xc0/0xc0\n[ 0.364000] ? kernel_init+0xa/0x100\n[ 0.364000] ? ret_from_fork+0x25/0x30\n\nI analyzed this memory leak in detail. I found that “Acpi-State” cache and\n“Acpi-Parse” cache were merged because the size of cache objects was same\nslab cache size.\n\nI finally found “Acpi-Parse” cache and “Acpi-parse_ext” cache were leaked\nusing SLAB_NEVER_MERGE flag in kmem_cache_create() function.\n\nReal ACPI cache leak point is as follows:\n[ 0.360101] ACPI: Added _OSI(Module Device)\n[ 0.360101] ACPI: Added _OSI(Processor Device)\n[ 0.360101] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.361043] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.364016] ACPI: Unable to start the ACPI Interpreter\n[ 0.365061] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.368174] kmem_cache_destroy Acpi-Parse: Slab cache still has objects\n[ 0.369332] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.371256] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.372000] Call Trace:\n[ 0.372000] ? dump_stack+0x5c/0x81\n[ 0.372000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.372000] ? acpi_ut_delete_caches+0x56/0x7b\n[ 0.372000] ? acpi_terminate+0xa/0x14\n[ 0.372000] ? acpi_init+0x2af/0x34f\n[ 0.372000] ? __class_create+0x4c/0x80\n[ 0.372000] ? video_setup+0x7f/0x7f\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? do_one_initcall+0x4e/0x1a0\n[ 0.372000] ? kernel_init_freeable+0x189/0x20a\n[ 0.372000] ? rest_init+0xc0/0xc0\n[ 0.372000] ? kernel_init+0xa/0x100\n[ 0.372000] ? ret_from_fork+0x25/0x30\n[ 0.388039] kmem_cache_destroy Acpi-parse_ext: Slab cache still has objects\n[ 0.389063] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.390557] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.392000] Call Trace:\n[ 0.392000] ? dump_stack+0x5c/0x81\n[ 0.392000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.392000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.392000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.392000] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.392000] ? acpi_terminate+0xa/0x14\n[ 0.392000] ? acpi_init+0x2af/0x3\n---truncated---(CVE-2025-38344)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmaple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()\n\nTemporarily clear the preallocation flag when explicitly requesting\nallocations. Pre-existing allocations are already counted against the\nrequest through mas_node_count_gfp(), but the allocations will not happen\nif the MA_STATE_PREALLOC flag is set. This flag is meant to avoid\nre-allocating in bulk allocation mode, and to detect issues with\npreallocation calculations.\n\nThe MA_STATE_PREALLOC flag should also always be set on zero allocations\nso that detection of underflow allocations will print a WARN_ON() during\nconsumption.\n\nUser visible effect of this flaw is a WARN_ON() followed by a null pointer\ndereference when subsequent requests for larger number of nodes is\nignored, such as the vma merge retry in mmap_region() caused by drivers\naltering the vma flags (which happens in v6.6, at least)(CVE-2025-38364)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_* TOCTOU\n\nTransport assignment may race with module unload. Protect new_transport\nfrom becoming a stale pointer.\n\nThis also takes care of an insecure call in vsock_use_local_transport();\nadd a lockdep assert.\n\nBUG: unable to handle page fault for address: fffffbfff8056000\nOops: Oops: 0000 [#1] SMP KASAN\nRIP: 0010:vsock_assign_transport+0x366/0x600\nCall Trace:\n vsock_connect+0x59c/0xc40\n __sys_connect+0xe8/0x100\n __x64_sys_connect+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53(CVE-2025-38461)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_{g2h,h2g} TOCTOU\n\nvsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.\ntransport_{g2h,h2g} may become NULL after the NULL check.\n\nIntroduce vsock_transport_local_cid() to protect from a potential\nnull-ptr-deref.\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_find_cid+0x47/0x90\nCall Trace:\n __vsock_bind+0x4b2/0x720\n vsock_bind+0x90/0xe0\n __sys_bind+0x14d/0x1e0\n __x64_sys_bind+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_dev_do_ioctl.isra.0+0x58/0xf0\nCall Trace:\n __x64_sys_ioctl+0x12d/0x190\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53(CVE-2025-38462)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in crypt_message when using async crypto\n\nThe CVE-2024-50047 fix removed asynchronous crypto handling from\ncrypt_message(), assuming all crypto operations are synchronous.\nHowever, when hardware crypto accelerators are used, this can cause\nuse-after-free crashes:\n\n crypt_message()\n // Allocate the creq buffer containing the req\n creq = smb2_get_aead_req(..., &req);\n\n // Async encryption returns -EINPROGRESS immediately\n rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);\n\n // Free creq while async operation is still in progress\n kvfree_sensitive(creq, ...);\n\nHardware crypto modules often implement async AEAD operations for\nperformance. When crypto_aead_encrypt/decrypt() returns -EINPROGRESS,\nthe operation completes asynchronously. Without crypto_wait_req(),\nthe function immediately frees the request buffer, leading to crashes\nwhen the driver later accesses the freed memory.\n\nThis results in a use-after-free condition when the hardware crypto\ndriver later accesses the freed request structure, leading to kernel\ncrashes with NULL pointer dereferences.\n\nThe issue occurs because crypto_alloc_aead() with mask=0 doesn\'t\nguarantee synchronous operation. Even without CRYPTO_ALG_ASYNC in\nthe mask, async implementations can be selected.\n\nFix by restoring the async crypto handling:\n- DECLARE_CRYPTO_WAIT(wait) for completion tracking\n- aead_request_set_callback() for async completion notification\n- crypto_wait_req() to wait for operation completion\n\nThis ensures the request buffer isn\'t freed until the crypto operation\ncompletes, whether synchronous or asynchronous, while preserving the\nCVE-2024-50047 fix.(CVE-2025-38488)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nclone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns\n\nWhat we want is to verify there is that clone won\'t expose something\nhidden by a mount we wouldn\'t be able to undo. "Wouldn\'t be able to undo"\nmay be a result of MNT_LOCKED on a child, but it may also come from\nlacking admin rights in the userns of the namespace mount belongs to.\n\nclone_private_mnt() checks the former, but not the latter.\n\nThere\'s a number of rather confusing CAP_SYS_ADMIN checks in various\nuserns during the mount, especially with the new mount API; they serve\ndifferent purposes and in case of clone_private_mnt() they usually,\nbut not always end up covering the missing check mentioned above.(CVE-2025-38499)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: plug races between subflow fail and subflow creation\n\nWe have races similar to the one addressed by the previous patch between\nsubflow failing and additional subflow creation. They are just harder to\ntrigger.\n\nThe solution is similar. Use a separate flag to track the condition\n\'socket state prevent any additional subflow creation\' protected by the\nfallback lock.\n\nThe socket fallback makes such flag true, and also receiving or sending\nan MP_FAIL option.\n\nThe field \'allow_infinite_fallback\' is now always touched under the\nrelevant lock, we can drop the ONCE annotation on write.(CVE-2025-38552)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use aead_request_free to match aead_request_alloc\n\nUse aead_request_free() instead of kfree() to properly free memory\nallocated by aead_request_alloc(). This ensures sensitive crypto data\nis zeroed before being freed.(CVE-2025-38575)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nPM / devfreq: Check governor before using governor->name\n\nCommit 96ffcdf239de ("PM / devfreq: Remove redundant governor_name from\nstruct devfreq") removes governor_name and uses governor->name to replace\nit. But devfreq->governor may be NULL and directly using\ndevfreq->governor->name may cause null pointer exception. Move the check of\ngovernor to before using governor->name.(CVE-2025-38609)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: fix refcount leak on table dump\n\nThere is a reference count leak in ctnetlink_dump_table():\n if (res < 0) {\n nf_conntrack_get(&ct->ct_general); // HERE\n cb->args[1] = (unsigned long)ct;\n ...\n\nWhile its very unlikely, its possible that ct == last.\nIf this happens, then the refcount of ct was already incremented.\nThis 2nd increment is never undone.\n\nThis prevents the conntrack object from being released, which in turn\nkeeps prevents cnet->count from dropping back to 0.\n\nThis will then block the netns dismantle (or conntrack rmmod) as\nnf_conntrack_cleanup_net_list() will wait forever.\n\nThis can be reproduced by running conntrack_resize.sh selftest in a loop.\nIt takes ~20 minutes for me on a preemptible kernel on average before\nI see a runaway kworker spinning in nf_conntrack_cleanup_net_list.\n\nOne fix would to change this to:\n if (res < 0) {\n\t\tif (ct != last)\n\t nf_conntrack_get(&ct->ct_general);\n\nBut this reference counting isn\'t needed in the first place.\nWe can just store a cookie value instead.\n\nA followup patch will do the same for ctnetlink_exp_dump_table,\nit looks to me as if this has the same problem and like\nctnetlink_dump_table, we only need a \'skip hint\', not the actual\nobject so we can apply the same cookie strategy there as well.(CVE-2025-38721)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla4xxx: Prevent a potential error pointer dereference\n\nThe qla4xxx_get_ep_fwdb() function is supposed to return NULL on error,\nbut qla4xxx_ep_connect() returns error pointers. Propagating the error\npointers will lead to an Oops in the caller, so change the error pointers\nto NULL.(CVE-2025-39676)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix handling of zero-length records on the rx_list\n\nEach recvmsg() call must process either\n - only contiguous DATA records (any number of them)\n - one non-DATA record\n\nIf the next record has different type than what has already been\nprocessed we break out of the main processing loop. If the record\nhas already been decrypted (which may be the case for TLS 1.3 where\nwe don\'t know type until decryption) we queue the pending record\nto the rx_list. Next recvmsg() will pick it up from there.\n\nQueuing the skb to rx_list after zero-copy decrypt is not possible,\nsince in that case we decrypted directly to the user space buffer,\nand we don\'t have an skb to queue (darg.skb points to the ciphertext\nskb for access to metadata like length).\n\nOnly data records are allowed zero-copy, and we break the processing\nloop after each non-data record. So we should never zero-copy and\nthen find out that the record type has changed. The corner case\nwe missed is when the initial record comes from rx_list, and it\'s\nzero length.(CVE-2025-39682)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this.(CVE-2025-39702)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nclk: samsung: Fix UBSAN panic in samsung_clk_init()\n\nWith UBSAN_ARRAY_BOUNDS=y, I\'m hitting the below panic due to\ndereferencing `ctx->clk_data.hws` before setting\n`ctx->clk_data.num = nr_clks`. Move that up to fix the crash.\n\n UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP\n <snip>\n Call trace:\n samsung_clk_init+0x110/0x124 (P)\n samsung_clk_init+0x48/0x124 (L)\n samsung_cmu_register_one+0x3c/0xa0\n exynos_arm64_register_cmu+0x54/0x64\n __gs101_cmu_top_of_clk_init_declare+0x28/0x60\n ...(CVE-2025-39728)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfs: Prevent file descriptor table allocations exceeding INT_MAX\n\nWhen sysctl_nr_open is set to a very high value (for example, 1073741816\nas set by systemd), processes attempting to use file descriptors near\nthe limit can trigger massive memory allocation attempts that exceed\nINT_MAX, resulting in a WARNING in mm/slub.c:\n\n WARNING: CPU: 0 PID: 44 at mm/slub.c:5027 __kvmalloc_node_noprof+0x21a/0x288\n\nThis happens because kvmalloc_array() and kvmalloc() check if the\nrequested size exceeds INT_MAX and emit a warning when the allocation is\nnot flagged with __GFP_NOWARN.\n\nSpecifically, when nr_open is set to 1073741816 (0x3ffffff8) and a\nprocess calls dup2(oldfd, 1073741880), the kernel attempts to allocate:\n- File descriptor array: 1073741880 * 8 bytes = 8,589,935,040 bytes\n- Multiple bitmaps: ~400MB\n- Total allocation size: > 8GB (exceeding INT_MAX = 2,147,483,647)\n\nReproducer:\n1. Set /proc/sys/fs/nr_open to 1073741816:\n # echo 1073741816 > /proc/sys/fs/nr_open\n\n2. Run a program that uses a high file descriptor:\n #include <unistd.h>\n #include <sys/resource.h>\n\n int main() {\n struct rlimit rlim = {1073741824, 1073741824};\n setrlimit(RLIMIT_NOFILE, &rlim);\n dup2(2, 1073741880); // Triggers the warning\n return 0;\n }\n\n3. Observe WARNING in dmesg at mm/slub.c:5027\n\nsystemd commit a8b627a introduced automatic bumping of fs.nr_open to the\nmaximum possible value. The rationale was that systems with memory\ncontrol groups (memcg) no longer need separate file descriptor limits\nsince memory is properly accounted. However, this change overlooked\nthat:\n\n1. The kernel\'s allocation functions still enforce INT_MAX as a maximum\n size regardless of memcg accounting\n2. Programs and tests that legitimately test file descriptor limits can\n inadvertently trigger massive allocations\n3. The resulting allocations (>8GB) are impractical and will always fail\n\nsystemd\'s algorithm starts with INT_MAX and keeps halving the value\nuntil the kernel accepts it. On most systems, this results in nr_open\nbeing set to 1073741816 (0x3ffffff8), which is just under 1GB of file\ndescriptors.\n\nWhile processes rarely use file descriptors near this limit in normal\noperation, certain selftests (like\ntools/testing/selftests/core/unshare_test.c) and programs that test file\ndescriptor limits can trigger this issue.\n\nFix this by adding a check in alloc_fdtable() to ensure the requested\nallocation size does not exceed INT_MAX. This causes the operation to\nfail with -EMFILE instead of triggering a kernel warning and avoids the\nimpractical >8GB memory allocation request.(CVE-2025-39756)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM\n\nWhen performing Generic Segmentation Offload (GSO) on an IPv6 packet that\ncontains extension headers, the kernel incorrectly requests checksum offload\nif the egress device only advertises NETIF_F_IPV6_CSUM feature, which has\na strict contract: it supports checksum offload only for plain TCP or UDP\nover IPv6 and explicitly does not support packets with extension headers.\nThe current GSO logic violates this contract by failing to disable the feature\nfor packets with extension headers, such as those used in GREoIPv6 tunnels.\n\nThis violation results in the device being asked to perform an operation\nit cannot support, leading to a `skb_warn_bad_offload` warning and a collapse\nof network throughput. While device TSO/USO is correctly bypassed in favor\nof software GSO for these packets, the GSO stack must be explicitly told not\nto request checksum offload.\n\nMask NETIF_F_IPV6_CSUM, NETIF_F_TSO6 and NETIF_F_GSO_UDP_L4\nin gso_features_check if the IPv6 header contains extension headers to compute\nchecksum in software.\n\nThe exception is a BIG TCP extension, which, as stated in commit\n68e068cabd2c6c53 ("net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets"):\n"The feature is only enabled on devices that support BIG TCP TSO.\nThe header is only present for PF_PACKET taps like tcpdump,\nand not transmitted by physical devices."\n\nkernel log output (truncated):\nWARNING: CPU: 1 PID: 5273 at net/core/dev.c:3535 skb_warn_bad_offload+0x81/0x140\n...\nCall Trace:\n <TASK>\n skb_checksum_help+0x12a/0x1f0\n validate_xmit_skb+0x1a3/0x2d0\n validate_xmit_skb_list+0x4f/0x80\n sch_direct_xmit+0x1a2/0x380\n __dev_xmit_skb+0x242/0x670\n __dev_queue_xmit+0x3fc/0x7f0\n ip6_finish_output2+0x25e/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_tnl_xmit+0x608/0xc00 [ip6_tunnel]\n ip6gre_tunnel_xmit+0x1c0/0x390 [ip6_gre]\n dev_hard_start_xmit+0x63/0x1c0\n __dev_queue_xmit+0x6d0/0x7f0\n ip6_finish_output2+0x214/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n inet6_csk_xmit+0xeb/0x150\n __tcp_transmit_skb+0x555/0xa80\n tcp_write_xmit+0x32a/0xe90\n tcp_sendmsg_locked+0x437/0x1110\n tcp_sendmsg+0x2f/0x50\n...\nskb linear: 00000000: e4 3d 1a 7d ec 30 e4 3d 1a 7e 5d 90 86 dd 60 0e\nskb linear: 00000010: 00 0a 1b 34 3c 40 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000020: 00 00 00 00 00 12 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000030: 00 00 00 00 00 11 2f 00 04 01 04 01 01 00 00 00\nskb linear: 00000040: 86 dd 60 0e 00 0a 1b 00 06 40 20 23 00 00 00 00\nskb linear: 00000050: 00 00 00 00 00 00 00 00 00 12 20 23 00 00 00 00\nskb linear: 00000060: 00 00 00 00 00 00 00 00 00 11 bf 96 14 51 13 f9\nskb linear: 00000070: ae 27 a0 a8 2b e3 80 18 00 40 5b 6f 00 00 01 01\nskb linear: 00000080: 08 0a 42 d4 50 d5 4b 70 f8 1a(CVE-2025-39770)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: initialize more fields in sctp_v6_from_sk()\n\nsyzbot found that sin6_scope_id was not properly initialized,\nleading to undefined behavior.\n\nClear sin6_scope_id and sin6_flowinfo.\n\nBUG: KMSAN: uninit-value in __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n sctp_inet6_cmp_addr+0x4f2/0x510 net/sctp/ipv6.c:983\n sctp_bind_addr_conflict+0x22a/0x3b0 net/sctp/bind_addr.c:390\n sctp_get_port_local+0x21eb/0x2440 net/sctp/socket.c:8452\n sctp_get_port net/sctp/socket.c:8523 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x710/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930\n x64_sys_call+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls_64.h:51\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable addr.i.i created at:\n sctp_get_port net/sctp/socket.c:8515 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x650/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930(CVE-2025-39812)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix buffer free/clear order in deferred receive path\n\nFix a use-after-free window by correcting the buffer release sequence in\nthe deferred receive path. The code freed the RQ buffer first and only\nthen cleared the context pointer under the lock. Concurrent paths (e.g.,\nABTS and the repost path) also inspect and release the same pointer under\nthe lock, so the old order could lead to double-free/UAF.\n\nNote that the repost path already uses the correct pattern: detach the\npointer under the lock, then free it after dropping the lock. The\ndeferred path should do the same.(CVE-2025-39841)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm\n\nWhen send a broadcast packet to a tap device, which was added to a bridge,\nbr_nf_local_in() is called to confirm the conntrack. If another conntrack\nwith the same hash value is added to the hash table, which can be\ntriggered by a normal packet to a non-bridge device, the below warning\nmay happen.\n\n ------------[ cut here ]------------\n WARNING: CPU: 1 PID: 96 at net/bridge/br_netfilter_hooks.c:632 br_nf_local_in+0x168/0x200\n CPU: 1 UID: 0 PID: 96 Comm: tap_send Not tainted 6.17.0-rc2-dirty #44 PREEMPT(voluntary)\n RIP: 0010:br_nf_local_in+0x168/0x200\n Call Trace:\n <TASK>\n nf_hook_slow+0x3e/0xf0\n br_pass_frame_up+0x103/0x180\n br_handle_frame_finish+0x2de/0x5b0\n br_nf_hook_thresh+0xc0/0x120\n br_nf_pre_routing_finish+0x168/0x3a0\n br_nf_pre_routing+0x237/0x5e0\n br_handle_frame+0x1ec/0x3c0\n __netif_receive_skb_core+0x225/0x1210\n __netif_receive_skb_one_core+0x37/0xa0\n netif_receive_skb+0x36/0x160\n tun_get_user+0xa54/0x10c0\n tun_chr_write_iter+0x65/0xb0\n vfs_write+0x305/0x410\n ksys_write+0x60/0xd0\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n ---[ end trace 0000000000000000 ]---\n\nTo solve the hash conflict, nf_ct_resolve_clash() try to merge the\nconntracks, and update skb->_nfct. However, br_nf_local_in() still use the\nold ct from local variable \'nfct\' after confirm(), which leads to this\nwarning.\n\nIf confirm() does not insert the conntrack entry and return NF_DROP, the\nwarning may also occur. There is no need to reserve the WARN_ON_ONCE, just\nremove it.(CVE-2025-39894)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer\n\nSince commit 7d5e9737efda ("net: rfkill: gpio: get the name and type from\ndevice property") rfkill_find_type() gets called with the possibly\nuninitialized "const char *type_name;" local variable.\n\nOn x86 systems when rfkill-gpio binds to a "BCM4752" or "LNV4752"\nacpi_device, the rfkill->type is set based on the ACPI acpi_device_id:\n\n rfkill->type = (unsigned)id->driver_data;\n\nand there is no "type" property so device_property_read_string() will fail\nand leave type_name uninitialized, leading to a potential crash.\n\nrfkill_find_type() does accept a NULL pointer, fix the potential crash\nby initializing type_name to NULL.\n\nNote likely sofar this has not been caught because:\n\n1. Not many x86 machines actually have a "BCM4752"/"LNV4752" acpi_device\n2. The stack happened to contain NULL where type_name is stored(CVE-2025-39937)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().\n\nsyzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk\nin the TCP_ESTABLISHED state. [0]\n\nsyzbot reused the server-side TCP Fast Open socket as a new client before\nthe TFO socket completes 3WHS:\n\n 1. accept()\n 2. connect(AF_UNSPEC)\n 3. connect() to another destination\n\nAs of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes\nit to TCP_CLOSE and makes connect() possible, which restarts timers.\n\nSince tcp_disconnect() forgot to clear tcp_sk(sk)->fastopen_rsk, the\nretransmit timer triggered the warning and the intended packet was not\nretransmitted.\n\nLet\'s call reqsk_fastopen_remove() in tcp_disconnect().\n\n[0]:\nWARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nModules linked in:\nCPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nCode: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 <0f> 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e\nRSP: 0018:ffffc900002f8d40 EFLAGS: 00010293\nRAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017\nRDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400\nRBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8\nR10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540\nR13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0\nFS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0\nCall Trace:\n <IRQ>\n tcp_write_timer (net/ipv4/tcp_timer.c:738)\n call_timer_fn (kernel/time/timer.c:1747)\n __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2372)\n timer_expire_remote (kernel/time/timer.c:2385 kernel/time/timer.c:2376 kernel/time/timer.c:2135)\n tmigr_handle_remote_up (kernel/time/timer_migration.c:944 kernel/time/timer_migration.c:1035)\n __walk_groups.isra.0 (kernel/time/timer_migration.c:533 (discriminator 1))\n tmigr_handle_remote (kernel/time/timer_migration.c:1096)\n handle_softirqs (./arch/x86/include/asm/jump_label.h:36 ./include/trace/events/irq.h:142 kernel/softirq.c:580)\n irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680 kernel/softirq.c:696)\n sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 (discriminator 35) arch/x86/kernel/apic/apic.c:1050 (discriminator 35))\n </IRQ>(CVE-2025-39955)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Forbid FDB status change while nexthop is in a group\n\nThe kernel forbids the creation of non-FDB nexthop groups with FDB\nnexthops:\n\n # ip nexthop add id 1 via 192.0.2.1 fdb\n # ip nexthop add id 2 group 1\n Error: Non FDB nexthop group cannot have fdb nexthops.\n\nAnd vice versa:\n\n # ip nexthop add id 3 via 192.0.2.2 dev dummy1\n # ip nexthop add id 4 group 3 fdb\n Error: FDB nexthop group can only have fdb nexthops.\n\nHowever, as long as no routes are pointing to a non-FDB nexthop group,\nthe kernel allows changing the type of a nexthop from FDB to non-FDB and\nvice versa:\n\n # ip nexthop add id 5 via 192.0.2.2 dev dummy1\n # ip nexthop add id 6 group 5\n # ip nexthop replace id 5 via 192.0.2.2 fdb\n # echo $?\n 0\n\nThis configuration is invalid and can result in a NPD [1] since FDB\nnexthops are not associated with a nexthop device:\n\n # ip route add 198.51.100.1/32 nhid 6\n # ping 198.51.100.1\n\nFix by preventing nexthop FDB status change while the nexthop is in a\ngroup:\n\n # ip nexthop add id 7 via 192.0.2.2 dev dummy1\n # ip nexthop add id 8 group 7\n # ip nexthop replace id 7 via 192.0.2.2 fdb\n Error: Cannot change nexthop FDB status while in a group.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 00000000000003c0\n[...]\nOops: Oops: 0000 [#1] SMP\nCPU: 6 UID: 0 PID: 367 Comm: ping Not tainted 6.17.0-rc6-virtme-gb65678cacc03 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\nRIP: 0010:fib_lookup_good_nhc+0x1e/0x80\n[...]\nCall Trace:\n <TASK>\n fib_table_lookup+0x541/0x650\n ip_route_output_key_hash_rcu+0x2ea/0x970\n ip_route_output_key_hash+0x55/0x80\n __ip4_datagram_connect+0x250/0x330\n udp_connect+0x2b/0x60\n __sys_connect+0x9c/0xd0\n __x64_sys_connect+0x18/0x20\n do_syscall_64+0xa4/0x2a0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53(CVE-2025-39980)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipvs: Defer ip_vs_ftp unregister during netns cleanup\n\nOn the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp\nbefore connections with valid cp->app pointers are flushed, leading to a\nuse-after-free.\n\nFix this by introducing a global `exiting_module` flag, set to true in\nip_vs_ftp_exit() before unregistering the pernet subsystem. In\n__ip_vs_ftp_exit(), skip ip_vs_ftp unregister if called during netns\ncleanup (when exiting_module is false) and defer it to\n__ip_vs_cleanup_batch(), which unregisters all apps after all connections\nare flushed. If called during module exit, unregister ip_vs_ftp\nimmediately.(CVE-2025-40018)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs\n\nWhen the initialization of qm->debug.acc_diff_reg fails,\nthe probe process does not exit. However, after qm->debug.qm_diff_regs is\nfreed, it is not set to NULL. This can lead to a double free when the\nremove process attempts to free it again. Therefore, qm->debug.qm_diff_regs\nshould be set to NULL after it is freed.(CVE-2025-40062)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n 0: r0 = 0\n 1: r2 = *(u32 *)(r1 +60)\n 2: exit\n\nwhich triggers:\n\n verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn\'t rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn\'t find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch.(CVE-2025-40078)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - request reserved interrupt for virtual function\n\nThe device interrupt vector 3 is an error interrupt for\nphysical function and a reserved interrupt for virtual function.\nHowever, the driver has not registered the reserved interrupt for\nvirtual function. When allocating interrupts, the number of interrupts\nis allocated based on powers of two, which includes this interrupt.\nWhen the system enables GICv4 and the virtual function passthrough\nto the virtual machine, releasing the interrupt in the driver\ntriggers a warning.\n\nThe WARNING report is:\nWARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4\n\nTherefore, register a reserved interrupt for VF and set the\nIRQF_NO_AUTOEN flag to avoid that warning.(CVE-2025-40136)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid NULL dereference when chunk data buffer is missing\n\nchunk->skb pointer is dereferenced in the if-block where it\'s supposed\nto be NULL only.\n\nchunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list\ninstead and do it just before replacing chunk->skb. We\'re sure that\notherwise chunk->skb is non-NULL because of outer if() condition.(CVE-2025-40240)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: remove never-working support for setting nsh fields\n\nThe validation of the set(nsh(...)) action is completely wrong.\nIt runs through the nsh_key_put_from_nlattr() function that is the\nsame function that validates NSH keys for the flow match and the\npush_nsh() action. However, the set(nsh(...)) has a very different\nmemory layout. Nested attributes in there are doubled in size in\ncase of the masked set(). That makes proper validation impossible.\n\nThere is also confusion in the code between the \'masked\' flag, that\nsays that the nested attributes are doubled in size containing both\nthe value and the mask, and the \'is_mask\' that says that the value\nwe\'re parsing is the mask. This is causing kernel crash on trying to\nwrite into mask part of the match with SW_FLOW_KEY_PUT() during\nvalidation, while validate_nsh() doesn\'t allocate any memory for it:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000018\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0\n Oops: Oops: 0000 [#1] SMP NOPTI\n CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary)\n RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch]\n Call Trace:\n <TASK>\n validate_nsh+0x60/0x90 [openvswitch]\n validate_set.constprop.0+0x270/0x3c0 [openvswitch]\n __ovs_nla_copy_actions+0x477/0x860 [openvswitch]\n ovs_nla_copy_actions+0x8d/0x100 [openvswitch]\n ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch]\n genl_family_rcv_msg_doit+0xdb/0x130\n genl_family_rcv_msg+0x14b/0x220\n genl_rcv_msg+0x47/0xa0\n netlink_rcv_skb+0x53/0x100\n genl_rcv+0x24/0x40\n netlink_unicast+0x280/0x3b0\n netlink_sendmsg+0x1f7/0x430\n ____sys_sendmsg+0x36b/0x3a0\n ___sys_sendmsg+0x87/0xd0\n __sys_sendmsg+0x6d/0xd0\n do_syscall_64+0x7b/0x2c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe third issue with this process is that while trying to convert\nthe non-masked set into masked one, validate_set() copies and doubles\nthe size of the OVS_KEY_ATTR_NSH as if it didn\'t have any nested\nattributes. It should be copying each nested attribute and doubling\nthem in size independently. And the process must be properly reversed\nduring the conversion back from masked to a non-masked variant during\nthe flow dump.\n\nIn the end, the only two outcomes of trying to use this action are\neither validation failure or a kernel crash. And if somehow someone\nmanages to install a flow with such an action, it will most definitely\nnot do what it is supposed to, since all the keys and the masks are\nmixed up.\n\nFixing all the issues is a complex task as it requires re-writing\nmost of the validation code.\n\nGiven that and the fact that this functionality never worked since\nintroduction, let\'s just remove it altogether. It\'s better to\nre-introduce it later with a proper implementation instead of trying\nto fix it in stable releases.(CVE-2025-40254)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Fix use-after-free in tipc_mon_reinit_self().\n\nsyzbot reported use-after-free of tipc_net(net)->monitors[]\nin tipc_mon_reinit_self(). [0]\n\nThe array is protected by RTNL, but tipc_mon_reinit_self()\niterates over it without RTNL.\n\ntipc_mon_reinit_self() is called from tipc_net_finalize(),\nwhich is always under RTNL except for tipc_net_finalize_work().\n\nLet\'s hold RTNL in tipc_net_finalize_work().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\nBUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\nRead of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989\n\nCPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)}\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025\nWorkqueue: events tipc_net_finalize_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568\n kasan_check_byte include/linux/kasan.h:399 [inline]\n lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\n rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline]\n rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline]\n rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244\n rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243\n write_lock_bh include/linux/rwlock_rt.h:99 [inline]\n tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718\n tipc_net_finalize+0x115/0x190 net/tipc/net.c:140\n process_one_work kernel/workqueue.c:3236 [inline]\n process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319\n worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400\n kthread+0x70e/0x8a0 kernel/kthread.c:463\n ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>\n\nAllocated by task 6089:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:388 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407\n kmalloc_noprof include/linux/slab.h:905 [inline]\n kzalloc_noprof include/linux/slab.h:1039 [inline]\n tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657\n tipc_enable_bearer net/tipc/bearer.c:357 [inline]\n __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047\n __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline]\n tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393\n tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline]\n tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321\n genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]\n netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346\n netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896\n sock_sendmsg_nosec net/socket.c:714 [inline]\n __sock_sendmsg+0x21c/0x270 net/socket.c:729\n ____sys_sendmsg+0x508/0x820 net/socket.c:2614\n ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668\n __sys_sendmsg net/socket.c:2700 [inline]\n __do_sys_sendmsg net/socket.c:2705 [inline]\n __se_sys_sendmsg net/socket.c:2703 [inline]\n __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/\n---truncated---(CVE-2025-40280)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto\n\nsyzbot reported a possible shift-out-of-bounds [1]\n\nBlamed commit added rto_alpha_max and rto_beta_max set to 1000.\n\nIt is unclear if some sctp users are setting very large rto_alpha\nand/or rto_beta.\n\nIn order to prevent user regression, perform the test at run time.\n\nAlso add READ_ONCE() annotations as sysctl values can change under us.\n\n[1]\n\nUBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41\nshift exponent 64 is too large for 32-bit type \'unsigned int\'\nCPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120\n ubsan_epilogue lib/ubsan.c:233 [inline]\n __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494\n sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509\n sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502\n sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338\n sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline]\n sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline](CVE-2025-40281)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Prevent TOCTOU out-of-bounds write\n\nFor the following path not holding the sock lock,\n\n sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump()\n\nmake sure not to exceed bounds in case the address list has grown\nbetween buffer allocation (time-of-check) and write (time-of-use).(CVE-2025-40331)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: replace BUG_ON with bounds check for map->max_osd\n\nOSD indexes come from untrusted network packets. Boundary checks are\nadded to validate these against map->max_osd.\n\n[ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic\n edits ](CVE-2025-68283)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()\n\nThe len field originates from untrusted network packets. Boundary\nchecks have been added to prevent potential out-of-bounds writes when\ndecrypting the connection secret or processing service tickets.\n\n[ idryomov: changelog ](CVE-2025-68284)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix potential use-after-free in have_mon_and_osd_map()\n\nThe wait loop in __ceph_open_session() can race with the client\nreceiving a new monmap or osdmap shortly after the initial map is\nreceived. Both ceph_monc_handle_map() and handle_one_map() install\na new map immediately after freeing the old one\n\n kfree(monc->monmap);\n monc->monmap = monmap;\n\n ceph_osdmap_destroy(osdc->osdmap);\n osdc->osdmap = newmap;\n\nunder client->monc.mutex and client->osdc.lock respectively, but\nbecause neither is taken in have_mon_and_osd_map() it\'s possible for\nclient->monc.monmap->epoch and client->osdc.osdmap->epoch arms in\n\n client->monc.monmap && client->monc.monmap->epoch &&\n client->osdc.osdmap && client->osdc.osdmap->epoch;\n\ncondition to dereference an already freed map. This happens to be\nreproducible with generic/395 and generic/397 with KASAN enabled:\n\n BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70\n Read of size 4 at addr ffff88811012d810 by task mount.ceph/13305\n CPU: 2 UID: 0 PID: 13305 Comm: mount.ceph Not tainted 6.14.0-rc2-build2+ #1266\n ...\n Call Trace:\n <TASK>\n have_mon_and_osd_map+0x56/0x70\n ceph_open_session+0x182/0x290\n ceph_get_tree+0x333/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\n Allocated by task 13305:\n ceph_osdmap_alloc+0x16/0x130\n ceph_osdc_init+0x27a/0x4c0\n ceph_create_client+0x153/0x190\n create_fs_client+0x50/0x2a0\n ceph_get_tree+0xff/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 9475:\n kfree+0x212/0x290\n handle_one_map+0x23c/0x3b0\n ceph_osdc_handle_map+0x3c9/0x590\n mon_dispatch+0x655/0x6f0\n ceph_con_process_message+0xc3/0xe0\n ceph_con_v1_try_read+0x614/0x760\n ceph_con_workfn+0x2de/0x650\n process_one_work+0x486/0x7c0\n process_scheduled_works+0x73/0x90\n worker_thread+0x1c8/0x2a0\n kthread+0x2ec/0x300\n ret_from_fork+0x24/0x40\n ret_from_fork_asm+0x1a/0x30\n\nRewrite the wait loop to check the above condition directly with\nclient->monc.mutex and client->osdc.lock taken as appropriate. While\nat it, improve the timeout handling (previously mount_timeout could be\nexceeded in case wait_event_interruptible_timeout() slept more than\nonce) and access client->auth_err under client->monc.mutex to match\nhow it\'s set in finish_auth().\n\nmonmap_show() and osdmap_show() now take the respective lock before\naccessing the map as well.(CVE-2025-68285)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: lookup hci_conn on RX path on protocol side\n\nThe hdev lock/lookup/unlock/use pattern in the packet RX path doesn\'t\nensure hci_conn* is not concurrently modified/deleted. This locking\nappears to be leftover from before conn_hash started using RCU\ncommit bf4c63252490b ("Bluetooth: convert conn hash to RCU")\nand not clear if it had purpose since then.\n\nCurrently, there are code paths that delete hci_conn* from elsewhere\nthan the ordered hdev->workqueue where the RX work runs in. E.g.\ncommit 5af1f84ed13a ("Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync")\nintroduced some of these, and there probably were a few others before\nit. It\'s better to do the locking so that even if these run\nconcurrently no UAF is possible.\n\nMove the lookup of hci_conn and associated socket-specific conn to\nprotocol recv handlers, and do them within a single critical section\nto cover hci_conn* usage and lookup.\n\nsyzkaller has reported a crash that appears to be this issue:\n\n [Task hdev->workqueue] [Task 2]\n hci_disconnect_all_sync\n l2cap_recv_acldata(hcon)\n hci_conn_get(hcon)\n hci_abort_conn_sync(hcon)\n hci_dev_lock\n hci_dev_lock\n hci_conn_del(hcon)\n v-------------------------------- hci_dev_unlock\n hci_conn_put(hcon)\n conn = hcon->l2cap_data (UAF)(CVE-2025-68304)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nima: Handle error code returned by ima_filter_rule_match()\n\nIn ima_match_rules(), if ima_filter_rule_match() returns -ENOENT due to\nthe rule being NULL, the function incorrectly skips the \'if (!rc)\' check\nand sets \'result = true\'. The LSM rule is considered a match, causing\nextra files to be measured by IMA.\n\nThis issue can be reproduced in the following scenario:\nAfter unloading the SELinux policy module via \'semodule -d\', if an IMA\nmeasurement is triggered before ima_lsm_rules is updated,\nin ima_match_rules(), the first call to ima_filter_rule_match() returns\n-ESTALE. This causes the code to enter the \'if (rc == -ESTALE &&\n!rule_reinitialized)\' block, perform ima_lsm_copy_rule() and retry. In\nima_lsm_copy_rule(), since the SELinux module has been removed, the rule\nbecomes NULL, and the second call to ima_filter_rule_match() returns\n-ENOENT. This bypasses the \'if (!rc)\' check and results in a false match.\n\nCall trace:\n selinux_audit_rule_match+0x310/0x3b8\n security_audit_rule_match+0x60/0xa0\n ima_match_rules+0x2e4/0x4a0\n ima_match_policy+0x9c/0x1e8\n ima_get_action+0x48/0x60\n process_measurement+0xf8/0xa98\n ima_bprm_check+0x98/0xd8\n security_bprm_check+0x5c/0x78\n search_binary_handler+0x6c/0x318\n exec_binprm+0x58/0x1b8\n bprm_execve+0xb8/0x130\n do_execveat_common.isra.0+0x1a8/0x258\n __arm64_sys_execve+0x48/0x68\n invoke_syscall+0x50/0x128\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x44/0x200\n el0t_64_sync_handler+0x100/0x130\n el0t_64_sync+0x3c8/0x3d0\n\nFix this by changing \'if (!rc)\' to \'if (rc <= 0)\' to ensure that error\ncodes like -ENOENT do not bypass the check and accidentally result in a\nsuccessful match.(CVE-2025-68740)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix invalid prog->stats access when update_effective_progs fails\n\nSyzkaller triggers an invalid memory access issue following fault\ninjection in update_effective_progs. The issue can be described as\nfollows:\n\n__cgroup_bpf_detach\n update_effective_progs\n compute_effective_progs\n bpf_prog_array_alloc <-- fault inject\n purge_effective_progs\n /* change to dummy_bpf_prog */\n array->items[index] = &dummy_bpf_prog.prog\n\n---softirq start---\n__do_softirq\n ...\n __cgroup_bpf_run_filter_skb\n __bpf_prog_run_save_cb\n bpf_prog_run\n stats = this_cpu_ptr(prog->stats)\n /* invalid memory access */\n flags = u64_stats_update_begin_irqsave(&stats->syncp)\n---softirq end---\n\n static_branch_dec(&cgroup_bpf_enabled_key[atype])\n\nThe reason is that fault injection caused update_effective_progs to fail\nand then changed the original prog into dummy_bpf_prog.prog in\npurge_effective_progs. Then a softirq came, and accessing the members of\ndummy_bpf_prog.prog in the softirq triggers invalid mem access.\n\nTo fix it, skip updating stats when stats is NULL.(CVE-2025-68742)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nethtool: Avoid overflowing userspace buffer on stats query\n\nThe ethtool -S command operates across three ioctl calls:\nETHTOOL_GSSET_INFO for the size, ETHTOOL_GSTRINGS for the names, and\nETHTOOL_GSTATS for the values.\n\nIf the number of stats changes between these calls (e.g., due to device\nreconfiguration), userspace\'s buffer allocation will be incorrect,\npotentially leading to buffer overflow.\n\nDrivers are generally expected to maintain stable stat counts, but some\ndrivers (e.g., mlx5, bnx2x, bna, ksz884x) use dynamic counters, making\nthis scenario possible.\n\nSome drivers try to handle this internally:\n- bnad_get_ethtool_stats() returns early in case stats.n_stats is not\n equal to the driver\'s stats count.\n- micrel/ksz884x also makes sure not to write anything beyond\n stats.n_stats and overflow the buffer.\n\nHowever, both use stats.n_stats which is already assigned with the value\nreturned from get_sset_count(), hence won\'t solve the issue described\nhere.\n\nChange ethtool_get_strings(), ethtool_get_stats(),\nethtool_get_phy_stats() to not return anything in case of a mismatch\nbetween userspace\'s size and get_sset_size(), to prevent buffer\noverflow.\nThe returned n_stats value will be equal to zero, to reflect that\nnothing has been returned.\n\nThis could result in one of two cases when using upstream ethtool,\ndepending on when the size change is detected:\n1. When detected in ethtool_get_strings():\n # ethtool -S eth2\n no stats available\n\n2. When detected in get stats, all stats will be reported as zero.\n\nBoth cases are presumably transient, and a subsequent ethtool call\nshould succeed.\n\nOther than the overflow avoidance, these two cases are very evident (no\noutput/cleared stats), which is arguably better than presenting\nincorrect/shifted stats.\nI also considered returning an error instead of a "silent" response, but\nthat seems more destructive towards userspace apps.\n\nNotes:\n- This patch does not claim to fix the inherent race, it only makes sure\n that we do not overflow the userspace buffer, and makes for a more\n predictable behavior.\n\n- RTNL lock is held during each ioctl, the race window exists between\n the separate ioctl calls when the lock is released.\n\n- Userspace ethtool always fills stats.n_stats, but it is likely that\n these stats ioctls are implemented in other userspace applications\n which might not fill it. The added code checks that it\'s not zero,\n to prevent any regressions.(CVE-2025-68795)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: xattr: fix null pointer deref in ext4_raw_inode()\n\nIf ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),\niloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()\nlacks error checking, this will lead to a null pointer dereference\nin ext4_raw_inode(), called right after ext4_get_inode_loc().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-68820)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.(CVE-2025-71064)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset\n\n`qfq_class->leaf_qdisc->q.qlen > 0` does not imply that the class\nitself is active.\n\nTwo qfq_class objects may point to the same leaf_qdisc. This happens\nwhen:\n\n1. one QFQ qdisc is attached to the dev as the root qdisc, and\n\n2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get()\n/ qdisc_put()) and is pending to be destroyed, as in function\ntc_new_tfilter.\n\nWhen packets are enqueued through the root QFQ qdisc, the shared\nleaf_qdisc->q.qlen increases. At the same time, the second QFQ\nqdisc triggers qdisc_put and qdisc_destroy: the qdisc enters\nqfq_reset() with its own q->q.qlen == 0, but its class\'s leaf\nqdisc->q.qlen > 0. Therefore, the qfq_reset would wrongly deactivate\nan inactive aggregate and trigger a null-deref in qfq_deactivate_agg:\n\n[ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 0.903571] #PF: supervisor write access in kernel mode\n[ 0.903860] #PF: error_code(0x0002) - not-present page\n[ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0\n[ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI\n[ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE\n[ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2))\n[ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0\n\nCode starting with the faulting instruction\n===========================================\n 0:\t0f 84 4d 01 00 00 \tje 0x153\n 6:\t48 89 70 18 \tmov %rsi,0x18(%rax)\n a:\t8b 4b 10 \tmov 0x10(%rbx),%ecx\n d:\t48 c7 c2 ff ff ff ff \tmov $0xffffffffffffffff,%rdx\n 14:\t48 8b 78 08 \tmov 0x8(%rax),%rdi\n 18:\t48 d3 e2 \tshl %cl,%rdx\n 1b:\t48 21 f2 \tand %rsi,%rdx\n 1e:\t48 2b 13 \tsub (%rbx),%rdx\n 21:\t48 8b 30 \tmov (%rax),%rsi\n 24:\t48 d3 ea \tshr %cl,%rdx\n 27:\t8b 4b 18 \tmov 0x18(%rbx),%ecx\n\t...\n[ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246\n[ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000\n[ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000\n[ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000\n[ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880\n[ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000\n[ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0\n[ 0.910247] PKRU: 55555554\n[ 0.910391] Call Trace:\n[ 0.910527] <TASK>\n[ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485)\n[ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036)\n[ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076)\n[ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447)\n[ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\n[ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861)\n[ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550)\n[ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\n[ 0.912296] ? __alloc_skb (net/core/skbuff.c:706)\n[ 0.912484] netlink_sendmsg (net/netlink/af\n---truncated---(CVE-2026-22976)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix reference count leak in bpf_prog_test_run_xdp()\n\nsyzbot is reporting\n\n unregister_netdevice: waiting for sit0 to become free. Usage count = 2\n\nproblem. A debug printk() patch found that a refcount is obtained at\nxdp_convert_md_to_buff() from bpf_prog_test_run_xdp().\n\nAccording to commit ec94670fcb3b ("bpf: Support specifying ingress via\nxdp_md context in BPF_PROG_TEST_RUN"), the refcount obtained by\nxdp_convert_md_to_buff() will be released by xdp_convert_buff_to_md().\n\nTherefore, we can consider that the error handling path introduced by\ncommit 1c1949982524 ("bpf: introduce frags support to\nbpf_prog_test_run_xdp()") forgot to call xdp_convert_buff_to_md().(CVE-2026-22994)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a deadlock involving nfs_release_folio()\n\nWang Zhaolong reports a deadlock involving NFSv4.1 state recovery\nwaiting on kthreadd, which is attempting to reclaim memory by calling\nnfs_release_folio(). The latter cannot make progress due to state\nrecovery being needed.\n\nIt seems that the only safe thing to do here is to kick off a writeback\nof the folio, without waiting for completion, or else kicking off an\nasynchronous commit.(CVE-2026-23053)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nuacce: implement mremap in uacce_vm_ops to return -EPERM\n\nThe current uacce_vm_ops does not support the mremap operation of\nvm_operations_struct. Implement .mremap to return -EPERM to remind\nusers.\n\nThe reason we need to explicitly disable mremap is that when the\ndriver does not implement .mremap, it uses the default mremap\nmethod. This could lead to a risk scenario:\n\nAn application might first mmap address p1, then mremap to p2,\nfollowed by munmap(p1), and finally munmap(p2). Since the default\nmremap copies the original vma\'s vm_private_data (i.e., q) to the\nnew vma, both munmap operations would trigger vma_close, causing\nq->qfr to be freed twice(qfr will be set to null here, so repeated\nrelease is ok).(CVE-2026-23056)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nuacce: ensure safe queue release with state management\n\nDirectly calling `put_queue` carries risks since it cannot\nguarantee that resources of `uacce_queue` have been fully released\nbeforehand. So adding a `stop_queue` operation for the\nUACCE_CMD_PUT_Q command and leaving the `put_queue` operation to\nthe final resource release ensures safety.\n\nQueue states are defined as follows:\n- UACCE_Q_ZOMBIE: Initial state\n- UACCE_Q_INIT: After opening `uacce`\n- UACCE_Q_STARTED: After `start` is issued via `ioctl`\n\nWhen executing `poweroff -f` in virt while accelerator are still\nworking, `uacce_fops_release` and `uacce_remove` may execute\nconcurrently. This can cause `uacce_put_queue` within\n`uacce_fops_release` to access a NULL `ops` pointer. Therefore, add\nstate checks to prevent accessing freed pointers.(CVE-2026-23063)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen\n\ndvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the\nDVR device. dvb_ringbuffer_init() calls init_waitqueue_head(), which\nreinitializes the waitqueue list head to empty.\n\nSince dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the\nsame DVR device share it), this orphans any existing waitqueue entries\nfrom io_uring poll or epoll, leaving them with stale prev/next pointers\nwhile the list head is reset to {self, self}.\n\nThe waitqueue and spinlock in dvr_buffer are already properly\ninitialized once in dvb_dmxdev_init(). The open path only needs to\nreset the buffer data pointer, size, and read/write positions.\n\nReplace the dvb_ringbuffer_init() call in dvb_dvr_open() with direct\nassignment of data/size and a call to dvb_ringbuffer_reset(), which\nproperly resets pread, pwrite, and error with correct memory ordering\nwithout touching the waitqueue or spinlock.(CVE-2026-23253)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nregmap: maple: free entry on mas_store_gfp() failure\n\nregcache_maple_write() allocates a new block (\'entry\') to merge\nadjacent ranges and then stores it with mas_store_gfp().\nWhen mas_store_gfp() fails, the new \'entry\' remains allocated and\nis never freed, leaking memory.\n\nFree \'entry\' on the failure path; on success continue freeing the\nreplaced neighbor blocks (\'lower\', \'upper\').(CVE-2026-23260)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix unprivileged local user can do privileged policy management\n\nAn unprivileged local user can load, replace, and remove profiles by\nopening the apparmorfs interfaces, via a confused deputy attack, by\npassing the opened fd to a privileged process, and getting the\nprivileged process to write to the interface.\n\nThis does require a privileged target that can be manipulated to do\nthe write for the unprivileged process, but once such access is\nachieved full policy management is possible and all the possible\nimplications that implies: removing confinement, DoS of system or\ntarget applications by denying all execution, by-passing the\nunprivileged user namespace restriction, to exploiting kernel bugs for\na local privilege escalation.\n\nThe policy management interface can not have its permissions simply\nchanged from 0666 to 0600 because non-root processes need to be able\nto load policy to different policy namespaces.\n\nInstead ensure the task writing the interface has privileges that\nare a subset of the task that opened the interface. This is already\ndone via policy for confined processes, but unconfined can delegate\naccess to the opened fd, by-passing the usual policy check.(CVE-2026-23268)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix __perf_event_overflow() vs perf_remove_from_context() race\n\nMake sure that __perf_event_overflow() runs with IRQs disabled for all\npossible callchains. Specifically the software events can end up running\nit with only preemption disabled.\n\nThis opens up a race vs perf_event_exit_event() and friends that will go\nand free various things the overflow path expects to be present, like\nthe BPF program.(CVE-2026-23271)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: observe an RCU grace period in macvlan_common_newlink() error path\n\nvalis reported that a race condition still happens after my prior patch.\n\nmacvlan_common_newlink() might have made @dev visible before\ndetecting an error, and its caller will directly call free_netdev(dev).\n\nWe must respect an RCU period, either in macvlan or the core networking\nstack.\n\nAfter adding a temporary mdelay(1000) in macvlan_forward_source_one()\nto open the race window, valis repro was:\n\nip link add p1 type veth peer p2\nip link set address 00:00:00:00:00:20 dev p1\nip link set up dev p1\nip link set up dev p2\nip link add mv0 link p2 type macvlan mode source\n\n(ip link add invalid% link p2 type macvlan mode source macaddr add\n00:00:00:00:00:20 &) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4\nPING 1.2.3.4 (1.2.3.4): 56 data bytes\nRTNETLINK answers: Invalid argument\n\nBUG: KASAN: slab-use-after-free in macvlan_forward_source\n(drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nRead of size 8 at addr ffff888016bb89c0 by task e/175\n\nCPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n<IRQ>\ndump_stack_lvl (lib/dump_stack.c:123)\nprint_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nkasan_report (mm/kasan/report.c:597)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nmacvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\n? tasklet_init (kernel/softirq.c:983)\nmacvlan_handle_frame (drivers/net/macvlan.c:501)\n\nAllocated by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\n__kasan_kmalloc (mm/kasan/common.c:419)\n__kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657\nmm/slub.c:7140)\nalloc_netdev_mqs (net/core/dev.c:12012)\nrtnl_create_link (net/core/rtnetlink.c:3648)\nrtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)\n\nFreed by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\nkasan_save_free_info (mm/kasan/generic.c:587)\n__kasan_slab_free (mm/kasan/common.c:287)\nkfree (mm/slub.c:6674 mm/slub.c:6882)\nrtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)(CVE-2026-23273)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.(CVE-2026-31447)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report\'s feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn\'t, omit reporting the raw event and\nreturn early.(CVE-2026-43047)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <(CVE-2026-43048)\n\nIn the Linux kernel, there is a potential out-of-bounds access vulnerability in the ceph_handle_auth_reply() function of the libceph component. When processing messages of type CEPH_MSG_AUTH_REPLY, the value of the payload_len field is stored in a variable of type int. A value greater than INT_MAX leads to integer overflow and is interpreted as a negative value, which causes the pointer address to be decremented and subsequently accessed because ceph_decode_need() only checks that the memory access does not exceed the end address of the allocation. The vulnerability is fixed by changing the data type of payload_len to u32 and introducing additional sanity checks.(CVE-2026-43407)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-20.03-LTS-SP4/openEuler-24.03-LTS/openEuler-22.03-LTS-SP3/openEuler-24.03-LTS-SP2.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'kernel', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for kernel is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2417', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:06+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:06+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:06+08:00', 'initial_release_date': '2026-05-22T21:22:06+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'summary': 'openEuler-SA-2026-2417', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56611&packageName=kernel', 'summary': 'CVE-2024-56611', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56760&packageName=kernel', 'summary': 'CVE-2024-56760', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21908&packageName=kernel', 'summary': 'CVE-2025-21908', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21931&packageName=kernel', 'summary': 'CVE-2025-21931', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21970&packageName=kernel', 'summary': 'CVE-2025-21970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21971&packageName=kernel', 'summary': 'CVE-2025-21971', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21980&packageName=kernel', 'summary': 'CVE-2025-21980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21981&packageName=kernel', 'summary': 'CVE-2025-21981', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21986&packageName=kernel', 'summary': 'CVE-2025-21986', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21995&packageName=kernel', 'summary': 'CVE-2025-21995', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22001&packageName=kernel', 'summary': 'CVE-2025-22001', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22009&packageName=kernel', 'summary': 'CVE-2025-22009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22071&packageName=kernel', 'summary': 'CVE-2025-22071', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22077&packageName=kernel', 'summary': 'CVE-2025-22077', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23138&packageName=kernel', 'summary': 'CVE-2025-23138', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23157&packageName=kernel', 'summary': 'CVE-2025-23157', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37740&packageName=kernel', 'summary': 'CVE-2025-37740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37748&packageName=kernel', 'summary': 'CVE-2025-37748', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37766&packageName=kernel', 'summary': 'CVE-2025-37766', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37768&packageName=kernel', 'summary': 'CVE-2025-37768', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37770&packageName=kernel', 'summary': 'CVE-2025-37770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37771&packageName=kernel', 'summary': 'CVE-2025-37771', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37778&packageName=kernel', 'summary': 'CVE-2025-37778', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37793&packageName=kernel', 'summary': 'CVE-2025-37793', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37805&packageName=kernel', 'summary': 'CVE-2025-37805', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37815&packageName=kernel', 'summary': 'CVE-2025-37815', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37831&packageName=kernel', 'summary': 'CVE-2025-37831', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37844&packageName=kernel', 'summary': 'CVE-2025-37844', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37853&packageName=kernel', 'summary': 'CVE-2025-37853', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37881&packageName=kernel', 'summary': 'CVE-2025-37881', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37889&packageName=kernel', 'summary': 'CVE-2025-37889', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37905&packageName=kernel', 'summary': 'CVE-2025-37905', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37918&packageName=kernel', 'summary': 'CVE-2025-37918', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37947&packageName=kernel', 'summary': 'CVE-2025-37947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37967&packageName=kernel', 'summary': 'CVE-2025-37967', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38014&packageName=kernel', 'summary': 'CVE-2025-38014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38037&packageName=kernel', 'summary': 'CVE-2025-38037', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38043&packageName=kernel', 'summary': 'CVE-2025-38043', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38051&packageName=kernel', 'summary': 'CVE-2025-38051', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38064&packageName=kernel', 'summary': 'CVE-2025-38064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38113&packageName=kernel', 'summary': 'CVE-2025-38113', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38122&packageName=kernel', 'summary': 'CVE-2025-38122', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38123&packageName=kernel', 'summary': 'CVE-2025-38123', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38131&packageName=kernel', 'summary': 'CVE-2025-38131', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38148&packageName=kernel', 'summary': 'CVE-2025-38148', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38161&packageName=kernel', 'summary': 'CVE-2025-38161', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38183&packageName=kernel', 'summary': 'CVE-2025-38183', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38193&packageName=kernel', 'summary': 'CVE-2025-38193', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38194&packageName=kernel', 'summary': 'CVE-2025-38194', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38241&packageName=kernel', 'summary': 'CVE-2025-38241', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38255&packageName=kernel', 'summary': 'CVE-2025-38255', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38304&packageName=kernel', 'summary': 'CVE-2025-38304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38307&packageName=kernel', 'summary': 'CVE-2025-38307', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38321&packageName=kernel', 'summary': 'CVE-2025-38321', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38344&packageName=kernel', 'summary': 'CVE-2025-38344', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38364&packageName=kernel', 'summary': 'CVE-2025-38364', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38461&packageName=kernel', 'summary': 'CVE-2025-38461', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38462&packageName=kernel', 'summary': 'CVE-2025-38462', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38488&packageName=kernel', 'summary': 'CVE-2025-38488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38499&packageName=kernel', 'summary': 'CVE-2025-38499', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38552&packageName=kernel', 'summary': 'CVE-2025-38552', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38575&packageName=kernel', 'summary': 'CVE-2025-38575', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38609&packageName=kernel', 'summary': 'CVE-2025-38609', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38721&packageName=kernel', 'summary': 'CVE-2025-38721', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39676&packageName=kernel', 'summary': 'CVE-2025-39676', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39682&packageName=kernel', 'summary': 'CVE-2025-39682', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39702&packageName=kernel', 'summary': 'CVE-2025-39702', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39728&packageName=kernel', 'summary': 'CVE-2025-39728', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39756&packageName=kernel', 'summary': 'CVE-2025-39756', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39770&packageName=kernel', 'summary': 'CVE-2025-39770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39812&packageName=kernel', 'summary': 'CVE-2025-39812', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39841&packageName=kernel', 'summary': 'CVE-2025-39841', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39894&packageName=kernel', 'summary': 'CVE-2025-39894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39937&packageName=kernel', 'summary': 'CVE-2025-39937', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39955&packageName=kernel', 'summary': 'CVE-2025-39955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39980&packageName=kernel', 'summary': 'CVE-2025-39980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40018&packageName=kernel', 'summary': 'CVE-2025-40018', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40062&packageName=kernel', 'summary': 'CVE-2025-40062', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40078&packageName=kernel', 'summary': 'CVE-2025-40078', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40136&packageName=kernel', 'summary': 'CVE-2025-40136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40240&packageName=kernel', 'summary': 'CVE-2025-40240', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40254&packageName=kernel', 'summary': 'CVE-2025-40254', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40280&packageName=kernel', 'summary': 'CVE-2025-40280', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40281&packageName=kernel', 'summary': 'CVE-2025-40281', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40331&packageName=kernel', 'summary': 'CVE-2025-40331', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68283&packageName=kernel', 'summary': 'CVE-2025-68283', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68284&packageName=kernel', 'summary': 'CVE-2025-68284', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68285&packageName=kernel', 'summary': 'CVE-2025-68285', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68304&packageName=kernel', 'summary': 'CVE-2025-68304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68740&packageName=kernel', 'summary': 'CVE-2025-68740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68742&packageName=kernel', 'summary': 'CVE-2025-68742', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68795&packageName=kernel', 'summary': 'CVE-2025-68795', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68820&packageName=kernel', 'summary': 'CVE-2025-68820', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-71064&packageName=kernel', 'summary': 'CVE-2025-71064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22976&packageName=kernel', 'summary': 'CVE-2026-22976', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22994&packageName=kernel', 'summary': 'CVE-2026-22994', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23053&packageName=kernel', 'summary': 'CVE-2026-23053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23056&packageName=kernel', 'summary': 'CVE-2026-23056', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23063&packageName=kernel', 'summary': 'CVE-2026-23063', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23253&packageName=kernel', 'summary': 'CVE-2026-23253', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23260&packageName=kernel', 'summary': 'CVE-2026-23260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23268&packageName=kernel', 'summary': 'CVE-2026-23268', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23271&packageName=kernel', 'summary': 'CVE-2026-23271', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23273&packageName=kernel', 'summary': 'CVE-2026-23273', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43407&packageName=kernel', 'summary': 'CVE-2026-43407', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56611', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56760', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21908', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21931', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21971', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21981', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21986', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21995', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22001', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22071', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22077', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23138', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23157', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37748', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37766', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37768', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37771', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37778', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37793', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37805', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37815', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37831', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37844', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37853', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37881', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37889', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37905', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37967', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38037', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38043', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38051', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38113', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38122', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38123', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38131', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38148', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38161', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38183', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38193', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38194', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38241', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38255', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38307', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38321', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38344', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38364', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38461', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38462', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38499', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38552', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38575', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38609', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38721', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39676', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39682', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39702', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39728', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39756', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39812', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39841', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39937', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40018', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40062', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40078', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40240', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40254', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40280', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40281', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40331', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68283', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68284', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68285', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68742', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68795', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68820', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-71064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22976', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22994', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23056', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23063', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23268', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23271', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23273', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43407', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2417.json', 'summary': 'openEuler-SA-2026-2417 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'x86_64', 'branches': [{'name': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product': {'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'kernel-6.6.0-145.0.12.138.oe2403.src.rpm', 'product': {'name': 'kernel-6.6.0-145.0.12.138.oe2403.src.rpm', 'product_id': 'kernel-6.6.0-145.0.12.138.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product': {'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:bpftool-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'bpftool-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-source-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-source-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perf-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-perf-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'python3-perf-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64'}, 'product_reference': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.0.12.138.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-6.6.0-145.0.12.138.oe2403.src'}, 'product_reference': 'kernel-6.6.0-145.0.12.138.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:bpftool-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'bpftool-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-source-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-source-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perf-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-perf-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'python3-perf-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64'}, 'product_reference': 'python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-56611', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MMWe currently assume that there is at least one VMA in a MM, which isn ttrue.So we might end up having find_vma() return NULL, to then de-referenceNULL. So properly handle find_vma() returning NULL.This fixes the report:Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTIKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194Code: ...RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8FS: 00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400Call Trace: <TASK> kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709 __do_sys_migrate_pages mm/mempolicy.c:1727 [inline] __se_sys_migrate_pages mm/mempolicy.c:1723 [inline] __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f[akpm@linux-foundation.org: add unlikely()]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56611', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:bpftool-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-debugsource-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-devel-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-headers-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-source-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-tools-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-tools-devel-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:perf-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:python3-perf-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.x86_64', 'openEuler-24.03-LTS:kernel-6.6.0-145.0.12.138.oe2403.src', 'openEuler-24.03-LTS:bpftool-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:bpftool-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-debugsource-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-devel-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-headers-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-source-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-tools-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-tools-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:kernel-tools-devel-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:perf-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:python3-perf-6.6.0-145.0.12.138.oe2403.aarch64', 'openEuler-24.03-LTS:python3-perf-debuginfo-6.6.0-145.0.12.138.oe2403.aarch64']}}, {'cve': 'CVE-2024-56760', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/MSI: Handle lack of irqdomain gracefully\n\nAlexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a\nRISCV platform which does not provide PCI/MSI support:\n\n WARNING: CPU: 1 PID: 1 at drivers/pci/msi/msi.h:121 pci_msi_setup_msi_irqs+0x2c/0x32\n __pci_enable_msix_range+0x30c/0x596\n pci_msi_setup_msi_irqs+0x2c/0x32\n pci_alloc_irq_vectors_affinity+0xb8/0xe2\n\nRISCV uses hierarchical interrupt domains and correctly does not implement\nthe legacy fallback. The warning triggers from the legacy fallback stub.\n\nThat warning is bogus as the PCI/MSI layer knows whether a PCI/MSI parent\ndomain is associated with the device or not. There is a check for MSI-X,\nwhich has a legacy assumption. But that legacy fallback assumption is only\nvalid when legacy support is enabled, but otherwise the check should simply\nreturn -ENOTSUPP.\n\nLoongarch tripped over the same problem and blindly enabled legacy support\nwithout implementing the legacy fallbacks. There are weak implementations\nwhich return an error, so the problem was papered over.\n\nCorrect pci_msi_domain_supports() to evaluate the legacy mode and add\nthe missing supported check into the MSI enable path to complete it.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56760', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21908', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix nfs_release_folio() to not deadlock via kcompactd writeback\n\nAdd PF_KCOMPACTD flag and current_is_kcompactd() helper to check for it so\nnfs_release_folio() can skip calling nfs_wb_folio() from kcompactd.\n\nOtherwise NFS can deadlock waiting for kcompactd enduced writeback which\nrecurses back to NFS (which triggers writeback to NFSD via NFS loopback\nmount on the same host, NFSD blocks waiting for XFS\'s call to\n__filemap_get_folio):\n\n6070.550357] INFO: task kcompactd0:58 blocked for more than 4435 seconds.\n\n{---\n[58] "kcompactd0"\n[<0>] folio_wait_bit+0xe8/0x200\n[<0>] folio_wait_writeback+0x2b/0x80\n[<0>] nfs_wb_folio+0x80/0x1b0 [nfs]\n[<0>] nfs_release_folio+0x68/0x130 [nfs]\n[<0>] split_huge_page_to_list_to_order+0x362/0x840\n[<0>] migrate_pages_batch+0x43d/0xb90\n[<0>] migrate_pages_sync+0x9a/0x240\n[<0>] migrate_pages+0x93c/0x9f0\n[<0>] compact_zone+0x8e2/0x1030\n[<0>] compact_node+0xdb/0x120\n[<0>] kcompactd+0x121/0x2e0\n[<0>] kthread+0xcf/0x100\n[<0>] ret_from_fork+0x31/0x40\n[<0>] ret_from_fork_asm+0x1a/0x30\n---}\n\n[', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21908', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21931', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwpoison, memory_hotplug: lock folio before unmap hwpoisoned folio\n\nCommit b15c87263a69 ("hwpoison, memory_hotplug: allow hwpoisoned pages to\nbe offlined) add page poison checks in do_migrate_range in order to make\noffline hwpoisoned page possible by introducing isolate_lru_page and\ntry_to_unmap for hwpoisoned page. However folio lock must be held before\ncalling try_to_unmap. Add it to fix this problem.\n\nWarning will be produced if folio is not locked during unmap:\n\n ------------[ cut here ]------------\n kernel BUG at ./include/linux/swapops.h:400!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 4 UID: 0 PID: 411 Comm: bash Tainted: G W 6.13.0-rc1-00016-g3c434c7ee82a-dirty #41\n Tainted: [W]=WARN\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : try_to_unmap_one+0xb08/0xd3c\n lr : try_to_unmap_one+0x3dc/0xd3c\n Call trace:\n try_to_unmap_one+0xb08/0xd3c (P)\n try_to_unmap_one+0x3dc/0xd3c (L)\n rmap_walk_anon+0xdc/0x1f8\n rmap_walk+0x3c/0x58\n try_to_unmap+0x88/0x90\n unmap_poisoned_folio+0x30/0xa8\n do_migrate_range+0x4a0/0x568\n offline_pages+0x5a4/0x670\n memory_block_action+0x17c/0x374\n memory_subsys_offline+0x3c/0x78\n device_offline+0xa4/0xd0\n state_store+0x8c/0xf0\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x44/0x54\n kernfs_fop_write_iter+0x118/0x1a8\n vfs_write+0x3a8/0x4bc\n ksys_write+0x6c/0xf8\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xd0\n el0t_64_sync_handler+0xc8/0xcc\n el0t_64_sync+0x198/0x19c\n Code: f9407be0 b5fff320 d4210000 17ffff97 (d4210000)\n ---[ end trace 0000000000000000 ]---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21931', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21970', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Bridge, fix the crash caused by LAG state check\n\nWhen removing LAG device from bridge, NETDEV_CHANGEUPPER event is\ntriggered. Driver finds the lower devices (PFs) to flush all the\noffloaded entries. And mlx5_lag_is_shared_fdb is checked, it returns\nfalse if one of PF is unloaded. In such case,\nmlx5_esw_bridge_lag_rep_get() and its caller return NULL, instead of\nthe alive PF, and the flush is skipped.\n\nBesides, the bridge fdb entry\'s lastuse is updated in mlx5 bridge\nevent handler. But this SWITCHDEV_FDB_ADD_TO_BRIDGE event can be\nignored in this case because the upper interface for bond is deleted,\nand the entry will never be aged because lastuse is never updated.\n\nTo make things worse, as the entry is alive, mlx5 bridge workqueue\nkeeps sending that event, which is then handled by kernel bridge\nnotifier. It causes the following crash when accessing the passed bond\nnetdev which is already destroyed.\n\nTo fix this issue, remove such checks. LAG state is already checked in\ncommit 15f8f168952f ("net/mlx5: Bridge, verify LAG state when adding\nbond to bridge"), driver still need to skip offload if LAG becomes\ninvalid state after initialization.\n\n Oops: stack segment: 0000 [#1] SMP\n CPU: 3 UID: 0 PID: 23695 Comm: kworker/u40:3 Tainted: G OE 6.11.0_mlnx #1\n Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5_bridge_wq mlx5_esw_bridge_update_work [mlx5_core]\n RIP: 0010:br_switchdev_event+0x2c/0x110 [bridge]\n Code: 44 00 00 48 8b 02 48 f7 00 00 02 00 00 74 69 41 54 55 53 48 83 ec 08 48 8b a8 08 01 00 00 48 85 ed 74 4a 48 83 fe 02 48 89 d3 <4c> 8b 65 00 74 23 76 49 48 83 fe 05 74 7e 48 83 fe 06 75 2f 0f b7\n RSP: 0018:ffffc900092cfda0 EFLAGS: 00010297\n RAX: ffff888123bfe000 RBX: ffffc900092cfe08 RCX: 00000000ffffffff\n RDX: ffffc900092cfe08 RSI: 0000000000000001 RDI: ffffffffa0c585f0\n RBP: 6669746f6e690a30 R08: 0000000000000000 R09: ffff888123ae92c8\n R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888123ae9c60\n R13: 0000000000000001 R14: ffffc900092cfe08 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff88852c980000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f15914c8734 CR3: 0000000002830005 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n <TASK>\n ? __die_body+0x1a/0x60\n ? die+0x38/0x60\n ? do_trap+0x10b/0x120\n ? do_error_trap+0x64/0xa0\n ? exc_stack_segment+0x33/0x50\n ? asm_exc_stack_segment+0x22/0x30\n ? br_switchdev_event+0x2c/0x110 [bridge]\n ? sched_balance_newidle.isra.149+0x248/0x390\n notifier_call_chain+0x4b/0xa0\n atomic_notifier_call_chain+0x16/0x20\n mlx5_esw_bridge_update+0xec/0x170 [mlx5_core]\n mlx5_esw_bridge_update_work+0x19/0x40 [mlx5_core]\n process_scheduled_works+0x81/0x390\n worker_thread+0x106/0x250\n ? bh_worker+0x110/0x110\n kthread+0xb7/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n </TASK>', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21970', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21971', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: Prevent creation of classes with TC_H_ROOT\n\nThe function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination\ncondition when traversing up the qdisc tree to update parent backlog\ncounters. However, if a class is created with classid TC_H_ROOT, the\ntraversal terminates prematurely at this class instead of reaching the\nactual root qdisc, causing parent statistics to be incorrectly maintained.\nIn case of DRR, this could lead to a crash as reported by Mingi Cho.\n\nPrevent the creation of any Qdisc class with classid TC_H_ROOT\n(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21971', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21980', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched: address a potential NULL pointer dereference in the GRED scheduler.\n\nIf kzalloc in gred_init returns a NULL pointer, the code follows the\nerror handling path, invoking gred_destroy. This, in turn, calls\ngred_offload, where memset could receive a NULL pointer as input,\npotentially leading to a kernel crash.\n\nWhen table->opt is NULL in gred_init(), gred_change_table_def()\nis not called yet, so it is not necessary to call ->ndo_setup_tc()\nin gred_offload().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21980', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21981', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix memory leak in aRFS after reset\n\nFix aRFS (accelerated Receive Flow Steering) structures memory leak by\nadding a checker to verify if aRFS memory is already allocated while\nconfiguring VSI. aRFS objects are allocated in two cases:\n- as part of VSI initialization (at probe), and\n- as part of reset handling\n\nHowever, VSI reconfiguration executed during reset involves memory\nallocation one more time, without prior releasing already allocated\nresources. This led to the memory leak with the following signature:\n\n[root@os-delivery ~]# cat /sys/kernel/debug/kmemleak\nunreferenced object 0xff3c1ca7252e6000 (size 8192):\n comm "kworker/0:0", pid 8, jiffies 4296833052\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 0):\n [<ffffffff991ec485>] __kmalloc_cache_noprof+0x275/0x340\n [<ffffffffc0a6e06a>] ice_init_arfs+0x3a/0xe0 [ice]\n [<ffffffffc09f1027>] ice_vsi_cfg_def+0x607/0x850 [ice]\n [<ffffffffc09f244b>] ice_vsi_setup+0x5b/0x130 [ice]\n [<ffffffffc09c2131>] ice_init+0x1c1/0x460 [ice]\n [<ffffffffc09c64af>] ice_probe+0x2af/0x520 [ice]\n [<ffffffff994fbcd3>] local_pci_probe+0x43/0xa0\n [<ffffffff98f07103>] work_for_cpu_fn+0x13/0x20\n [<ffffffff98f0b6d9>] process_one_work+0x179/0x390\n [<ffffffff98f0c1e9>] worker_thread+0x239/0x340\n [<ffffffff98f14abc>] kthread+0xcc/0x100\n [<ffffffff98e45a6d>] ret_from_fork+0x2d/0x50\n [<ffffffff98e083ba>] ret_from_fork_asm+0x1a/0x30\n ...', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21981', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21986', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: switchdev: Convert blocking notification chain to a raw one\n\nA blocking notification chain uses a read-write semaphore to protect the\nintegrity of the chain. The semaphore is acquired for writing when\nadding / removing notifiers to / from the chain and acquired for reading\nwhen traversing the chain and informing notifiers about an event.\n\nIn case of the blocking switchdev notification chain, recursive\nnotifications are possible which leads to the semaphore being acquired\ntwice for reading and to lockdep warnings being generated [1].\n\nSpecifically, this can happen when the bridge driver processes a\nSWITCHDEV_BRPORT_UNOFFLOADED event which causes it to emit notifications\nabout deferred events when calling switchdev_deferred_process().\n\nFix this by converting the notification chain to a raw notification\nchain in a similar fashion to the netdev notification chain. Protect\nthe chain using the RTNL mutex by acquiring it when modifying the chain.\nEvents are always informed under the RTNL mutex, but add an assertion in\ncall_switchdev_blocking_notifiers() to make sure this is not violated in\nthe future.\n\nMaintain the "blocking" prefix as events are always emitted from process\ncontext and listeners are allowed to block.\n\n[1]:\nWARNING: possible recursive locking detected\n6.14.0-rc4-custom-g079270089484 #1 Not tainted\n--------------------------------------------\nip/52731 is trying to acquire lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nbut task is already holding lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nother info that might help us debug this:\nPossible unsafe locking scenario:\nCPU0\n----\nlock((switchdev_blocking_notif_chain).rwsem);\nlock((switchdev_blocking_notif_chain).rwsem);\n\n*** DEADLOCK ***\nMay be due to missing lock nesting notation\n3 locks held by ip/52731:\n #0: ffffffff84f795b0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x727/0x1dc0\n #1: ffffffff8731f628 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x790/0x1dc0\n #2: ffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nstack backtrace:\n...\n? __pfx_down_read+0x10/0x10\n? __pfx_mark_lock+0x10/0x10\n? __pfx_switchdev_port_attr_set_deferred+0x10/0x10\nblocking_notifier_call_chain+0x58/0xa0\nswitchdev_port_attr_notify.constprop.0+0xb3/0x1b0\n? __pfx_switchdev_port_attr_notify.constprop.0+0x10/0x10\n? mark_held_locks+0x94/0xe0\n? switchdev_deferred_process+0x11a/0x340\nswitchdev_port_attr_set_deferred+0x27/0xd0\nswitchdev_deferred_process+0x164/0x340\nbr_switchdev_port_unoffload+0xc8/0x100 [bridge]\nbr_switchdev_blocking_event+0x29f/0x580 [bridge]\nnotifier_call_chain+0xa2/0x440\nblocking_notifier_call_chain+0x6e/0xa0\nswitchdev_bridge_port_unoffload+0xde/0x1a0\n...', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21986', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21995', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: Fix fence reference count leak\n\nThe last_scheduled fence leaks when an entity is being killed and adding\nthe cleanup callback fails.\n\nDecrement the reference count of prev when dma_fence_add_callback()\nfails, ensuring proper balance.\n\n[phasta: add git tag info for stable kernel]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21995', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22001', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Fix integer overflow in qaic_validate_req()\n\nThese are u64 variables that come from the user via\nqaic_attach_slice_bo_ioctl(). Use check_add_overflow() to ensure that\nthe math doesn't have an integer wrapping bug.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22001', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22009', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: dummy: force synchronous probing\n\nSometimes I get a NULL pointer dereference at boot time in kobject_get()\nwith the following call stack:\n\nanatop_regulator_probe()\n devm_regulator_register()\n regulator_register()\n regulator_resolve_supply()\n kobject_get()\n\nBy placing some extra BUG_ON() statements I could verify that this is\nraised because probing of the 'dummy' regulator driver is not completed\n('dummy_regulator_rdev' is still NULL).\n\nIn the JTAG debugger I can see that dummy_regulator_probe() and\nanatop_regulator_probe() can be run by different kernel threads\n(kworker/u4:*). I haven't further investigated whether this can be\nchanged or if there are other possibilities to force synchronization\nbetween these two probe routines. On the other hand I don't expect much\nboot time penalty by probing the 'dummy' regulator synchronously.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22071', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix a leak in spufs_create_context()\n\nLeak fixes back in 2008 missed one case - if we are trying to set affinity\nand spufs_mkdir() fails, we need to drop the reference to neighbor.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22071', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22077', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "smb: client: fix TCP timers deadlock after rmmod"\n\nThis reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.\n\nCommit e9f2517a3e18 ("smb: client: fix TCP timers deadlock after\nrmmod") is intended to fix a null-ptr-deref in LOCKDEP, which is\nmentioned as CVE-2024-54680, but is actually did not fix anything;\nThe issue can be reproduced on top of it. [0]\n\nAlso, it reverted the change by commit ef7134c7fc48 ("smb: client:\nFix use-after-free of network namespace.") and introduced a real\nissue by reviving the kernel TCP socket.\n\nWhen a reconnect happens for a CIFS connection, the socket state\ntransitions to FIN_WAIT_1. Then, inet_csk_clear_xmit_timers_sync()\nin tcp_close() stops all timers for the socket.\n\nIf an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1\nforever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.\n\nUsually, FIN can be retransmitted by the peer, but if the peer aborts\nthe connection, the issue comes into reality.\n\nI warned about this privately by pointing out the exact report [1],\nbut the bogus fix was finally merged.\n\nSo, we should not stop the timers to finally kill the connection on\nour side in that case, meaning we must not use a kernel socket for\nTCP whose sk->sk_net_refcnt is 0.\n\nThe kernel socket does not have a reference to its netns to make it\npossible to tear down netns without cleaning up every resource in it.\n\nFor example, tunnel devices use a UDP socket internally, but we can\ndestroy netns without removing such devices and let it complete\nduring exit. Otherwise, netns would be leaked when the last application\ndied.\n\nHowever, this is problematic for TCP sockets because TCP has timers to\nclose the connection gracefully even after the socket is close()d. The\nlifetime of the socket and its netns is different from the lifetime of\nthe underlying connection.\n\nIf the socket user does not maintain the netns lifetime, the timer could\nbe fired after the socket is close()d and its netns is freed up, resulting\nin use-after-free.\n\nActually, we have seen so many similar issues and converted such sockets\nto have a reference to netns.\n\nThat\'s why I converted the CIFS client socket to have a reference to\nnetns (sk->sk_net_refcnt == 1), which is somehow mentioned as out-of-scope\nof CIFS and technically wrong in e9f2517a3e18, but **is in-scope and right\nfix**.\n\nRegarding the LOCKDEP issue, we can prevent the module unload by\nbumping the module refcount when switching the LOCKDDEP key in\nsock_lock_init_class_and_name(). [2]\n\nFor a while, let\'s revert the bogus fix.\n\nNote that now we can use sk_net_refcnt_upgrade() for the socket\nconversion, but I\'ll do so later separately to make backport easy.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22077', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-23138', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nwatch_queue: fix pipe accounting mismatch\n\nCurrently, watch_queue_set_size() modifies the pipe buffers charged to\nuser->pipe_bufs without updating the pipe->nr_accounted on the pipe\nitself, due to the if (!pipe_has_watch_queue()) test in\npipe_resize_ring(). This means that when the pipe is ultimately freed,\nwe decrement user->pipe_bufs by something other than what than we had\ncharged to it, potentially leading to an underflow. This in turn can\ncause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM.\n\nTo remedy this, explicitly account for the pipe usage in\nwatch_queue_set_size() to match the number set via account_pipe_buffers()\n\n(It's unclear why watch_queue_set_size() does not update nr_accounted;\nit may be due to intentional overprovisioning in watch_queue_set_size()?)", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-23138', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-23157', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: add check to avoid out of bound access\n\nThere is a possibility that init_codecs is invoked multiple times during\nmanipulated payload from video firmware. In such case, if codecs_count\ncan get incremented to value more than MAX_CODEC_NUM, there can be OOB\naccess. Reset the count so that it always starts from beginning.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-23157', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37740', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add sanity check for agwidth in dbMount\n\nThe width in dmapctl of the AG is zero, it trigger a divide error when\ncalculating the control page level in dbAllocAG.\n\nTo avoid this issue, add a check for agwidth in dbAllocAG.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37740', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37748', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group\n\nCurrently, mtk_iommu calls during probe iommu_device_register before\nthe hw_list from driver data is initialized. Since iommu probing issue\nfix, it leads to NULL pointer dereference in mtk_iommu_device_group when\nhw_list is accessed with list_first_entry (not null safe).\n\nSo, change the call order to ensure iommu_device_register is called\nafter the driver data are initialized.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37766', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37766', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37768', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37768', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37770', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37770', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37771', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37771', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37778', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Fix dangling pointer in krb_authenticate\n\nkrb_authenticate frees sess->user and does not set the pointer\nto NULL. It calls ksmbd_krb5_authenticate to reinitialise\nsess->user but that function may return without doing so. If\nthat happens then smb2_sess_setup, which calls krb_authenticate,\nwill be accessing free'd memory when it later uses sess->user.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37778', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37793', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\navs_component_probe() does not check for this case, which results in a\nNULL pointer dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37793', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37805', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsound/virtio: Fix cancel_sync warnings on uninitialized work_structs\n\nBetty reported hitting the following warning:\n\n[ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182\n...\n[ 8.713282][ T221] Call trace:\n[ 8.713365][ T221] __flush_work+0x8d0/0x914\n[ 8.713468][ T221] __cancel_work_sync+0xac/0xfc\n[ 8.713570][ T221] cancel_work_sync+0x24/0x34\n[ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.714035][ T221] virtio_dev_probe+0x28c/0x390\n[ 8.714139][ T221] really_probe+0x1bc/0x4c8\n...\n\nIt seems we're hitting the error path in virtsnd_probe(), which\ntriggers a virtsnd_remove() which iterates over the substreams\ncalling cancel_work_sync() on the elapsed_period work_struct.\n\nLooking at the code, from earlier in:\nvirtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg()\n\nWe set snd->nsubstreams, allocate the snd->substreams, and if\nwe then hit an error on the info allocation or something in\nvirtsnd_ctl_query_info() fails, we will exit without having\ninitialized the elapsed_period work_struct.\n\nWhen that error path unwinds we then call virtsnd_remove()\nwhich as long as the substreams array is allocated, will iterate\nthrough calling cancel_work_sync() on the uninitialized work\nstruct hitting this warning.\n\nTakashi Iwai suggested this fix, which initializes the substreams\nstructure right after allocation, so that if we hit the error\npaths we avoid trying to cleanup uninitialized data.\n\nNote: I have not yet managed to reproduce the issue myself, so\nthis patch has had limited testing.\n\nFeedback or thoughts would be appreciated!", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37805', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37815', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration\n\nResolve kernel panic while accessing IRQ handler associated with the\ngenerated IRQ. This is done by acquiring the spinlock and storing the\ncurrent interrupt state before handling the interrupt request using\ngeneric_handle_irq.\n\nA previous fix patch was submitted where 'generic_handle_irq' was\nreplaced with 'handle_nested_irq'. However, this change also causes\nthe kernel panic where after determining which GPIO triggered the\ninterrupt and attempting to call handle_nested_irq with the mapped\nIRQ number, leads to a failure in locating the registered handler.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37815', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37831', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check\nfor this case, which results in a NULL pointer dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37831', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37844', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: avoid NULL pointer dereference in dbg call\n\ncifs_server_dbg() implies server to be non-NULL so\nmove call under condition to avoid NULL pointer dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37844', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37853', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: debugfs hang_hws skip GPU with MES\n\ndebugfs hang_hws is used by GPU reset test with HWS, for MES this crash\nthe kernel with NULL pointer access because dqm->packet_mgr is not setup\nfor MES path.\n\nSkip GPU with MES for now, MES hang_hws debugfs interface will be\nsupported later.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37853', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37881', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()\n\nThe variable d->name, returned by devm_kasprintf(), could be NULL.\nA pointer check is added to prevent potential NULL pointer dereference.\nThis is similar to the fix in commit 3027e7b15b02\n("ice: Fix some null pointer dereference issues in ice_ptp.c").\n\nThis issue is found by our static analysis tool', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37881', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37889', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Consistently treat platform_max as control value\n\nThis reverts commit 9bdd10d57a88 ("ASoC: ops: Shift tested values in\nsnd_soc_put_volsw() by +min"), and makes some additional related\nupdates.\n\nThere are two ways the platform_max could be interpreted; the maximum\nregister value, or the maximum value the control can be set to. The\npatch moved from treating the value as a control value to a register\none. When the patch was applied it was technically correct as\nsnd_soc_limit_volume() also used the register interpretation. However,\neven then most of the other usages treated platform_max as a\ncontrol value, and snd_soc_limit_volume() has since been updated to\nalso do so in commit fb9ad24485087 ("ASoC: ops: add correct range\ncheck for limiting volume"). That patch however, missed updating\nsnd_soc_put_volsw() back to the control interpretation, and fixing\nsnd_soc_info_volsw_range(). The control interpretation makes more\nsense as limiting is typically done from the machine driver, so it is\nappropriate to use the customer facing representation rather than the\ninternal codec representation. Update all the code to consistently use\nthis interpretation of platform_max.\n\nFinally, also add some comments to the soc_mixer_control struct to\nhopefully avoid further patches switching between the two approaches.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37889', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37905', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Balance device refcount when destroying devices\n\nUsing device_find_child() to lookup the proper SCMI device to destroy\ncauses an unbalance in device refcount, since device_find_child() calls an\nimplicit get_device(): this, in turns, inhibits the call of the provided\nrelease methods upon devices destruction.\n\nAs a consequence, one of the structures that is not freed properly upon\ndestruction is the internal struct device_private dev->p populated by the\ndrivers subsystem core.\n\nKMemleak detects this situation since loading/unloding some SCMI driver\ncauses related devices to be created/destroyed without calling any\ndevice_release method.\n\nunreferenced object 0xffff00000f583800 (size 512):\n comm "insmod", pid 227, jiffies 4294912190\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 60 36 1d 8a 00 80 ff ff ........`6......\n backtrace (crc 114e2eed):\n kmemleak_alloc+0xbc/0xd8\n __kmalloc_cache_noprof+0x2dc/0x398\n device_add+0x954/0x12d0\n device_register+0x28/0x40\n __scmi_device_create.part.0+0x1bc/0x380\n scmi_device_create+0x2d0/0x390\n scmi_create_protocol_devices+0x74/0xf8\n scmi_device_request_notifier+0x1f8/0x2a8\n notifier_call_chain+0x110/0x3b0\n blocking_notifier_call_chain+0x70/0xb0\n scmi_driver_register+0x350/0x7f0\n 0xffff80000a3b3038\n do_one_initcall+0x12c/0x730\n do_init_module+0x1dc/0x640\n load_module+0x4b20/0x5b70\n init_module_from_file+0xec/0x158\n\n$ ./scripts/faddr2line ./vmlinux device_add+0x954/0x12d0\ndevice_add+0x954/0x12d0:\nkmalloc_noprof at include/linux/slab.h:901\n(inlined by) kzalloc_noprof at include/linux/slab.h:1037\n(inlined by) device_private_init at drivers/base/core.c:3510\n(inlined by) device_add at drivers/base/core.c:3561\n\nBalance device refcount by issuing a put_device() on devices found via\ndevice_find_child().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37905', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37918', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()\n\nA NULL pointer dereference can occur in skb_dequeue() when processing a\nQCA firmware crash dump on WCN7851 (0489:e0f3).\n\n[ 93.672166] Bluetooth: hci0: ACL memdump size(589824)\n\n[ 93.672475] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[ 93.672517] Workqueue: hci0 hci_devcd_rx [bluetooth]\n[ 93.672598] RIP: 0010:skb_dequeue+0x50/0x80\n\nThe issue stems from handle_dump_pkt_qca() returning 0 even when a dump\npacket is successfully processed. This is because it incorrectly\nforwards the return value of hci_devcd_init() (which returns 0 on\nsuccess). As a result, the caller (btusb_recv_acl_qca() or\nbtusb_recv_evt_qca()) assumes the packet was not handled and passes it\nto hci_recv_frame(), leading to premature kfree() of the skb.\n\nLater, hci_devcd_rx() attempts to dequeue the same skb from the dump\nqueue, resulting in a NULL pointer dereference.\n\nFix this by:\n1. Making handle_dump_pkt_qca() return 0 on success and negative errno\n on failure, consistent with kernel conventions.\n2. Splitting dump packet detection into separate functions for ACL\n and event packets for better structure and readability.\n\nThis ensures dump packets are properly identified and consumed, avoiding\ndouble handling and preventing NULL pointer access.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37918', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37947', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent out-of-bounds stream writes by validating *pos\n\nksmbd_vfs_stream_write() did not validate whether the write offset\n(*pos) was within the bounds of the existing stream data length (v_len).\nIf *pos was greater than or equal to v_len, this could lead to an\nout-of-bounds memory write.\n\nThis patch adds a check to ensure *pos is less than v_len before\nproceeding. If the condition fails, -EINVAL is returned.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37947', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37967', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: displayport: Fix deadlock\n\nThis patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock\nfunctions to the UCSI driver. ucsi_con_mutex_lock ensures the connector\nmutex is only locked if a connection is established and the partner pointer\nis valid. This resolves a deadlock scenario where\nucsi_displayport_remove_partner holds con->mutex waiting for\ndp_altmode_work to complete while dp_altmode_work attempts to acquire it.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37967', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38014', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Refactor remove call with idxd_cleanup() helper\n\nThe idxd_cleanup() helper cleans up perfmon, interrupts, internals and\nso on. Refactor remove call with the idxd_cleanup() helper to avoid code\nduplication. Note, this also fixes the missing put_device() for idxd\ngroups, enginces and wqs.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38037', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Annotate FDB data races\n\nThe 'used' and 'updated' fields in the FDB entry structure can be\naccessed concurrently by multiple threads, leading to reports such as\n[1]. Can be reproduced using [2].\n\nSuppress these reports by annotating these accesses using\nREAD_ONCE() / WRITE_ONCE().\n\n[1]\nBUG: KCSAN: data-race in vxlan_xmit / vxlan_xmit\n\nwrite to 0xffff942604d263a8 of 8 bytes by task 286 on cpu 0:\n vxlan_xmit+0xb29/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff942604d263a8 of 8 bytes by task 287 on cpu 2:\n vxlan_xmit+0xadf/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000000fffbac6e -> 0x00000000fffbac6f\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 2 UID: 0 PID: 287 Comm: mausezahn Not tainted 6.13.0-rc7-01544-gb4b270f11a02 #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014\n\n[2]\n #!/bin/bash\n\n set +H\n echo whitelist > /sys/kernel/debug/kcsan\n echo !vxlan_xmit > /sys/kernel/debug/kcsan\n\n ip link add name vx0 up type vxlan id 10010 dstport 4789 local 192.0.2.1\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 198.51.100.1\n taskset -c 0 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &\n taskset -c 2 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38037', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38043', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Set dma_mask for ffa devices\n\nSet dma_mask for FFA devices, otherwise DMA allocation using the device pointer\nlead to following warning:\n\nWARNING: CPU: 1 PID: 1 at kernel/dma/mapping.c:597 dma_alloc_attrs+0xe0/0x124', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38043', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38051', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_fill_dirent\n\nThere is a race condition in the readdir concurrency process, which may\naccess the rsp buffer after it has been released, triggering the\nfollowing KASAN warning.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03/0xb60 [cifs]\n Read of size 4 at addr ffff8880099b819c by task a.out/342975\n\n CPU: 2 UID: 0 PID: 342975 Comm: a.out Not tainted 6.15.0-rc6+ #240 PREEMPT(full)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\n Call Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n print_report+0xce/0x640\n kasan_report+0xb8/0xf0\n cifs_fill_dirent+0xb03/0xb60 [cifs]\n cifs_readdir+0x12cb/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f996f64b9f9\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01\n f0 ff ff 0d f7 c3 0c 00 f7 d8 64 89 8\n RSP: 002b:00007f996f53de78 EFLAGS: 00000207 ORIG_RAX: 000000000000004e\n RAX: ffffffffffffffda RBX: 00007f996f53ecdc RCX: 00007f996f64b9f9\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007f996f53dea0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000207 R12: ffffffffffffff88\n R13: 0000000000000000 R14: 00007ffc8cd9a500 R15: 00007f996f51e000\n </TASK>\n\n Allocated by task 408:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x6e/0x70\n kmem_cache_alloc_noprof+0x117/0x3d0\n mempool_alloc_noprof+0xf2/0x2c0\n cifs_buf_get+0x36/0x80 [cifs]\n allocate_buffers+0x1d2/0x330 [cifs]\n cifs_demultiplex_thread+0x22b/0x2690 [cifs]\n kthread+0x394/0x720\n ret_from_fork+0x34/0x70\n ret_from_fork_asm+0x1a/0x30\n\n Freed by task 342979:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x37/0x50\n kmem_cache_free+0x2b8/0x500\n cifs_buf_release+0x3c/0x70 [cifs]\n cifs_readdir+0x1c97/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents64+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n The buggy address belongs to the object at ffff8880099b8000\n which belongs to the cache cifs_request of size 16588\n The buggy address is located 412 bytes inside of\n freed 16588-byte region [ffff8880099b8000, ffff8880099bc0cc)\n\n The buggy address belongs to the physical page:\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x99b8\n head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n anon flags: 0x80000000000040(head|node=0|zone=1)\n page_type: f5(slab)\n raw: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n raw: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n head: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000003 ffffea0000266e01 00000000ffffffff 00000000ffffffff\n head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8880099b8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8880099b8180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8880099b8200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\nPOC is available in the link [1].\n\nThe problem triggering process is as follows:\n\nProcess 1 Process 2\n-----------------------------------\n---truncated---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38051', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38064', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()\n\nHongyu reported a hang on kexec in a VM. QEMU reported invalid memory\naccesses during the hang.\n\n\tInvalid read at addr 0x102877002, size 2, region '(null)', reason: rejected\n\tInvalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected\n\t...\n\nIt was traced down to virtio-console. Kexec works fine if virtio-console\nis not in use.\n\nThe issue is that virtio-console continues to write to the MMIO even after\nunderlying virtio-pci device is reset.\n\nAdditionally, Eric noticed that IOMMUs are reset before devices, if\ndevices are not reset on shutdown they continue to poke at guest memory\nand get errors from the IOMMU. Some devices get wedged then.\n\nThe problem can be solved by breaking all virtio devices on virtio\nbus shutdown, then resetting them.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38064', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38113', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Fix NULL pointer dereference when nosmp is used\n\nWith nosmp in cmdline, other CPUs are not brought up, leaving\ntheir cpc_desc_ptr NULL. CPU0's iteration via for_each_possible_cpu()\ndereferences these NULL pointers, causing panic.\n\nPanic backtrace:\n\n[ 0.401123] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b8\n...\n[ 0.403255] [<ffffffff809a5818>] cppc_allow_fast_switch+0x6a/0xd4\n...\nKernel panic - not syncing: Attempted to kill init!\n\n[ rjw: New subject ]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38113', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38122', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngve: add missing NULL check for gve_alloc_pending_packet() in TX DQO\n\ngve_alloc_pending_packet() can return NULL, but gve_tx_add_skb_dqo()\ndid not check for this case before dereferencing the returned pointer.\n\nAdd a missing NULL check to prevent a potential NULL pointer\ndereference when allocation fails.\n\nThis improves robustness in low-memory scenarios.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38122', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38123', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: Fix napi rx poll issue\n\nWhen driver handles the napi rx polling requests, the netdev might\nhave been released by the dellink logic triggered by the disconnect\noperation on user plane. However, in the logic of processing skb in\npolling, an invalid netdev is still being used, which causes a panic.\n\nBUG: kernel NULL pointer dereference, address: 00000000000000f1\nOops: 0000 [#1] PREEMPT SMP NOPTI\nRIP: 0010:dev_gro_receive+0x3a/0x620\n[...]\nCall Trace:\n <IRQ>\n ? __die_body+0x68/0xb0\n ? page_fault_oops+0x379/0x3e0\n ? exc_page_fault+0x4f/0xa0\n ? asm_exc_page_fault+0x22/0x30\n ? __pfx_t7xx_ccmni_recv_skb+0x10/0x10 [mtk_t7xx (HASH:1400 7)]\n ? dev_gro_receive+0x3a/0x620\n napi_gro_receive+0xad/0x170\n t7xx_ccmni_recv_skb+0x48/0x70 [mtk_t7xx (HASH:1400 7)]\n t7xx_dpmaif_napi_rx_poll+0x590/0x800 [mtk_t7xx (HASH:1400 7)]\n net_rx_action+0x103/0x470\n irq_exit_rcu+0x13a/0x310\n sysvec_apic_timer_interrupt+0x56/0x90\n </IRQ>', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38123', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38131', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: prevent deactivate active config while enabling the config\n\nWhile enable active config via cscfg_csdev_enable_active_config(),\nactive config could be deactivated via configfs' sysfs interface.\nThis could make UAF issue in below scenario:\n\nCPU0 CPU1\n(sysfs enable) load module\n cscfg_load_config_sets()\n activate config. // sysfs\n (sys_active_cnt == 1)\n...\ncscfg_csdev_enable_active_config()\nlock(csdev->cscfg_csdev_lock)\n// here load config activate by CPU1\nunlock(csdev->cscfg_csdev_lock)\n\n deactivate config // sysfs\n (sys_activec_cnt == 0)\n cscfg_unload_config_sets()\n unload module\n\n// access to config_desc which freed\n// while unloading module.\ncscfg_csdev_enable_config\n\nTo address this, use cscfg_config_desc's active_cnt as a reference count\n which will be holded when\n - activate the config.\n - enable the activated config.\nand put the module reference when config_active_cnt == 0.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38131', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38148', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: mscc: Fix memory leak when using one step timestamping\n\nFix memory leak when running one-step timestamping. When running\none-step sync timestamping, the HW is configured to insert the TX time\ninto the frame, so there is no reason to keep the skb anymore. As in\nthis case the HW will never generate an interrupt to say that the frame\nwas timestamped, then the frame will never released.\nFix this by freeing the frame in case of one-step timestamping.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38148', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38161', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix error flow upon firmware failure for RQ destruction\n\nUpon RQ destruction if the firmware command fails which is the\nlast resource to be destroyed some SW resources were already cleaned\nregardless of the failure.\n\nNow properly rollback the object to its original state upon such failure.\n\nIn order to avoid a use-after free in case someone tries to destroy the\nobject again, which results in the following kernel trace:\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 0 PID: 37589 at lib/refcount.c:28 refcount_warn_saturate+0xf4/0x148\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) rfkill mlx5_core(OE) mlxdevm(OE) ib_uverbs(OE) ib_core(OE) psample mlxfw(OE) mlx_compat(OE) macsec tls pci_hyperv_intf sunrpc vfat fat virtio_net net_failover failover fuse loop nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_console virtio_gpu virtio_blk virtio_dma_buf virtio_mmio dm_mirror dm_region_hash dm_log dm_mod xpmem(OE)\nCPU: 0 UID: 0 PID: 37589 Comm: python3 Kdump: loaded Tainted: G OE ------- --- 6.12.0-54.el10.aarch64 #1\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : refcount_warn_saturate+0xf4/0x148\nlr : refcount_warn_saturate+0xf4/0x148\nsp : ffff80008b81b7e0\nx29: ffff80008b81b7e0 x28: ffff000133d51600 x27: 0000000000000001\nx26: 0000000000000000 x25: 00000000ffffffea x24: ffff00010ae80f00\nx23: ffff00010ae80f80 x22: ffff0000c66e5d08 x21: 0000000000000000\nx20: ffff0000c66e0000 x19: ffff00010ae80340 x18: 0000000000000006\nx17: 0000000000000000 x16: 0000000000000020 x15: ffff80008b81b37f\nx14: 0000000000000000 x13: 2e656572662d7265 x12: ffff80008283ef78\nx11: ffff80008257efd0 x10: ffff80008283efd0 x9 : ffff80008021ed90\nx8 : 0000000000000001 x7 : 00000000000bffe8 x6 : c0000000ffff7fff\nx5 : ffff0001fb8e3408 x4 : 0000000000000000 x3 : ffff800179993000\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000133d51600\nCall trace:\n refcount_warn_saturate+0xf4/0x148\n mlx5_core_put_rsc+0x88/0xa0 [mlx5_ib]\n mlx5_core_destroy_rq_tracked+0x64/0x98 [mlx5_ib]\n mlx5_ib_destroy_wq+0x34/0x80 [mlx5_ib]\n ib_destroy_wq_user+0x30/0xc0 [ib_core]\n uverbs_free_wq+0x28/0x58 [ib_uverbs]\n destroy_hw_idr_uobject+0x34/0x78 [ib_uverbs]\n uverbs_destroy_uobject+0x48/0x240 [ib_uverbs]\n __uverbs_cleanup_ufile+0xd4/0x1a8 [ib_uverbs]\n uverbs_destroy_ufile_hw+0x48/0x120 [ib_uverbs]\n ib_uverbs_close+0x2c/0x100 [ib_uverbs]\n __fput+0xd8/0x2f0\n __fput_sync+0x50/0x70\n __arm64_sys_close+0x40/0x90\n invoke_syscall.constprop.0+0x74/0xd0\n do_el0_svc+0x48/0xe8\n el0_svc+0x44/0x1d0\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x1a4/0x1a8', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38161', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38183', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()\n\nBefore calling lan743x_ptp_io_event_clock_get(), the 'channel' value\nis checked against the maximum value of PCI11X1X_PTP_IO_MAX_CHANNELS(8).\nThis seems correct and aligns with the PTP interrupt status register\n(PTP_INT_STS) specifications.\n\nHowever, lan743x_ptp_io_event_clock_get() writes to ptp->extts[] with\nonly LAN743X_PTP_N_EXTTS(4) elements, using channel as an index:\n\n lan743x_ptp_io_event_clock_get(..., u8 channel,...)\n {\n ...\n /* Update Local timestamp */\n extts = &ptp->extts[channel];\n extts->ts.tv_sec = sec;\n ...\n }\n\nTo avoid an out-of-bounds write and utilize all the supported GPIO\ninputs, set LAN743X_PTP_N_EXTTS to 8.\n\nDetected using the static analysis tool - Svace.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38183', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38193', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: reject invalid perturb period\n\nGerrard Tai reported that SFQ perturb_period has no range check yet,\nand this can be used to trigger a race condition fixed in a separate patch.\n\nWe want to make sure ctl->perturb_period * HZ will not overflow\nand is positive.\n\n\ntc qd add dev lo root sfq perturb -10 # negative value : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 1000000000 # too big : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 2000000 # acceptable value\ntc -s -d qd sh dev lo\nqdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec\n Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)\n backlog 0b 0p requeues 0', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38193', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38194', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: check that raw node were preallocated before writing summary\n\nSyzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault\ninjection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't\ncheck return value of jffs2_prealloc_raw_node_refs and simply lets any\nerror propagate into jffs2_sum_write_data, which eventually calls\njffs2_link_node_ref in order to link the summary to an expectedly allocated\nnode.\n\nkernel BUG at fs/jffs2/nodelist.c:592!\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:jffs2_link_node_ref+0x570/0x690 fs/jffs2/nodelist.c:592\nCall Trace:\n <TASK>\n jffs2_sum_write_data fs/jffs2/summary.c:841 [inline]\n jffs2_sum_write_sumnode+0xd1a/0x1da0 fs/jffs2/summary.c:874\n jffs2_do_reserve_space+0xa18/0xd60 fs/jffs2/nodemgmt.c:388\n jffs2_reserve_space+0x55f/0xaa0 fs/jffs2/nodemgmt.c:197\n jffs2_write_inode_range+0x246/0xb50 fs/jffs2/write.c:362\n jffs2_write_end+0x726/0x15d0 fs/jffs2/file.c:301\n generic_perform_write+0x314/0x5d0 mm/filemap.c:3856\n __generic_file_write_iter+0x2ae/0x4d0 mm/filemap.c:3973\n generic_file_write_iter+0xe3/0x350 mm/filemap.c:4005\n call_write_iter include/linux/fs.h:2265 [inline]\n do_iter_readv_writev+0x20f/0x3c0 fs/read_write.c:735\n do_iter_write+0x186/0x710 fs/read_write.c:861\n vfs_iter_write+0x70/0xa0 fs/read_write.c:902\n iter_file_splice_write+0x73b/0xc90 fs/splice.c:685\n do_splice_from fs/splice.c:763 [inline]\n direct_splice_actor+0x10c/0x170 fs/splice.c:950\n splice_direct_to_actor+0x337/0xa10 fs/splice.c:896\n do_splice_direct+0x1a9/0x280 fs/splice.c:1002\n do_sendfile+0xb13/0x12c0 fs/read_write.c:1255\n __do_sys_sendfile64 fs/read_write.c:1323 [inline]\n __se_sys_sendfile64 fs/read_write.c:1309 [inline]\n __x64_sys_sendfile64+0x1cf/0x210 fs/read_write.c:1309\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFix this issue by checking return value of jffs2_prealloc_raw_node_refs\nbefore calling jffs2_sum_write_data.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38194', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38241', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem, swap: fix softlockup with mTHP swapin\n\nFollowing softlockup can be easily reproduced on my test machine with:\n\necho always > /sys/kernel/mm/transparent_hugepage/hugepages-64kB/enabled\nswapon /dev/zram0 # zram0 is a 48G swap device\nmkdir -p /sys/fs/cgroup/memory/test\necho 1G > /sys/fs/cgroup/test/memory.max\necho $BASHPID > /sys/fs/cgroup/test/cgroup.procs\nwhile true; do\n dd if=/dev/zero of=/tmp/test.img bs=1M count=5120\n cat /tmp/test.img > /dev/null\n rm /tmp/test.img\ndone\n\nThen after a while:\nwatchdog: BUG: soft lockup - CPU#0 stuck for 763s! [cat:5787]\nModules linked in: zram virtiofs\nCPU: 0 UID: 0 PID: 5787 Comm: cat Kdump: loaded Tainted: G L 6.15.0.orig-gf3021d9246bc-dirty #118 PREEMPT(voluntary)·\nTainted: [L]=SOFTLOCKUP\nHardware name: Red Hat KVM/RHEL-AV, BIOS 0.0.0 02/06/2015\nRIP: 0010:mpol_shared_policy_lookup+0xd/0x70\nCode: e9 b8 b4 ff ff 31 c0 c3 cc cc cc cc 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 41 54 55 53 <48> 8b 1f 48 85 db 74 41 4c 8d 67 08 48 89 fb 48 89 f5 4c 89 e7 e8\nRSP: 0018:ffffc90002b1fc28 EFLAGS: 00000202\nRAX: 00000000001c20ca RBX: 0000000000724e1e RCX: 0000000000000001\nRDX: ffff888118e214c8 RSI: 0000000000057d42 RDI: ffff888118e21518\nRBP: 000000000002bec8 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000bf4 R11: 0000000000000000 R12: 0000000000000001\nR13: 00000000001c20ca R14: 00000000001c20ca R15: 0000000000000000\nFS: 00007f03f995c740(0000) GS:ffff88a07ad9a000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f03f98f1000 CR3: 0000000144626004 CR4: 0000000000770eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n <TASK>\n shmem_alloc_folio+0x31/0xc0\n shmem_swapin_folio+0x309/0xcf0\n ? filemap_get_entry+0x117/0x1e0\n ? xas_load+0xd/0xb0\n ? filemap_get_entry+0x101/0x1e0\n shmem_get_folio_gfp+0x2ed/0x5b0\n shmem_file_read_iter+0x7f/0x2e0\n vfs_read+0x252/0x330\n ksys_read+0x68/0xf0\n do_syscall_64+0x4c/0x1c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f03f9a46991\nCode: 00 48 8b 15 81 14 10 00 f7 d8 64 89 02 b8 ff ff ff ff eb bd e8 20 ad 01 00 f3 0f 1e fa 80 3d 35 97 10 00 00 74 13 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 4f c3 66 0f 1f 44 00 00 55 48 89 e5 48 83 ec\nRSP: 002b:00007fff3c52bd28 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\nRAX: ffffffffffffffda RBX: 0000000000040000 RCX: 00007f03f9a46991\nRDX: 0000000000040000 RSI: 00007f03f98ba000 RDI: 0000000000000003\nRBP: 00007fff3c52bd50 R08: 0000000000000000 R09: 00007f03f9b9a380\nR10: 0000000000000022 R11: 0000000000000246 R12: 0000000000040000\nR13: 00007f03f98ba000 R14: 0000000000000003 R15: 0000000000000000\n </TASK>\n\nThe reason is simple, readahead brought some order 0 folio in swap cache,\nand the swapin mTHP folio being allocated is in conflict with it, so\nswapcache_prepare fails and causes shmem_swap_alloc_folio to return\n-EEXIST, and shmem simply retries again and again causing this loop.\n\nFix it by applying a similar fix for anon mTHP swapin.\n\nThe performance change is very slight, time of swapin 10g zero folios\nwith shmem (test for 12 times):\nBefore: 2.47s\nAfter: 2.48s\n\n[', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38241', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38255', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()\n\nWhile testing null_blk with configfs, echo 0 > poll_queues will trigger\nfollowing panic:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000010\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 27 UID: 0 PID: 920 Comm: bash Not tainted 6.15.0-02023-gadbdb95c8696-dirty #1238 PREEMPT(undef)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\nRIP: 0010:__bitmap_or+0x48/0x70\nCall Trace:\n <TASK>\n __group_cpus_evenly+0x822/0x8c0\n group_cpus_evenly+0x2d9/0x490\n blk_mq_map_queues+0x1e/0x110\n null_map_queues+0xc9/0x170 [null_blk]\n blk_mq_update_queue_map+0xdb/0x160\n blk_mq_update_nr_hw_queues+0x22b/0x560\n nullb_update_nr_hw_queues+0x71/0xf0 [null_blk]\n nullb_device_poll_queues_store+0xa4/0x130 [null_blk]\n configfs_write_iter+0x109/0x1d0\n vfs_write+0x26e/0x6f0\n ksys_write+0x79/0x180\n __x64_sys_write+0x1d/0x30\n x64_sys_call+0x45c4/0x45f0\n do_syscall_64+0xa5/0x240\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nRoot cause is that numgrps is set to 0, and ZERO_SIZE_PTR is returned from\nkcalloc(), and later ZERO_SIZE_PTR will be deferenced.\n\nFix the problem by checking numgrps first in group_cpus_evenly(), and\nreturn NULL directly if numgrps is zero.\n\n[', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38255', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38304', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix NULL pointer deference on eir_get_service_data\n\nThe len parameter is considered optional so it can be NULL so it cannot\nbe used for skipping to next entry of EIR_SERVICE_DATA.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38307', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Verify content returned by parse_int_array()\n\nThe first element of the returned array stores its length. If it is 0,\nany manipulation beyond the element at index 0 ends with null-ptr-deref.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38307', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38321', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can\'t move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a "Dentry still in use" error, so add an error\nmessage that makes it clear this is what happened:\n\n[ 495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[ 495.281595] ------------[ cut here ]------------\n[ 495.281887] BUG: Dentry ffff888115531138{i=78,n=/} still in use (2) [unmount of cifs cifs]\n[ 495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we\'re already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38321', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38344', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: fix acpi parse and parseext cache leaks\n\nACPICA commit 8829e70e1360c81e7a5a901b5d4f48330e021ea5\n\nI'm Seunghun Han, and I work for National Security Research Institute of\nSouth Korea.\n\nI have been doing a research on ACPI and found an ACPI cache leak in ACPI\nearly abort cases.\n\nBoot log of ACPI cache leak is as follows:\n[ 0.352414] ACPI: Added _OSI(Module Device)\n[ 0.353182] ACPI: Added _OSI(Processor Device)\n[ 0.353182] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.353182] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.356028] ACPI: Unable to start the ACPI Interpreter\n[ 0.356799] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.360215] kmem_cache_destroy Acpi-State: Slab cache still has objects\n[ 0.360648] CPU: 0 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #10\n[ 0.361273] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.361873] Call Trace:\n[ 0.362243] ? dump_stack+0x5c/0x81\n[ 0.362591] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.362944] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.363296] ? acpi_os_delete_cache+0xa/0x10\n[ 0.363646] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.364000] ? acpi_terminate+0xa/0x14\n[ 0.364000] ? acpi_init+0x2af/0x34f\n[ 0.364000] ? __class_create+0x4c/0x80\n[ 0.364000] ? video_setup+0x7f/0x7f\n[ 0.364000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.364000] ? do_one_initcall+0x4e/0x1a0\n[ 0.364000] ? kernel_init_freeable+0x189/0x20a\n[ 0.364000] ? rest_init+0xc0/0xc0\n[ 0.364000] ? kernel_init+0xa/0x100\n[ 0.364000] ? ret_from_fork+0x25/0x30\n\nI analyzed this memory leak in detail. I found that “Acpi-State” cache and\n“Acpi-Parse” cache were merged because the size of cache objects was same\nslab cache size.\n\nI finally found “Acpi-Parse” cache and “Acpi-parse_ext” cache were leaked\nusing SLAB_NEVER_MERGE flag in kmem_cache_create() function.\n\nReal ACPI cache leak point is as follows:\n[ 0.360101] ACPI: Added _OSI(Module Device)\n[ 0.360101] ACPI: Added _OSI(Processor Device)\n[ 0.360101] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.361043] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.364016] ACPI: Unable to start the ACPI Interpreter\n[ 0.365061] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.368174] kmem_cache_destroy Acpi-Parse: Slab cache still has objects\n[ 0.369332] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.371256] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.372000] Call Trace:\n[ 0.372000] ? dump_stack+0x5c/0x81\n[ 0.372000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.372000] ? acpi_ut_delete_caches+0x56/0x7b\n[ 0.372000] ? acpi_terminate+0xa/0x14\n[ 0.372000] ? acpi_init+0x2af/0x34f\n[ 0.372000] ? __class_create+0x4c/0x80\n[ 0.372000] ? video_setup+0x7f/0x7f\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? do_one_initcall+0x4e/0x1a0\n[ 0.372000] ? kernel_init_freeable+0x189/0x20a\n[ 0.372000] ? rest_init+0xc0/0xc0\n[ 0.372000] ? kernel_init+0xa/0x100\n[ 0.372000] ? ret_from_fork+0x25/0x30\n[ 0.388039] kmem_cache_destroy Acpi-parse_ext: Slab cache still has objects\n[ 0.389063] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.390557] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.392000] Call Trace:\n[ 0.392000] ? dump_stack+0x5c/0x81\n[ 0.392000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.392000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.392000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.392000] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.392000] ? acpi_terminate+0xa/0x14\n[ 0.392000] ? acpi_init+0x2af/0x3\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38344', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38364', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmaple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()\n\nTemporarily clear the preallocation flag when explicitly requesting\nallocations. Pre-existing allocations are already counted against the\nrequest through mas_node_count_gfp(), but the allocations will not happen\nif the MA_STATE_PREALLOC flag is set. This flag is meant to avoid\nre-allocating in bulk allocation mode, and to detect issues with\npreallocation calculations.\n\nThe MA_STATE_PREALLOC flag should also always be set on zero allocations\nso that detection of underflow allocations will print a WARN_ON() during\nconsumption.\n\nUser visible effect of this flaw is a WARN_ON() followed by a null pointer\ndereference when subsequent requests for larger number of nodes is\nignored, such as the vma merge retry in mmap_region() caused by drivers\naltering the vma flags (which happens in v6.6, at least)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38364', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38461', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_* TOCTOU\n\nTransport assignment may race with module unload. Protect new_transport\nfrom becoming a stale pointer.\n\nThis also takes care of an insecure call in vsock_use_local_transport();\nadd a lockdep assert.\n\nBUG: unable to handle page fault for address: fffffbfff8056000\nOops: Oops: 0000 [#1] SMP KASAN\nRIP: 0010:vsock_assign_transport+0x366/0x600\nCall Trace:\n vsock_connect+0x59c/0xc40\n __sys_connect+0xe8/0x100\n __x64_sys_connect+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38461', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38462', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_{g2h,h2g} TOCTOU\n\nvsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.\ntransport_{g2h,h2g} may become NULL after the NULL check.\n\nIntroduce vsock_transport_local_cid() to protect from a potential\nnull-ptr-deref.\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_find_cid+0x47/0x90\nCall Trace:\n __vsock_bind+0x4b2/0x720\n vsock_bind+0x90/0xe0\n __sys_bind+0x14d/0x1e0\n __x64_sys_bind+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_dev_do_ioctl.isra.0+0x58/0xf0\nCall Trace:\n __x64_sys_ioctl+0x12d/0x190\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38462', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38488', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in crypt_message when using async crypto\n\nThe CVE-2024-50047 fix removed asynchronous crypto handling from\ncrypt_message(), assuming all crypto operations are synchronous.\nHowever, when hardware crypto accelerators are used, this can cause\nuse-after-free crashes:\n\n crypt_message()\n // Allocate the creq buffer containing the req\n creq = smb2_get_aead_req(..., &req);\n\n // Async encryption returns -EINPROGRESS immediately\n rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);\n\n // Free creq while async operation is still in progress\n kvfree_sensitive(creq, ...);\n\nHardware crypto modules often implement async AEAD operations for\nperformance. When crypto_aead_encrypt/decrypt() returns -EINPROGRESS,\nthe operation completes asynchronously. Without crypto_wait_req(),\nthe function immediately frees the request buffer, leading to crashes\nwhen the driver later accesses the freed memory.\n\nThis results in a use-after-free condition when the hardware crypto\ndriver later accesses the freed request structure, leading to kernel\ncrashes with NULL pointer dereferences.\n\nThe issue occurs because crypto_alloc_aead() with mask=0 doesn't\nguarantee synchronous operation. Even without CRYPTO_ALG_ASYNC in\nthe mask, async implementations can be selected.\n\nFix by restoring the async crypto handling:\n- DECLARE_CRYPTO_WAIT(wait) for completion tracking\n- aead_request_set_callback() for async completion notification\n- crypto_wait_req() to wait for operation completion\n\nThis ensures the request buffer isn't freed until the crypto operation\ncompletes, whether synchronous or asynchronous, while preserving the\nCVE-2024-50047 fix.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38488', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38499', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nclone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns\n\nWhat we want is to verify there is that clone won\'t expose something\nhidden by a mount we wouldn\'t be able to undo. "Wouldn\'t be able to undo"\nmay be a result of MNT_LOCKED on a child, but it may also come from\nlacking admin rights in the userns of the namespace mount belongs to.\n\nclone_private_mnt() checks the former, but not the latter.\n\nThere\'s a number of rather confusing CAP_SYS_ADMIN checks in various\nuserns during the mount, especially with the new mount API; they serve\ndifferent purposes and in case of clone_private_mnt() they usually,\nbut not always end up covering the missing check mentioned above.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38499', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38552', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: plug races between subflow fail and subflow creation\n\nWe have races similar to the one addressed by the previous patch between\nsubflow failing and additional subflow creation. They are just harder to\ntrigger.\n\nThe solution is similar. Use a separate flag to track the condition\n'socket state prevent any additional subflow creation' protected by the\nfallback lock.\n\nThe socket fallback makes such flag true, and also receiving or sending\nan MP_FAIL option.\n\nThe field 'allow_infinite_fallback' is now always touched under the\nrelevant lock, we can drop the ONCE annotation on write.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38552', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38575', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use aead_request_free to match aead_request_alloc\n\nUse aead_request_free() instead of kfree() to properly free memory\nallocated by aead_request_alloc(). This ensures sensitive crypto data\nis zeroed before being freed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38575', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38609', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPM / devfreq: Check governor before using governor->name\n\nCommit 96ffcdf239de ("PM / devfreq: Remove redundant governor_name from\nstruct devfreq") removes governor_name and uses governor->name to replace\nit. But devfreq->governor may be NULL and directly using\ndevfreq->governor->name may cause null pointer exception. Move the check of\ngovernor to before using governor->name.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38609', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38721', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: fix refcount leak on table dump\n\nThere is a reference count leak in ctnetlink_dump_table():\n if (res < 0) {\n nf_conntrack_get(&ct->ct_general); // HERE\n cb->args[1] = (unsigned long)ct;\n ...\n\nWhile its very unlikely, its possible that ct == last.\nIf this happens, then the refcount of ct was already incremented.\nThis 2nd increment is never undone.\n\nThis prevents the conntrack object from being released, which in turn\nkeeps prevents cnet->count from dropping back to 0.\n\nThis will then block the netns dismantle (or conntrack rmmod) as\nnf_conntrack_cleanup_net_list() will wait forever.\n\nThis can be reproduced by running conntrack_resize.sh selftest in a loop.\nIt takes ~20 minutes for me on a preemptible kernel on average before\nI see a runaway kworker spinning in nf_conntrack_cleanup_net_list.\n\nOne fix would to change this to:\n if (res < 0) {\n\t\tif (ct != last)\n\t nf_conntrack_get(&ct->ct_general);\n\nBut this reference counting isn't needed in the first place.\nWe can just store a cookie value instead.\n\nA followup patch will do the same for ctnetlink_exp_dump_table,\nit looks to me as if this has the same problem and like\nctnetlink_dump_table, we only need a 'skip hint', not the actual\nobject so we can apply the same cookie strategy there as well.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38721', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39676', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla4xxx: Prevent a potential error pointer dereference\n\nThe qla4xxx_get_ep_fwdb() function is supposed to return NULL on error,\nbut qla4xxx_ep_connect() returns error pointers. Propagating the error\npointers will lead to an Oops in the caller, so change the error pointers\nto NULL.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39676', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39682', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix handling of zero-length records on the rx_list\n\nEach recvmsg() call must process either\n - only contiguous DATA records (any number of them)\n - one non-DATA record\n\nIf the next record has different type than what has already been\nprocessed we break out of the main processing loop. If the record\nhas already been decrypted (which may be the case for TLS 1.3 where\nwe don't know type until decryption) we queue the pending record\nto the rx_list. Next recvmsg() will pick it up from there.\n\nQueuing the skb to rx_list after zero-copy decrypt is not possible,\nsince in that case we decrypted directly to the user space buffer,\nand we don't have an skb to queue (darg.skb points to the ciphertext\nskb for access to metadata like length).\n\nOnly data records are allowed zero-copy, and we break the processing\nloop after each non-data record. So we should never zero-copy and\nthen find out that the record type has changed. The corner case\nwe missed is when the initial record comes from rx_list, and it's\nzero length.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39682', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39702', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39702', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39728', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: samsung: Fix UBSAN panic in samsung_clk_init()\n\nWith UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to\ndereferencing `ctx->clk_data.hws` before setting\n`ctx->clk_data.num = nr_clks`. Move that up to fix the crash.\n\n UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP\n <snip>\n Call trace:\n samsung_clk_init+0x110/0x124 (P)\n samsung_clk_init+0x48/0x124 (L)\n samsung_cmu_register_one+0x3c/0xa0\n exynos_arm64_register_cmu+0x54/0x64\n __gs101_cmu_top_of_clk_init_declare+0x28/0x60\n ...", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39728', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39756', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Prevent file descriptor table allocations exceeding INT_MAX\n\nWhen sysctl_nr_open is set to a very high value (for example, 1073741816\nas set by systemd), processes attempting to use file descriptors near\nthe limit can trigger massive memory allocation attempts that exceed\nINT_MAX, resulting in a WARNING in mm/slub.c:\n\n WARNING: CPU: 0 PID: 44 at mm/slub.c:5027 __kvmalloc_node_noprof+0x21a/0x288\n\nThis happens because kvmalloc_array() and kvmalloc() check if the\nrequested size exceeds INT_MAX and emit a warning when the allocation is\nnot flagged with __GFP_NOWARN.\n\nSpecifically, when nr_open is set to 1073741816 (0x3ffffff8) and a\nprocess calls dup2(oldfd, 1073741880), the kernel attempts to allocate:\n- File descriptor array: 1073741880 * 8 bytes = 8,589,935,040 bytes\n- Multiple bitmaps: ~400MB\n- Total allocation size: > 8GB (exceeding INT_MAX = 2,147,483,647)\n\nReproducer:\n1. Set /proc/sys/fs/nr_open to 1073741816:\n # echo 1073741816 > /proc/sys/fs/nr_open\n\n2. Run a program that uses a high file descriptor:\n #include <unistd.h>\n #include <sys/resource.h>\n\n int main() {\n struct rlimit rlim = {1073741824, 1073741824};\n setrlimit(RLIMIT_NOFILE, &rlim);\n dup2(2, 1073741880); // Triggers the warning\n return 0;\n }\n\n3. Observe WARNING in dmesg at mm/slub.c:5027\n\nsystemd commit a8b627a introduced automatic bumping of fs.nr_open to the\nmaximum possible value. The rationale was that systems with memory\ncontrol groups (memcg) no longer need separate file descriptor limits\nsince memory is properly accounted. However, this change overlooked\nthat:\n\n1. The kernel's allocation functions still enforce INT_MAX as a maximum\n size regardless of memcg accounting\n2. Programs and tests that legitimately test file descriptor limits can\n inadvertently trigger massive allocations\n3. The resulting allocations (>8GB) are impractical and will always fail\n\nsystemd's algorithm starts with INT_MAX and keeps halving the value\nuntil the kernel accepts it. On most systems, this results in nr_open\nbeing set to 1073741816 (0x3ffffff8), which is just under 1GB of file\ndescriptors.\n\nWhile processes rarely use file descriptors near this limit in normal\noperation, certain selftests (like\ntools/testing/selftests/core/unshare_test.c) and programs that test file\ndescriptor limits can trigger this issue.\n\nFix this by adding a check in alloc_fdtable() to ensure the requested\nallocation size does not exceed INT_MAX. This causes the operation to\nfail with -EMFILE instead of triggering a kernel warning and avoids the\nimpractical >8GB memory allocation request.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39756', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39770', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM\n\nWhen performing Generic Segmentation Offload (GSO) on an IPv6 packet that\ncontains extension headers, the kernel incorrectly requests checksum offload\nif the egress device only advertises NETIF_F_IPV6_CSUM feature, which has\na strict contract: it supports checksum offload only for plain TCP or UDP\nover IPv6 and explicitly does not support packets with extension headers.\nThe current GSO logic violates this contract by failing to disable the feature\nfor packets with extension headers, such as those used in GREoIPv6 tunnels.\n\nThis violation results in the device being asked to perform an operation\nit cannot support, leading to a `skb_warn_bad_offload` warning and a collapse\nof network throughput. While device TSO/USO is correctly bypassed in favor\nof software GSO for these packets, the GSO stack must be explicitly told not\nto request checksum offload.\n\nMask NETIF_F_IPV6_CSUM, NETIF_F_TSO6 and NETIF_F_GSO_UDP_L4\nin gso_features_check if the IPv6 header contains extension headers to compute\nchecksum in software.\n\nThe exception is a BIG TCP extension, which, as stated in commit\n68e068cabd2c6c53 ("net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets"):\n"The feature is only enabled on devices that support BIG TCP TSO.\nThe header is only present for PF_PACKET taps like tcpdump,\nand not transmitted by physical devices."\n\nkernel log output (truncated):\nWARNING: CPU: 1 PID: 5273 at net/core/dev.c:3535 skb_warn_bad_offload+0x81/0x140\n...\nCall Trace:\n <TASK>\n skb_checksum_help+0x12a/0x1f0\n validate_xmit_skb+0x1a3/0x2d0\n validate_xmit_skb_list+0x4f/0x80\n sch_direct_xmit+0x1a2/0x380\n __dev_xmit_skb+0x242/0x670\n __dev_queue_xmit+0x3fc/0x7f0\n ip6_finish_output2+0x25e/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_tnl_xmit+0x608/0xc00 [ip6_tunnel]\n ip6gre_tunnel_xmit+0x1c0/0x390 [ip6_gre]\n dev_hard_start_xmit+0x63/0x1c0\n __dev_queue_xmit+0x6d0/0x7f0\n ip6_finish_output2+0x214/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n inet6_csk_xmit+0xeb/0x150\n __tcp_transmit_skb+0x555/0xa80\n tcp_write_xmit+0x32a/0xe90\n tcp_sendmsg_locked+0x437/0x1110\n tcp_sendmsg+0x2f/0x50\n...\nskb linear: 00000000: e4 3d 1a 7d ec 30 e4 3d 1a 7e 5d 90 86 dd 60 0e\nskb linear: 00000010: 00 0a 1b 34 3c 40 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000020: 00 00 00 00 00 12 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000030: 00 00 00 00 00 11 2f 00 04 01 04 01 01 00 00 00\nskb linear: 00000040: 86 dd 60 0e 00 0a 1b 00 06 40 20 23 00 00 00 00\nskb linear: 00000050: 00 00 00 00 00 00 00 00 00 12 20 23 00 00 00 00\nskb linear: 00000060: 00 00 00 00 00 00 00 00 00 11 bf 96 14 51 13 f9\nskb linear: 00000070: ae 27 a0 a8 2b e3 80 18 00 40 5b 6f 00 00 01 01\nskb linear: 00000080: 08 0a 42 d4 50 d5 4b 70 f8 1a', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39770', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39812', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: initialize more fields in sctp_v6_from_sk()\n\nsyzbot found that sin6_scope_id was not properly initialized,\nleading to undefined behavior.\n\nClear sin6_scope_id and sin6_flowinfo.\n\nBUG: KMSAN: uninit-value in __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n sctp_inet6_cmp_addr+0x4f2/0x510 net/sctp/ipv6.c:983\n sctp_bind_addr_conflict+0x22a/0x3b0 net/sctp/bind_addr.c:390\n sctp_get_port_local+0x21eb/0x2440 net/sctp/socket.c:8452\n sctp_get_port net/sctp/socket.c:8523 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x710/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930\n x64_sys_call+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls_64.h:51\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable addr.i.i created at:\n sctp_get_port net/sctp/socket.c:8515 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x650/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39812', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39841', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix buffer free/clear order in deferred receive path\n\nFix a use-after-free window by correcting the buffer release sequence in\nthe deferred receive path. The code freed the RQ buffer first and only\nthen cleared the context pointer under the lock. Concurrent paths (e.g.,\nABTS and the repost path) also inspect and release the same pointer under\nthe lock, so the old order could lead to double-free/UAF.\n\nNote that the repost path already uses the correct pattern: detach the\npointer under the lock, then free it after dropping the lock. The\ndeferred path should do the same.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39841', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39894', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm\n\nWhen send a broadcast packet to a tap device, which was added to a bridge,\nbr_nf_local_in() is called to confirm the conntrack. If another conntrack\nwith the same hash value is added to the hash table, which can be\ntriggered by a normal packet to a non-bridge device, the below warning\nmay happen.\n\n ------------[ cut here ]------------\n WARNING: CPU: 1 PID: 96 at net/bridge/br_netfilter_hooks.c:632 br_nf_local_in+0x168/0x200\n CPU: 1 UID: 0 PID: 96 Comm: tap_send Not tainted 6.17.0-rc2-dirty #44 PREEMPT(voluntary)\n RIP: 0010:br_nf_local_in+0x168/0x200\n Call Trace:\n <TASK>\n nf_hook_slow+0x3e/0xf0\n br_pass_frame_up+0x103/0x180\n br_handle_frame_finish+0x2de/0x5b0\n br_nf_hook_thresh+0xc0/0x120\n br_nf_pre_routing_finish+0x168/0x3a0\n br_nf_pre_routing+0x237/0x5e0\n br_handle_frame+0x1ec/0x3c0\n __netif_receive_skb_core+0x225/0x1210\n __netif_receive_skb_one_core+0x37/0xa0\n netif_receive_skb+0x36/0x160\n tun_get_user+0xa54/0x10c0\n tun_chr_write_iter+0x65/0xb0\n vfs_write+0x305/0x410\n ksys_write+0x60/0xd0\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n ---[ end trace 0000000000000000 ]---\n\nTo solve the hash conflict, nf_ct_resolve_clash() try to merge the\nconntracks, and update skb->_nfct. However, br_nf_local_in() still use the\nold ct from local variable 'nfct' after confirm(), which leads to this\nwarning.\n\nIf confirm() does not insert the conntrack entry and return NF_DROP, the\nwarning may also occur. There is no need to reserve the WARN_ON_ONCE, just\nremove it.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39894', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39937', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer\n\nSince commit 7d5e9737efda ("net: rfkill: gpio: get the name and type from\ndevice property") rfkill_find_type() gets called with the possibly\nuninitialized "const char *type_name;" local variable.\n\nOn x86 systems when rfkill-gpio binds to a "BCM4752" or "LNV4752"\nacpi_device, the rfkill->type is set based on the ACPI acpi_device_id:\n\n rfkill->type = (unsigned)id->driver_data;\n\nand there is no "type" property so device_property_read_string() will fail\nand leave type_name uninitialized, leading to a potential crash.\n\nrfkill_find_type() does accept a NULL pointer, fix the potential crash\nby initializing type_name to NULL.\n\nNote likely sofar this has not been caught because:\n\n1. Not many x86 machines actually have a "BCM4752"/"LNV4752" acpi_device\n2. The stack happened to contain NULL where type_name is stored', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39937', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39955', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().\n\nsyzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk\nin the TCP_ESTABLISHED state. [0]\n\nsyzbot reused the server-side TCP Fast Open socket as a new client before\nthe TFO socket completes 3WHS:\n\n 1. accept()\n 2. connect(AF_UNSPEC)\n 3. connect() to another destination\n\nAs of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes\nit to TCP_CLOSE and makes connect() possible, which restarts timers.\n\nSince tcp_disconnect() forgot to clear tcp_sk(sk)->fastopen_rsk, the\nretransmit timer triggered the warning and the intended packet was not\nretransmitted.\n\nLet's call reqsk_fastopen_remove() in tcp_disconnect().\n\n[0]:\nWARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nModules linked in:\nCPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nCode: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 <0f> 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e\nRSP: 0018:ffffc900002f8d40 EFLAGS: 00010293\nRAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017\nRDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400\nRBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8\nR10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540\nR13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0\nFS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0\nCall Trace:\n <IRQ>\n tcp_write_timer (net/ipv4/tcp_timer.c:738)\n call_timer_fn (kernel/time/timer.c:1747)\n __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2372)\n timer_expire_remote (kernel/time/timer.c:2385 kernel/time/timer.c:2376 kernel/time/timer.c:2135)\n tmigr_handle_remote_up (kernel/time/timer_migration.c:944 kernel/time/timer_migration.c:1035)\n __walk_groups.isra.0 (kernel/time/timer_migration.c:533 (discriminator 1))\n tmigr_handle_remote (kernel/time/timer_migration.c:1096)\n handle_softirqs (./arch/x86/include/asm/jump_label.h:36 ./include/trace/events/irq.h:142 kernel/softirq.c:580)\n irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680 kernel/softirq.c:696)\n sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 (discriminator 35) arch/x86/kernel/apic/apic.c:1050 (discriminator 35))\n </IRQ>", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39955', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39980', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Forbid FDB status change while nexthop is in a group\n\nThe kernel forbids the creation of non-FDB nexthop groups with FDB\nnexthops:\n\n # ip nexthop add id 1 via 192.0.2.1 fdb\n # ip nexthop add id 2 group 1\n Error: Non FDB nexthop group cannot have fdb nexthops.\n\nAnd vice versa:\n\n # ip nexthop add id 3 via 192.0.2.2 dev dummy1\n # ip nexthop add id 4 group 3 fdb\n Error: FDB nexthop group can only have fdb nexthops.\n\nHowever, as long as no routes are pointing to a non-FDB nexthop group,\nthe kernel allows changing the type of a nexthop from FDB to non-FDB and\nvice versa:\n\n # ip nexthop add id 5 via 192.0.2.2 dev dummy1\n # ip nexthop add id 6 group 5\n # ip nexthop replace id 5 via 192.0.2.2 fdb\n # echo $?\n 0\n\nThis configuration is invalid and can result in a NPD [1] since FDB\nnexthops are not associated with a nexthop device:\n\n # ip route add 198.51.100.1/32 nhid 6\n # ping 198.51.100.1\n\nFix by preventing nexthop FDB status change while the nexthop is in a\ngroup:\n\n # ip nexthop add id 7 via 192.0.2.2 dev dummy1\n # ip nexthop add id 8 group 7\n # ip nexthop replace id 7 via 192.0.2.2 fdb\n Error: Cannot change nexthop FDB status while in a group.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 00000000000003c0\n[...]\nOops: Oops: 0000 [#1] SMP\nCPU: 6 UID: 0 PID: 367 Comm: ping Not tainted 6.17.0-rc6-virtme-gb65678cacc03 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\nRIP: 0010:fib_lookup_good_nhc+0x1e/0x80\n[...]\nCall Trace:\n <TASK>\n fib_table_lookup+0x541/0x650\n ip_route_output_key_hash_rcu+0x2ea/0x970\n ip_route_output_key_hash+0x55/0x80\n __ip4_datagram_connect+0x250/0x330\n udp_connect+0x2b/0x60\n __sys_connect+0x9c/0xd0\n __x64_sys_connect+0x18/0x20\n do_syscall_64+0xa4/0x2a0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39980', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40018', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: Defer ip_vs_ftp unregister during netns cleanup\n\nOn the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp\nbefore connections with valid cp->app pointers are flushed, leading to a\nuse-after-free.\n\nFix this by introducing a global `exiting_module` flag, set to true in\nip_vs_ftp_exit() before unregistering the pernet subsystem. In\n__ip_vs_ftp_exit(), skip ip_vs_ftp unregister if called during netns\ncleanup (when exiting_module is false) and defer it to\n__ip_vs_cleanup_batch(), which unregisters all apps after all connections\nare flushed. If called during module exit, unregister ip_vs_ftp\nimmediately.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40018', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40062', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs\n\nWhen the initialization of qm->debug.acc_diff_reg fails,\nthe probe process does not exit. However, after qm->debug.qm_diff_regs is\nfreed, it is not set to NULL. This can lead to a double free when the\nremove process attempts to free it again. Therefore, qm->debug.qm_diff_regs\nshould be set to NULL after it is freed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40062', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40078', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n 0: r0 = 0\n 1: r2 = *(u32 *)(r1 +60)\n 2: exit\n\nwhich triggers:\n\n verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn't rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn't find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40078', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40136', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - request reserved interrupt for virtual function\n\nThe device interrupt vector 3 is an error interrupt for\nphysical function and a reserved interrupt for virtual function.\nHowever, the driver has not registered the reserved interrupt for\nvirtual function. When allocating interrupts, the number of interrupts\nis allocated based on powers of two, which includes this interrupt.\nWhen the system enables GICv4 and the virtual function passthrough\nto the virtual machine, releasing the interrupt in the driver\ntriggers a warning.\n\nThe WARNING report is:\nWARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4\n\nTherefore, register a reserved interrupt for VF and set the\nIRQF_NO_AUTOEN flag to avoid that warning.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40136', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40240', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid NULL dereference when chunk data buffer is missing\n\nchunk->skb pointer is dereferenced in the if-block where it's supposed\nto be NULL only.\n\nchunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list\ninstead and do it just before replacing chunk->skb. We're sure that\notherwise chunk->skb is non-NULL because of outer if() condition.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40240', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40254', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: remove never-working support for setting nsh fields\n\nThe validation of the set(nsh(...)) action is completely wrong.\nIt runs through the nsh_key_put_from_nlattr() function that is the\nsame function that validates NSH keys for the flow match and the\npush_nsh() action. However, the set(nsh(...)) has a very different\nmemory layout. Nested attributes in there are doubled in size in\ncase of the masked set(). That makes proper validation impossible.\n\nThere is also confusion in the code between the 'masked' flag, that\nsays that the nested attributes are doubled in size containing both\nthe value and the mask, and the 'is_mask' that says that the value\nwe're parsing is the mask. This is causing kernel crash on trying to\nwrite into mask part of the match with SW_FLOW_KEY_PUT() during\nvalidation, while validate_nsh() doesn't allocate any memory for it:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000018\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0\n Oops: Oops: 0000 [#1] SMP NOPTI\n CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary)\n RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch]\n Call Trace:\n <TASK>\n validate_nsh+0x60/0x90 [openvswitch]\n validate_set.constprop.0+0x270/0x3c0 [openvswitch]\n __ovs_nla_copy_actions+0x477/0x860 [openvswitch]\n ovs_nla_copy_actions+0x8d/0x100 [openvswitch]\n ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch]\n genl_family_rcv_msg_doit+0xdb/0x130\n genl_family_rcv_msg+0x14b/0x220\n genl_rcv_msg+0x47/0xa0\n netlink_rcv_skb+0x53/0x100\n genl_rcv+0x24/0x40\n netlink_unicast+0x280/0x3b0\n netlink_sendmsg+0x1f7/0x430\n ____sys_sendmsg+0x36b/0x3a0\n ___sys_sendmsg+0x87/0xd0\n __sys_sendmsg+0x6d/0xd0\n do_syscall_64+0x7b/0x2c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe third issue with this process is that while trying to convert\nthe non-masked set into masked one, validate_set() copies and doubles\nthe size of the OVS_KEY_ATTR_NSH as if it didn't have any nested\nattributes. It should be copying each nested attribute and doubling\nthem in size independently. And the process must be properly reversed\nduring the conversion back from masked to a non-masked variant during\nthe flow dump.\n\nIn the end, the only two outcomes of trying to use this action are\neither validation failure or a kernel crash. And if somehow someone\nmanages to install a flow with such an action, it will most definitely\nnot do what it is supposed to, since all the keys and the masks are\nmixed up.\n\nFixing all the issues is a complex task as it requires re-writing\nmost of the validation code.\n\nGiven that and the fact that this functionality never worked since\nintroduction, let's just remove it altogether. It's better to\nre-introduce it later with a proper implementation instead of trying\nto fix it in stable releases.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40254', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40280', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Fix use-after-free in tipc_mon_reinit_self().\n\nsyzbot reported use-after-free of tipc_net(net)->monitors[]\nin tipc_mon_reinit_self(). [0]\n\nThe array is protected by RTNL, but tipc_mon_reinit_self()\niterates over it without RTNL.\n\ntipc_mon_reinit_self() is called from tipc_net_finalize(),\nwhich is always under RTNL except for tipc_net_finalize_work().\n\nLet's hold RTNL in tipc_net_finalize_work().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\nBUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\nRead of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989\n\nCPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)}\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025\nWorkqueue: events tipc_net_finalize_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568\n kasan_check_byte include/linux/kasan.h:399 [inline]\n lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\n rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline]\n rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline]\n rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244\n rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243\n write_lock_bh include/linux/rwlock_rt.h:99 [inline]\n tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718\n tipc_net_finalize+0x115/0x190 net/tipc/net.c:140\n process_one_work kernel/workqueue.c:3236 [inline]\n process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319\n worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400\n kthread+0x70e/0x8a0 kernel/kthread.c:463\n ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>\n\nAllocated by task 6089:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:388 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407\n kmalloc_noprof include/linux/slab.h:905 [inline]\n kzalloc_noprof include/linux/slab.h:1039 [inline]\n tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657\n tipc_enable_bearer net/tipc/bearer.c:357 [inline]\n __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047\n __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline]\n tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393\n tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline]\n tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321\n genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]\n netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346\n netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896\n sock_sendmsg_nosec net/socket.c:714 [inline]\n __sock_sendmsg+0x21c/0x270 net/socket.c:729\n ____sys_sendmsg+0x508/0x820 net/socket.c:2614\n ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668\n __sys_sendmsg net/socket.c:2700 [inline]\n __do_sys_sendmsg net/socket.c:2705 [inline]\n __se_sys_sendmsg net/socket.c:2703 [inline]\n __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40280', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40281', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto\n\nsyzbot reported a possible shift-out-of-bounds [1]\n\nBlamed commit added rto_alpha_max and rto_beta_max set to 1000.\n\nIt is unclear if some sctp users are setting very large rto_alpha\nand/or rto_beta.\n\nIn order to prevent user regression, perform the test at run time.\n\nAlso add READ_ONCE() annotations as sysctl values can change under us.\n\n[1]\n\nUBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41\nshift exponent 64 is too large for 32-bit type 'unsigned int'\nCPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120\n ubsan_epilogue lib/ubsan.c:233 [inline]\n __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494\n sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509\n sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502\n sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338\n sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline]\n sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40281', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40331', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Prevent TOCTOU out-of-bounds write\n\nFor the following path not holding the sock lock,\n\n sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump()\n\nmake sure not to exceed bounds in case the address list has grown\nbetween buffer allocation (time-of-check) and write (time-of-use).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40331', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68283', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: replace BUG_ON with bounds check for map->max_osd\n\nOSD indexes come from untrusted network packets. Boundary checks are\nadded to validate these against map->max_osd.\n\n[ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic\n edits ]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68283', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68284', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()\n\nThe len field originates from untrusted network packets. Boundary\nchecks have been added to prevent potential out-of-bounds writes when\ndecrypting the connection secret or processing service tickets.\n\n[ idryomov: changelog ]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68284', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68285', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix potential use-after-free in have_mon_and_osd_map()\n\nThe wait loop in __ceph_open_session() can race with the client\nreceiving a new monmap or osdmap shortly after the initial map is\nreceived. Both ceph_monc_handle_map() and handle_one_map() install\na new map immediately after freeing the old one\n\n kfree(monc->monmap);\n monc->monmap = monmap;\n\n ceph_osdmap_destroy(osdc->osdmap);\n osdc->osdmap = newmap;\n\nunder client->monc.mutex and client->osdc.lock respectively, but\nbecause neither is taken in have_mon_and_osd_map() it's possible for\nclient->monc.monmap->epoch and client->osdc.osdmap->epoch arms in\n\n client->monc.monmap && client->monc.monmap->epoch &&\n client->osdc.osdmap && client->osdc.osdmap->epoch;\n\ncondition to dereference an already freed map. This happens to be\nreproducible with generic/395 and generic/397 with KASAN enabled:\n\n BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70\n Read of size 4 at addr ffff88811012d810 by task mount.ceph/13305\n CPU: 2 UID: 0 PID: 13305 Comm: mount.ceph Not tainted 6.14.0-rc2-build2+ #1266\n ...\n Call Trace:\n <TASK>\n have_mon_and_osd_map+0x56/0x70\n ceph_open_session+0x182/0x290\n ceph_get_tree+0x333/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\n Allocated by task 13305:\n ceph_osdmap_alloc+0x16/0x130\n ceph_osdc_init+0x27a/0x4c0\n ceph_create_client+0x153/0x190\n create_fs_client+0x50/0x2a0\n ceph_get_tree+0xff/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 9475:\n kfree+0x212/0x290\n handle_one_map+0x23c/0x3b0\n ceph_osdc_handle_map+0x3c9/0x590\n mon_dispatch+0x655/0x6f0\n ceph_con_process_message+0xc3/0xe0\n ceph_con_v1_try_read+0x614/0x760\n ceph_con_workfn+0x2de/0x650\n process_one_work+0x486/0x7c0\n process_scheduled_works+0x73/0x90\n worker_thread+0x1c8/0x2a0\n kthread+0x2ec/0x300\n ret_from_fork+0x24/0x40\n ret_from_fork_asm+0x1a/0x30\n\nRewrite the wait loop to check the above condition directly with\nclient->monc.mutex and client->osdc.lock taken as appropriate. While\nat it, improve the timeout handling (previously mount_timeout could be\nexceeded in case wait_event_interruptible_timeout() slept more than\nonce) and access client->auth_err under client->monc.mutex to match\nhow it's set in finish_auth().\n\nmonmap_show() and osdmap_show() now take the respective lock before\naccessing the map as well.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68285', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68304', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: lookup hci_conn on RX path on protocol side\n\nThe hdev lock/lookup/unlock/use pattern in the packet RX path doesn\'t\nensure hci_conn* is not concurrently modified/deleted. This locking\nappears to be leftover from before conn_hash started using RCU\ncommit bf4c63252490b ("Bluetooth: convert conn hash to RCU")\nand not clear if it had purpose since then.\n\nCurrently, there are code paths that delete hci_conn* from elsewhere\nthan the ordered hdev->workqueue where the RX work runs in. E.g.\ncommit 5af1f84ed13a ("Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync")\nintroduced some of these, and there probably were a few others before\nit. It\'s better to do the locking so that even if these run\nconcurrently no UAF is possible.\n\nMove the lookup of hci_conn and associated socket-specific conn to\nprotocol recv handlers, and do them within a single critical section\nto cover hci_conn* usage and lookup.\n\nsyzkaller has reported a crash that appears to be this issue:\n\n [Task hdev->workqueue] [Task 2]\n hci_disconnect_all_sync\n l2cap_recv_acldata(hcon)\n hci_conn_get(hcon)\n hci_abort_conn_sync(hcon)\n hci_dev_lock\n hci_dev_lock\n hci_conn_del(hcon)\n v-------------------------------- hci_dev_unlock\n hci_conn_put(hcon)\n conn = hcon->l2cap_data (UAF)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68740', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nima: Handle error code returned by ima_filter_rule_match()\n\nIn ima_match_rules(), if ima_filter_rule_match() returns -ENOENT due to\nthe rule being NULL, the function incorrectly skips the 'if (!rc)' check\nand sets 'result = true'. The LSM rule is considered a match, causing\nextra files to be measured by IMA.\n\nThis issue can be reproduced in the following scenario:\nAfter unloading the SELinux policy module via 'semodule -d', if an IMA\nmeasurement is triggered before ima_lsm_rules is updated,\nin ima_match_rules(), the first call to ima_filter_rule_match() returns\n-ESTALE. This causes the code to enter the 'if (rc == -ESTALE &&\n!rule_reinitialized)' block, perform ima_lsm_copy_rule() and retry. In\nima_lsm_copy_rule(), since the SELinux module has been removed, the rule\nbecomes NULL, and the second call to ima_filter_rule_match() returns\n-ENOENT. This bypasses the 'if (!rc)' check and results in a false match.\n\nCall trace:\n selinux_audit_rule_match+0x310/0x3b8\n security_audit_rule_match+0x60/0xa0\n ima_match_rules+0x2e4/0x4a0\n ima_match_policy+0x9c/0x1e8\n ima_get_action+0x48/0x60\n process_measurement+0xf8/0xa98\n ima_bprm_check+0x98/0xd8\n security_bprm_check+0x5c/0x78\n search_binary_handler+0x6c/0x318\n exec_binprm+0x58/0x1b8\n bprm_execve+0xb8/0x130\n do_execveat_common.isra.0+0x1a8/0x258\n __arm64_sys_execve+0x48/0x68\n invoke_syscall+0x50/0x128\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x44/0x200\n el0t_64_sync_handler+0x100/0x130\n el0t_64_sync+0x3c8/0x3d0\n\nFix this by changing 'if (!rc)' to 'if (rc <= 0)' to ensure that error\ncodes like -ENOENT do not bypass the check and accidentally result in a\nsuccessful match.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68740', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68742', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix invalid prog->stats access when update_effective_progs fails\n\nSyzkaller triggers an invalid memory access issue following fault\ninjection in update_effective_progs. The issue can be described as\nfollows:\n\n__cgroup_bpf_detach\n update_effective_progs\n compute_effective_progs\n bpf_prog_array_alloc <-- fault inject\n purge_effective_progs\n /* change to dummy_bpf_prog */\n array->items[index] = &dummy_bpf_prog.prog\n\n---softirq start---\n__do_softirq\n ...\n __cgroup_bpf_run_filter_skb\n __bpf_prog_run_save_cb\n bpf_prog_run\n stats = this_cpu_ptr(prog->stats)\n /* invalid memory access */\n flags = u64_stats_update_begin_irqsave(&stats->syncp)\n---softirq end---\n\n static_branch_dec(&cgroup_bpf_enabled_key[atype])\n\nThe reason is that fault injection caused update_effective_progs to fail\nand then changed the original prog into dummy_bpf_prog.prog in\npurge_effective_progs. Then a softirq came, and accessing the members of\ndummy_bpf_prog.prog in the softirq triggers invalid mem access.\n\nTo fix it, skip updating stats when stats is NULL.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68742', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68795', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: Avoid overflowing userspace buffer on stats query\n\nThe ethtool -S command operates across three ioctl calls:\nETHTOOL_GSSET_INFO for the size, ETHTOOL_GSTRINGS for the names, and\nETHTOOL_GSTATS for the values.\n\nIf the number of stats changes between these calls (e.g., due to device\nreconfiguration), userspace\'s buffer allocation will be incorrect,\npotentially leading to buffer overflow.\n\nDrivers are generally expected to maintain stable stat counts, but some\ndrivers (e.g., mlx5, bnx2x, bna, ksz884x) use dynamic counters, making\nthis scenario possible.\n\nSome drivers try to handle this internally:\n- bnad_get_ethtool_stats() returns early in case stats.n_stats is not\n equal to the driver\'s stats count.\n- micrel/ksz884x also makes sure not to write anything beyond\n stats.n_stats and overflow the buffer.\n\nHowever, both use stats.n_stats which is already assigned with the value\nreturned from get_sset_count(), hence won\'t solve the issue described\nhere.\n\nChange ethtool_get_strings(), ethtool_get_stats(),\nethtool_get_phy_stats() to not return anything in case of a mismatch\nbetween userspace\'s size and get_sset_size(), to prevent buffer\noverflow.\nThe returned n_stats value will be equal to zero, to reflect that\nnothing has been returned.\n\nThis could result in one of two cases when using upstream ethtool,\ndepending on when the size change is detected:\n1. When detected in ethtool_get_strings():\n # ethtool -S eth2\n no stats available\n\n2. When detected in get stats, all stats will be reported as zero.\n\nBoth cases are presumably transient, and a subsequent ethtool call\nshould succeed.\n\nOther than the overflow avoidance, these two cases are very evident (no\noutput/cleared stats), which is arguably better than presenting\nincorrect/shifted stats.\nI also considered returning an error instead of a "silent" response, but\nthat seems more destructive towards userspace apps.\n\nNotes:\n- This patch does not claim to fix the inherent race, it only makes sure\n that we do not overflow the userspace buffer, and makes for a more\n predictable behavior.\n\n- RTNL lock is held during each ioctl, the race window exists between\n the separate ioctl calls when the lock is released.\n\n- Userspace ethtool always fills stats.n_stats, but it is likely that\n these stats ioctls are implemented in other userspace applications\n which might not fill it. The added code checks that it\'s not zero,\n to prevent any regressions.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68795', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68820', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: xattr: fix null pointer deref in ext4_raw_inode()\n\nIf ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),\niloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()\nlacks error checking, this will lead to a null pointer dereference\nin ext4_raw_inode(), called right after ext4_get_inode_loc().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68820', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-71064', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-71064', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-22976', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset\n\n`qfq_class->leaf_qdisc->q.qlen > 0` does not imply that the class\nitself is active.\n\nTwo qfq_class objects may point to the same leaf_qdisc. This happens\nwhen:\n\n1. one QFQ qdisc is attached to the dev as the root qdisc, and\n\n2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get()\n/ qdisc_put()) and is pending to be destroyed, as in function\ntc_new_tfilter.\n\nWhen packets are enqueued through the root QFQ qdisc, the shared\nleaf_qdisc->q.qlen increases. At the same time, the second QFQ\nqdisc triggers qdisc_put and qdisc_destroy: the qdisc enters\nqfq_reset() with its own q->q.qlen == 0, but its class's leaf\nqdisc->q.qlen > 0. Therefore, the qfq_reset would wrongly deactivate\nan inactive aggregate and trigger a null-deref in qfq_deactivate_agg:\n\n[ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 0.903571] #PF: supervisor write access in kernel mode\n[ 0.903860] #PF: error_code(0x0002) - not-present page\n[ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0\n[ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI\n[ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE\n[ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2))\n[ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0\n\nCode starting with the faulting instruction\n===========================================\n 0:\t0f 84 4d 01 00 00 \tje 0x153\n 6:\t48 89 70 18 \tmov %rsi,0x18(%rax)\n a:\t8b 4b 10 \tmov 0x10(%rbx),%ecx\n d:\t48 c7 c2 ff ff ff ff \tmov $0xffffffffffffffff,%rdx\n 14:\t48 8b 78 08 \tmov 0x8(%rax),%rdi\n 18:\t48 d3 e2 \tshl %cl,%rdx\n 1b:\t48 21 f2 \tand %rsi,%rdx\n 1e:\t48 2b 13 \tsub (%rbx),%rdx\n 21:\t48 8b 30 \tmov (%rax),%rsi\n 24:\t48 d3 ea \tshr %cl,%rdx\n 27:\t8b 4b 18 \tmov 0x18(%rbx),%ecx\n\t...\n[ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246\n[ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000\n[ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000\n[ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000\n[ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880\n[ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000\n[ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0\n[ 0.910247] PKRU: 55555554\n[ 0.910391] Call Trace:\n[ 0.910527] <TASK>\n[ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485)\n[ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036)\n[ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076)\n[ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447)\n[ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\n[ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861)\n[ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550)\n[ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\n[ 0.912296] ? __alloc_skb (net/core/skbuff.c:706)\n[ 0.912484] netlink_sendmsg (net/netlink/af\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-22976', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-22994', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix reference count leak in bpf_prog_test_run_xdp()\n\nsyzbot is reporting\n\n unregister_netdevice: waiting for sit0 to become free. Usage count = 2\n\nproblem. A debug printk() patch found that a refcount is obtained at\nxdp_convert_md_to_buff() from bpf_prog_test_run_xdp().\n\nAccording to commit ec94670fcb3b ("bpf: Support specifying ingress via\nxdp_md context in BPF_PROG_TEST_RUN"), the refcount obtained by\nxdp_convert_md_to_buff() will be released by xdp_convert_buff_to_md().\n\nTherefore, we can consider that the error handling path introduced by\ncommit 1c1949982524 ("bpf: introduce frags support to\nbpf_prog_test_run_xdp()") forgot to call xdp_convert_buff_to_md().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-22994', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23053', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a deadlock involving nfs_release_folio()\n\nWang Zhaolong reports a deadlock involving NFSv4.1 state recovery\nwaiting on kthreadd, which is attempting to reclaim memory by calling\nnfs_release_folio(). The latter cannot make progress due to state\nrecovery being needed.\n\nIt seems that the only safe thing to do here is to kick off a writeback\nof the folio, without waiting for completion, or else kicking off an\nasynchronous commit.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23053', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23056', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nuacce: implement mremap in uacce_vm_ops to return -EPERM\n\nThe current uacce_vm_ops does not support the mremap operation of\nvm_operations_struct. Implement .mremap to return -EPERM to remind\nusers.\n\nThe reason we need to explicitly disable mremap is that when the\ndriver does not implement .mremap, it uses the default mremap\nmethod. This could lead to a risk scenario:\n\nAn application might first mmap address p1, then mremap to p2,\nfollowed by munmap(p1), and finally munmap(p2). Since the default\nmremap copies the original vma's vm_private_data (i.e., q) to the\nnew vma, both munmap operations would trigger vma_close, causing\nq->qfr to be freed twice(qfr will be set to null here, so repeated\nrelease is ok).", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23056', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23063', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuacce: ensure safe queue release with state management\n\nDirectly calling `put_queue` carries risks since it cannot\nguarantee that resources of `uacce_queue` have been fully released\nbeforehand. So adding a `stop_queue` operation for the\nUACCE_CMD_PUT_Q command and leaving the `put_queue` operation to\nthe final resource release ensures safety.\n\nQueue states are defined as follows:\n- UACCE_Q_ZOMBIE: Initial state\n- UACCE_Q_INIT: After opening `uacce`\n- UACCE_Q_STARTED: After `start` is issued via `ioctl`\n\nWhen executing `poweroff -f` in virt while accelerator are still\nworking, `uacce_fops_release` and `uacce_remove` may execute\nconcurrently. This can cause `uacce_put_queue` within\n`uacce_fops_release` to access a NULL `ops` pointer. Therefore, add\nstate checks to prevent accessing freed pointers.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23063', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23253', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen\n\ndvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the\nDVR device. dvb_ringbuffer_init() calls init_waitqueue_head(), which\nreinitializes the waitqueue list head to empty.\n\nSince dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the\nsame DVR device share it), this orphans any existing waitqueue entries\nfrom io_uring poll or epoll, leaving them with stale prev/next pointers\nwhile the list head is reset to {self, self}.\n\nThe waitqueue and spinlock in dvr_buffer are already properly\ninitialized once in dvb_dmxdev_init(). The open path only needs to\nreset the buffer data pointer, size, and read/write positions.\n\nReplace the dvb_ringbuffer_init() call in dvb_dvr_open() with direct\nassignment of data/size and a call to dvb_ringbuffer_reset(), which\nproperly resets pread, pwrite, and error with correct memory ordering\nwithout touching the waitqueue or spinlock.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23253', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23260', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: maple: free entry on mas_store_gfp() failure\n\nregcache_maple_write() allocates a new block ('entry') to merge\nadjacent ranges and then stores it with mas_store_gfp().\nWhen mas_store_gfp() fails, the new 'entry' remains allocated and\nis never freed, leaking memory.\n\nFree 'entry' on the failure path; on success continue freeing the\nreplaced neighbor blocks ('lower', 'upper').", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23268', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix unprivileged local user can do privileged policy management\n\nAn unprivileged local user can load, replace, and remove profiles by\nopening the apparmorfs interfaces, via a confused deputy attack, by\npassing the opened fd to a privileged process, and getting the\nprivileged process to write to the interface.\n\nThis does require a privileged target that can be manipulated to do\nthe write for the unprivileged process, but once such access is\nachieved full policy management is possible and all the possible\nimplications that implies: removing confinement, DoS of system or\ntarget applications by denying all execution, by-passing the\nunprivileged user namespace restriction, to exploiting kernel bugs for\na local privilege escalation.\n\nThe policy management interface can not have its permissions simply\nchanged from 0666 to 0600 because non-root processes need to be able\nto load policy to different policy namespaces.\n\nInstead ensure the task writing the interface has privileges that\nare a subset of the task that opened the interface. This is already\ndone via policy for confined processes, but unconfined can delegate\naccess to the opened fd, by-passing the usual policy check.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23268', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23271', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix __perf_event_overflow() vs perf_remove_from_context() race\n\nMake sure that __perf_event_overflow() runs with IRQs disabled for all\npossible callchains. Specifically the software events can end up running\nit with only preemption disabled.\n\nThis opens up a race vs perf_event_exit_event() and friends that will go\nand free various things the overflow path expects to be present, like\nthe BPF program.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23271', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23273', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: observe an RCU grace period in macvlan_common_newlink() error path\n\nvalis reported that a race condition still happens after my prior patch.\n\nmacvlan_common_newlink() might have made @dev visible before\ndetecting an error, and its caller will directly call free_netdev(dev).\n\nWe must respect an RCU period, either in macvlan or the core networking\nstack.\n\nAfter adding a temporary mdelay(1000) in macvlan_forward_source_one()\nto open the race window, valis repro was:\n\nip link add p1 type veth peer p2\nip link set address 00:00:00:00:00:20 dev p1\nip link set up dev p1\nip link set up dev p2\nip link add mv0 link p2 type macvlan mode source\n\n(ip link add invalid% link p2 type macvlan mode source macaddr add\n00:00:00:00:00:20 &) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4\nPING 1.2.3.4 (1.2.3.4): 56 data bytes\nRTNETLINK answers: Invalid argument\n\nBUG: KASAN: slab-use-after-free in macvlan_forward_source\n(drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nRead of size 8 at addr ffff888016bb89c0 by task e/175\n\nCPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n<IRQ>\ndump_stack_lvl (lib/dump_stack.c:123)\nprint_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nkasan_report (mm/kasan/report.c:597)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nmacvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\n? tasklet_init (kernel/softirq.c:983)\nmacvlan_handle_frame (drivers/net/macvlan.c:501)\n\nAllocated by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\n__kasan_kmalloc (mm/kasan/common.c:419)\n__kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657\nmm/slub.c:7140)\nalloc_netdev_mqs (net/core/dev.c:12012)\nrtnl_create_link (net/core/rtnetlink.c:3648)\nrtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)\n\nFreed by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\nkasan_save_free_info (mm/kasan/generic.c:587)\n__kasan_slab_free (mm/kasan/common.c:287)\nkfree (mm/slub.c:6674 mm/slub.c:6882)\nrtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23273', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31447', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31447', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43047', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report's feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn't, omit reporting the raw event and\nreturn early.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43047', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43048', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43048', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43407', 'notes': [{'text': 'In the Linux kernel, there is a potential out-of-bounds access vulnerability in the ceph_handle_auth_reply() function of the libceph component. When processing messages of type CEPH_MSG_AUTH_REPLY, the value of the payload_len field is stored in a variable of type int. A value greater than INT_MAX leads to integer overflow and is interpreted as a negative value, which causes the pointer address to be decremented and subsequently accessed because ceph_decode_need() only checks that the memory access does not exceed the end address of the allocation. The vulnerability is fixed by changing the data type of payload_len to u32 and introducing additional sanity checks.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43407', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2417', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
0b191c98c998c467d00aa7b099408cd35f1e2ed6507a43b93369e540c4b2831e
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2418
An update for kernel is now available for openEuler-24.03-LTS-SP1
Critical
2026-05-22 16:22:06+03:00
2026-05-22 16:22:06+03:00
['CVE-2024-56611', 'CVE-2024-56760', 'CVE-2025-21908', 'CVE-2025-21931', 'CVE-2025-21970', 'CVE-2025-21971', 'CVE-2025-21980', 'CVE-2025-21981', 'CVE-2025-21986', 'CVE-2025-21995', 'CVE-2025-22001', 'CVE-2025-22009', 'CVE-2025-22071', 'CVE-2025-22077', 'CVE-2025-23138', 'CVE-2025-23157', 'CVE-2025-37740', 'CVE-2025-37748', 'CVE-2025-37766', 'CVE-2025-37768', 'CVE-2025-37770', 'CVE-2025-37771', 'CVE-2025-37778', 'CVE-2025-37793', 'CVE-2025-37805', 'CVE-2025-37815', 'CVE-2025-37831', 'CVE-2025-37844', 'CVE-2025-37853', 'CVE-2025-37881', 'CVE-2025-37889', 'CVE-2025-37905', 'CVE-2025-37918', 'CVE-2025-37947', 'CVE-2025-37967', 'CVE-2025-38014', 'CVE-2025-38037', 'CVE-2025-38043', 'CVE-2025-38051', 'CVE-2025-38064', 'CVE-2025-38113', 'CVE-2025-38122', 'CVE-2025-38123', 'CVE-2025-38131', 'CVE-2025-38148', 'CVE-2025-38161', 'CVE-2025-38183', 'CVE-2025-38193', 'CVE-2025-38194', 'CVE-2025-38241', 'CVE-2025-38255', 'CVE-2025-38304', 'CVE-2025-38307', 'CVE-2025-38321', 'CVE-2025-38344', 'CVE-2025-38364', 'CVE-2025-38461', 'CVE-2025-38462', 'CVE-2025-38488', 'CVE-2025-38499', 'CVE-2025-38552', 'CVE-2025-38575', 'CVE-2025-38609', 'CVE-2025-38721', 'CVE-2025-39676', 'CVE-2025-39682', 'CVE-2025-39702', 'CVE-2025-39728', 'CVE-2025-39756', 'CVE-2025-39770', 'CVE-2025-39812', 'CVE-2025-39841', 'CVE-2025-39894', 'CVE-2025-39937', 'CVE-2025-39955', 'CVE-2025-39980', 'CVE-2025-40018', 'CVE-2025-40062', 'CVE-2025-40078', 'CVE-2025-40136', 'CVE-2025-40240', 'CVE-2025-40254', 'CVE-2025-40280', 'CVE-2025-40281', 'CVE-2025-40331', 'CVE-2025-68283', 'CVE-2025-68284', 'CVE-2025-68285', 'CVE-2025-68304', 'CVE-2025-68740', 'CVE-2025-68742', 'CVE-2025-68795', 'CVE-2025-68820', 'CVE-2025-71064', 'CVE-2026-22976', 'CVE-2026-22994', 'CVE-2026-23053', 'CVE-2026-23253', 'CVE-2026-23260', 'CVE-2026-23268', 'CVE-2026-23271', 'CVE-2026-23273', 'CVE-2026-23292', 'CVE-2026-23296', 'CVE-2026-23313', 'CVE-2026-23317', 'CVE-2026-23319', 'CVE-2026-23352', 'CVE-2026-23359', 'CVE-2026-23360', 'CVE-2026-23374', 'CVE-2026-23383', 'CVE-2026-23388', 'CVE-2026-31447', 'CVE-2026-43047', 'CVE-2026-43048', 'CVE-2026-43053', 'CVE-2026-43147', 'CVE-2026-43261', 'CVE-2026-43289', 'CVE-2026-43407', 'CVE-2026-43470']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1', 'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src.rpm', 'product_id': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'summary': 'openEuler-SA-2026-2418', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56611&packageName=kernel', 'summary': 'CVE-2024-56611', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56760&packageName=kernel', 'summary': 'CVE-2024-56760', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21908&packageName=kernel', 'summary': 'CVE-2025-21908', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21931&packageName=kernel', 'summary': 'CVE-2025-21931', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21970&packageName=kernel', 'summary': 'CVE-2025-21970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21971&packageName=kernel', 'summary': 'CVE-2025-21971', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21980&packageName=kernel', 'summary': 'CVE-2025-21980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21981&packageName=kernel', 'summary': 'CVE-2025-21981', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21986&packageName=kernel', 'summary': 'CVE-2025-21986', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21995&packageName=kernel', 'summary': 'CVE-2025-21995', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22001&packageName=kernel', 'summary': 'CVE-2025-22001', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22009&packageName=kernel', 'summary': 'CVE-2025-22009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22071&packageName=kernel', 'summary': 'CVE-2025-22071', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22077&packageName=kernel', 'summary': 'CVE-2025-22077', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23138&packageName=kernel', 'summary': 'CVE-2025-23138', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23157&packageName=kernel', 'summary': 'CVE-2025-23157', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37740&packageName=kernel', 'summary': 'CVE-2025-37740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37748&packageName=kernel', 'summary': 'CVE-2025-37748', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37766&packageName=kernel', 'summary': 'CVE-2025-37766', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37768&packageName=kernel', 'summary': 'CVE-2025-37768', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37770&packageName=kernel', 'summary': 'CVE-2025-37770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37771&packageName=kernel', 'summary': 'CVE-2025-37771', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37778&packageName=kernel', 'summary': 'CVE-2025-37778', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37793&packageName=kernel', 'summary': 'CVE-2025-37793', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37805&packageName=kernel', 'summary': 'CVE-2025-37805', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37815&packageName=kernel', 'summary': 'CVE-2025-37815', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37831&packageName=kernel', 'summary': 'CVE-2025-37831', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37844&packageName=kernel', 'summary': 'CVE-2025-37844', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37853&packageName=kernel', 'summary': 'CVE-2025-37853', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37881&packageName=kernel', 'summary': 'CVE-2025-37881', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37889&packageName=kernel', 'summary': 'CVE-2025-37889', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37905&packageName=kernel', 'summary': 'CVE-2025-37905', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37918&packageName=kernel', 'summary': 'CVE-2025-37918', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37947&packageName=kernel', 'summary': 'CVE-2025-37947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37967&packageName=kernel', 'summary': 'CVE-2025-37967', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38014&packageName=kernel', 'summary': 'CVE-2025-38014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38037&packageName=kernel', 'summary': 'CVE-2025-38037', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38043&packageName=kernel', 'summary': 'CVE-2025-38043', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38051&packageName=kernel', 'summary': 'CVE-2025-38051', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38064&packageName=kernel', 'summary': 'CVE-2025-38064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38113&packageName=kernel', 'summary': 'CVE-2025-38113', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38122&packageName=kernel', 'summary': 'CVE-2025-38122', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38123&packageName=kernel', 'summary': 'CVE-2025-38123', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38131&packageName=kernel', 'summary': 'CVE-2025-38131', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38148&packageName=kernel', 'summary': 'CVE-2025-38148', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38161&packageName=kernel', 'summary': 'CVE-2025-38161', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38183&packageName=kernel', 'summary': 'CVE-2025-38183', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38193&packageName=kernel', 'summary': 'CVE-2025-38193', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38194&packageName=kernel', 'summary': 'CVE-2025-38194', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38241&packageName=kernel', 'summary': 'CVE-2025-38241', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38255&packageName=kernel', 'summary': 'CVE-2025-38255', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38304&packageName=kernel', 'summary': 'CVE-2025-38304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38307&packageName=kernel', 'summary': 'CVE-2025-38307', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38321&packageName=kernel', 'summary': 'CVE-2025-38321', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38344&packageName=kernel', 'summary': 'CVE-2025-38344', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38364&packageName=kernel', 'summary': 'CVE-2025-38364', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38461&packageName=kernel', 'summary': 'CVE-2025-38461', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38462&packageName=kernel', 'summary': 'CVE-2025-38462', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38488&packageName=kernel', 'summary': 'CVE-2025-38488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38499&packageName=kernel', 'summary': 'CVE-2025-38499', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38552&packageName=kernel', 'summary': 'CVE-2025-38552', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38575&packageName=kernel', 'summary': 'CVE-2025-38575', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38609&packageName=kernel', 'summary': 'CVE-2025-38609', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38721&packageName=kernel', 'summary': 'CVE-2025-38721', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39676&packageName=kernel', 'summary': 'CVE-2025-39676', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39682&packageName=kernel', 'summary': 'CVE-2025-39682', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39702&packageName=kernel', 'summary': 'CVE-2025-39702', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39728&packageName=kernel', 'summary': 'CVE-2025-39728', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39756&packageName=kernel', 'summary': 'CVE-2025-39756', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39770&packageName=kernel', 'summary': 'CVE-2025-39770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39812&packageName=kernel', 'summary': 'CVE-2025-39812', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39841&packageName=kernel', 'summary': 'CVE-2025-39841', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39894&packageName=kernel', 'summary': 'CVE-2025-39894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39937&packageName=kernel', 'summary': 'CVE-2025-39937', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39955&packageName=kernel', 'summary': 'CVE-2025-39955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39980&packageName=kernel', 'summary': 'CVE-2025-39980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40018&packageName=kernel', 'summary': 'CVE-2025-40018', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40062&packageName=kernel', 'summary': 'CVE-2025-40062', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40078&packageName=kernel', 'summary': 'CVE-2025-40078', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40136&packageName=kernel', 'summary': 'CVE-2025-40136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40240&packageName=kernel', 'summary': 'CVE-2025-40240', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40254&packageName=kernel', 'summary': 'CVE-2025-40254', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40280&packageName=kernel', 'summary': 'CVE-2025-40280', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40281&packageName=kernel', 'summary': 'CVE-2025-40281', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40331&packageName=kernel', 'summary': 'CVE-2025-40331', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68283&packageName=kernel', 'summary': 'CVE-2025-68283', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68284&packageName=kernel', 'summary': 'CVE-2025-68284', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68285&packageName=kernel', 'summary': 'CVE-2025-68285', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68304&packageName=kernel', 'summary': 'CVE-2025-68304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68740&packageName=kernel', 'summary': 'CVE-2025-68740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68742&packageName=kernel', 'summary': 'CVE-2025-68742', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68795&packageName=kernel', 'summary': 'CVE-2025-68795', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68820&packageName=kernel', 'summary': 'CVE-2025-68820', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-71064&packageName=kernel', 'summary': 'CVE-2025-71064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22976&packageName=kernel', 'summary': 'CVE-2026-22976', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22994&packageName=kernel', 'summary': 'CVE-2026-22994', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23053&packageName=kernel', 'summary': 'CVE-2026-23053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23253&packageName=kernel', 'summary': 'CVE-2026-23253', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23260&packageName=kernel', 'summary': 'CVE-2026-23260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23268&packageName=kernel', 'summary': 'CVE-2026-23268', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23271&packageName=kernel', 'summary': 'CVE-2026-23271', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23273&packageName=kernel', 'summary': 'CVE-2026-23273', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23292&packageName=kernel', 'summary': 'CVE-2026-23292', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23296&packageName=kernel', 'summary': 'CVE-2026-23296', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23313&packageName=kernel', 'summary': 'CVE-2026-23313', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23317&packageName=kernel', 'summary': 'CVE-2026-23317', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23319&packageName=kernel', 'summary': 'CVE-2026-23319', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23352&packageName=kernel', 'summary': 'CVE-2026-23352', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23359&packageName=kernel', 'summary': 'CVE-2026-23359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23360&packageName=kernel', 'summary': 'CVE-2026-23360', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23374&packageName=kernel', 'summary': 'CVE-2026-23374', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23383&packageName=kernel', 'summary': 'CVE-2026-23383', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23388&packageName=kernel', 'summary': 'CVE-2026-23388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43053&packageName=kernel', 'summary': 'CVE-2026-43053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43147&packageName=kernel', 'summary': 'CVE-2026-43147', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43261&packageName=kernel', 'summary': 'CVE-2026-43261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43289&packageName=kernel', 'summary': 'CVE-2026-43289', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43407&packageName=kernel', 'summary': 'CVE-2026-43407', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43470&packageName=kernel', 'summary': 'CVE-2026-43470', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56611', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56760', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21908', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21931', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21971', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21981', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21986', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21995', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22001', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22071', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22077', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23138', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23157', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37748', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37766', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37768', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37771', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37778', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37793', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37805', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37815', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37831', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37844', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37853', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37881', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37889', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37905', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37967', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38037', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38043', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38051', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38113', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38122', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38123', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38131', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38148', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38161', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38183', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38193', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38194', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38241', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38255', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38307', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38321', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38344', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38364', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38461', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38462', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38499', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38552', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38575', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38609', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38721', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39676', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39682', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39702', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39728', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39756', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39812', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39841', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39937', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40018', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40062', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40078', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40240', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40254', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40280', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40281', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40331', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68283', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68284', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68285', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68742', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68795', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68820', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-71064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22976', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22994', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23268', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23271', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23273', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23292', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23296', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23313', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23317', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23319', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23352', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23360', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23374', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23383', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43147', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43289', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43407', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43470', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2418.json', 'summary': 'openEuler-SA-2026-2418 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'kernel security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-24.03-LTS-SP1', 'title': 'Summary', 'category': 'general'}, {'text': 'The Linux Kernel, the operating system core itself.\n\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MMWe currently assume that there is at least one VMA in a MM, which isn ttrue.So we might end up having find_vma() return NULL, to then de-referenceNULL. So properly handle find_vma() returning NULL.This fixes the report:Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTIKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194Code: ...RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8FS: 00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400Call Trace: <TASK> kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709 __do_sys_migrate_pages mm/mempolicy.c:1727 [inline] __se_sys_migrate_pages mm/mempolicy.c:1723 [inline] __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f[akpm@linux-foundation.org: add unlikely()](CVE-2024-56611)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nPCI/MSI: Handle lack of irqdomain gracefully\n\nAlexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a\nRISCV platform which does not provide PCI/MSI support:\n\n WARNING: CPU: 1 PID: 1 at drivers/pci/msi/msi.h:121 pci_msi_setup_msi_irqs+0x2c/0x32\n __pci_enable_msix_range+0x30c/0x596\n pci_msi_setup_msi_irqs+0x2c/0x32\n pci_alloc_irq_vectors_affinity+0xb8/0xe2\n\nRISCV uses hierarchical interrupt domains and correctly does not implement\nthe legacy fallback. The warning triggers from the legacy fallback stub.\n\nThat warning is bogus as the PCI/MSI layer knows whether a PCI/MSI parent\ndomain is associated with the device or not. There is a check for MSI-X,\nwhich has a legacy assumption. But that legacy fallback assumption is only\nvalid when legacy support is enabled, but otherwise the check should simply\nreturn -ENOTSUPP.\n\nLoongarch tripped over the same problem and blindly enabled legacy support\nwithout implementing the legacy fallbacks. There are weak implementations\nwhich return an error, so the problem was papered over.\n\nCorrect pci_msi_domain_supports() to evaluate the legacy mode and add\nthe missing supported check into the MSI enable path to complete it.(CVE-2024-56760)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix nfs_release_folio() to not deadlock via kcompactd writeback\n\nAdd PF_KCOMPACTD flag and current_is_kcompactd() helper to check for it so\nnfs_release_folio() can skip calling nfs_wb_folio() from kcompactd.\n\nOtherwise NFS can deadlock waiting for kcompactd enduced writeback which\nrecurses back to NFS (which triggers writeback to NFSD via NFS loopback\nmount on the same host, NFSD blocks waiting for XFS\'s call to\n__filemap_get_folio):\n\n6070.550357] INFO: task kcompactd0:58 blocked for more than 4435 seconds.\n\n{---\n[58] "kcompactd0"\n[<0>] folio_wait_bit+0xe8/0x200\n[<0>] folio_wait_writeback+0x2b/0x80\n[<0>] nfs_wb_folio+0x80/0x1b0 [nfs]\n[<0>] nfs_release_folio+0x68/0x130 [nfs]\n[<0>] split_huge_page_to_list_to_order+0x362/0x840\n[<0>] migrate_pages_batch+0x43d/0xb90\n[<0>] migrate_pages_sync+0x9a/0x240\n[<0>] migrate_pages+0x93c/0x9f0\n[<0>] compact_zone+0x8e2/0x1030\n[<0>] compact_node+0xdb/0x120\n[<0>] kcompactd+0x121/0x2e0\n[<0>] kthread+0xcf/0x100\n[<0>] ret_from_fork+0x31/0x40\n[<0>] ret_from_fork_asm+0x1a/0x30\n---}\n\n[(CVE-2025-21908)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nhwpoison, memory_hotplug: lock folio before unmap hwpoisoned folio\n\nCommit b15c87263a69 ("hwpoison, memory_hotplug: allow hwpoisoned pages to\nbe offlined) add page poison checks in do_migrate_range in order to make\noffline hwpoisoned page possible by introducing isolate_lru_page and\ntry_to_unmap for hwpoisoned page. However folio lock must be held before\ncalling try_to_unmap. Add it to fix this problem.\n\nWarning will be produced if folio is not locked during unmap:\n\n ------------[ cut here ]------------\n kernel BUG at ./include/linux/swapops.h:400!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 4 UID: 0 PID: 411 Comm: bash Tainted: G W 6.13.0-rc1-00016-g3c434c7ee82a-dirty #41\n Tainted: [W]=WARN\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : try_to_unmap_one+0xb08/0xd3c\n lr : try_to_unmap_one+0x3dc/0xd3c\n Call trace:\n try_to_unmap_one+0xb08/0xd3c (P)\n try_to_unmap_one+0x3dc/0xd3c (L)\n rmap_walk_anon+0xdc/0x1f8\n rmap_walk+0x3c/0x58\n try_to_unmap+0x88/0x90\n unmap_poisoned_folio+0x30/0xa8\n do_migrate_range+0x4a0/0x568\n offline_pages+0x5a4/0x670\n memory_block_action+0x17c/0x374\n memory_subsys_offline+0x3c/0x78\n device_offline+0xa4/0xd0\n state_store+0x8c/0xf0\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x44/0x54\n kernfs_fop_write_iter+0x118/0x1a8\n vfs_write+0x3a8/0x4bc\n ksys_write+0x6c/0xf8\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xd0\n el0t_64_sync_handler+0xc8/0xcc\n el0t_64_sync+0x198/0x19c\n Code: f9407be0 b5fff320 d4210000 17ffff97 (d4210000)\n ---[ end trace 0000000000000000 ]---(CVE-2025-21931)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Bridge, fix the crash caused by LAG state check\n\nWhen removing LAG device from bridge, NETDEV_CHANGEUPPER event is\ntriggered. Driver finds the lower devices (PFs) to flush all the\noffloaded entries. And mlx5_lag_is_shared_fdb is checked, it returns\nfalse if one of PF is unloaded. In such case,\nmlx5_esw_bridge_lag_rep_get() and its caller return NULL, instead of\nthe alive PF, and the flush is skipped.\n\nBesides, the bridge fdb entry\'s lastuse is updated in mlx5 bridge\nevent handler. But this SWITCHDEV_FDB_ADD_TO_BRIDGE event can be\nignored in this case because the upper interface for bond is deleted,\nand the entry will never be aged because lastuse is never updated.\n\nTo make things worse, as the entry is alive, mlx5 bridge workqueue\nkeeps sending that event, which is then handled by kernel bridge\nnotifier. It causes the following crash when accessing the passed bond\nnetdev which is already destroyed.\n\nTo fix this issue, remove such checks. LAG state is already checked in\ncommit 15f8f168952f ("net/mlx5: Bridge, verify LAG state when adding\nbond to bridge"), driver still need to skip offload if LAG becomes\ninvalid state after initialization.\n\n Oops: stack segment: 0000 [#1] SMP\n CPU: 3 UID: 0 PID: 23695 Comm: kworker/u40:3 Tainted: G OE 6.11.0_mlnx #1\n Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5_bridge_wq mlx5_esw_bridge_update_work [mlx5_core]\n RIP: 0010:br_switchdev_event+0x2c/0x110 [bridge]\n Code: 44 00 00 48 8b 02 48 f7 00 00 02 00 00 74 69 41 54 55 53 48 83 ec 08 48 8b a8 08 01 00 00 48 85 ed 74 4a 48 83 fe 02 48 89 d3 <4c> 8b 65 00 74 23 76 49 48 83 fe 05 74 7e 48 83 fe 06 75 2f 0f b7\n RSP: 0018:ffffc900092cfda0 EFLAGS: 00010297\n RAX: ffff888123bfe000 RBX: ffffc900092cfe08 RCX: 00000000ffffffff\n RDX: ffffc900092cfe08 RSI: 0000000000000001 RDI: ffffffffa0c585f0\n RBP: 6669746f6e690a30 R08: 0000000000000000 R09: ffff888123ae92c8\n R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888123ae9c60\n R13: 0000000000000001 R14: ffffc900092cfe08 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff88852c980000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f15914c8734 CR3: 0000000002830005 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n <TASK>\n ? __die_body+0x1a/0x60\n ? die+0x38/0x60\n ? do_trap+0x10b/0x120\n ? do_error_trap+0x64/0xa0\n ? exc_stack_segment+0x33/0x50\n ? asm_exc_stack_segment+0x22/0x30\n ? br_switchdev_event+0x2c/0x110 [bridge]\n ? sched_balance_newidle.isra.149+0x248/0x390\n notifier_call_chain+0x4b/0xa0\n atomic_notifier_call_chain+0x16/0x20\n mlx5_esw_bridge_update+0xec/0x170 [mlx5_core]\n mlx5_esw_bridge_update_work+0x19/0x40 [mlx5_core]\n process_scheduled_works+0x81/0x390\n worker_thread+0x106/0x250\n ? bh_worker+0x110/0x110\n kthread+0xb7/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n </TASK>(CVE-2025-21970)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: Prevent creation of classes with TC_H_ROOT\n\nThe function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination\ncondition when traversing up the qdisc tree to update parent backlog\ncounters. However, if a class is created with classid TC_H_ROOT, the\ntraversal terminates prematurely at this class instead of reaching the\nactual root qdisc, causing parent statistics to be incorrectly maintained.\nIn case of DRR, this could lead to a crash as reported by Mingi Cho.\n\nPrevent the creation of any Qdisc class with classid TC_H_ROOT\n(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.(CVE-2025-21971)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsched: address a potential NULL pointer dereference in the GRED scheduler.\n\nIf kzalloc in gred_init returns a NULL pointer, the code follows the\nerror handling path, invoking gred_destroy. This, in turn, calls\ngred_offload, where memset could receive a NULL pointer as input,\npotentially leading to a kernel crash.\n\nWhen table->opt is NULL in gred_init(), gred_change_table_def()\nis not called yet, so it is not necessary to call ->ndo_setup_tc()\nin gred_offload().(CVE-2025-21980)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nice: fix memory leak in aRFS after reset\n\nFix aRFS (accelerated Receive Flow Steering) structures memory leak by\nadding a checker to verify if aRFS memory is already allocated while\nconfiguring VSI. aRFS objects are allocated in two cases:\n- as part of VSI initialization (at probe), and\n- as part of reset handling\n\nHowever, VSI reconfiguration executed during reset involves memory\nallocation one more time, without prior releasing already allocated\nresources. This led to the memory leak with the following signature:\n\n[root@os-delivery ~]# cat /sys/kernel/debug/kmemleak\nunreferenced object 0xff3c1ca7252e6000 (size 8192):\n comm "kworker/0:0", pid 8, jiffies 4296833052\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 0):\n [<ffffffff991ec485>] __kmalloc_cache_noprof+0x275/0x340\n [<ffffffffc0a6e06a>] ice_init_arfs+0x3a/0xe0 [ice]\n [<ffffffffc09f1027>] ice_vsi_cfg_def+0x607/0x850 [ice]\n [<ffffffffc09f244b>] ice_vsi_setup+0x5b/0x130 [ice]\n [<ffffffffc09c2131>] ice_init+0x1c1/0x460 [ice]\n [<ffffffffc09c64af>] ice_probe+0x2af/0x520 [ice]\n [<ffffffff994fbcd3>] local_pci_probe+0x43/0xa0\n [<ffffffff98f07103>] work_for_cpu_fn+0x13/0x20\n [<ffffffff98f0b6d9>] process_one_work+0x179/0x390\n [<ffffffff98f0c1e9>] worker_thread+0x239/0x340\n [<ffffffff98f14abc>] kthread+0xcc/0x100\n [<ffffffff98e45a6d>] ret_from_fork+0x2d/0x50\n [<ffffffff98e083ba>] ret_from_fork_asm+0x1a/0x30\n ...(CVE-2025-21981)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: switchdev: Convert blocking notification chain to a raw one\n\nA blocking notification chain uses a read-write semaphore to protect the\nintegrity of the chain. The semaphore is acquired for writing when\nadding / removing notifiers to / from the chain and acquired for reading\nwhen traversing the chain and informing notifiers about an event.\n\nIn case of the blocking switchdev notification chain, recursive\nnotifications are possible which leads to the semaphore being acquired\ntwice for reading and to lockdep warnings being generated [1].\n\nSpecifically, this can happen when the bridge driver processes a\nSWITCHDEV_BRPORT_UNOFFLOADED event which causes it to emit notifications\nabout deferred events when calling switchdev_deferred_process().\n\nFix this by converting the notification chain to a raw notification\nchain in a similar fashion to the netdev notification chain. Protect\nthe chain using the RTNL mutex by acquiring it when modifying the chain.\nEvents are always informed under the RTNL mutex, but add an assertion in\ncall_switchdev_blocking_notifiers() to make sure this is not violated in\nthe future.\n\nMaintain the "blocking" prefix as events are always emitted from process\ncontext and listeners are allowed to block.\n\n[1]:\nWARNING: possible recursive locking detected\n6.14.0-rc4-custom-g079270089484 #1 Not tainted\n--------------------------------------------\nip/52731 is trying to acquire lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nbut task is already holding lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nother info that might help us debug this:\nPossible unsafe locking scenario:\nCPU0\n----\nlock((switchdev_blocking_notif_chain).rwsem);\nlock((switchdev_blocking_notif_chain).rwsem);\n\n*** DEADLOCK ***\nMay be due to missing lock nesting notation\n3 locks held by ip/52731:\n #0: ffffffff84f795b0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x727/0x1dc0\n #1: ffffffff8731f628 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x790/0x1dc0\n #2: ffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nstack backtrace:\n...\n? __pfx_down_read+0x10/0x10\n? __pfx_mark_lock+0x10/0x10\n? __pfx_switchdev_port_attr_set_deferred+0x10/0x10\nblocking_notifier_call_chain+0x58/0xa0\nswitchdev_port_attr_notify.constprop.0+0xb3/0x1b0\n? __pfx_switchdev_port_attr_notify.constprop.0+0x10/0x10\n? mark_held_locks+0x94/0xe0\n? switchdev_deferred_process+0x11a/0x340\nswitchdev_port_attr_set_deferred+0x27/0xd0\nswitchdev_deferred_process+0x164/0x340\nbr_switchdev_port_unoffload+0xc8/0x100 [bridge]\nbr_switchdev_blocking_event+0x29f/0x580 [bridge]\nnotifier_call_chain+0xa2/0x440\nblocking_notifier_call_chain+0x6e/0xa0\nswitchdev_bridge_port_unoffload+0xde/0x1a0\n...(CVE-2025-21986)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: Fix fence reference count leak\n\nThe last_scheduled fence leaks when an entity is being killed and adding\nthe cleanup callback fails.\n\nDecrement the reference count of prev when dma_fence_add_callback()\nfails, ensuring proper balance.\n\n[phasta: add git tag info for stable kernel](CVE-2025-21995)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Fix integer overflow in qaic_validate_req()\n\nThese are u64 variables that come from the user via\nqaic_attach_slice_bo_ioctl(). Use check_add_overflow() to ensure that\nthe math doesn\'t have an integer wrapping bug.(CVE-2025-22001)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nregulator: dummy: force synchronous probing\n\nSometimes I get a NULL pointer dereference at boot time in kobject_get()\nwith the following call stack:\n\nanatop_regulator_probe()\n devm_regulator_register()\n regulator_register()\n regulator_resolve_supply()\n kobject_get()\n\nBy placing some extra BUG_ON() statements I could verify that this is\nraised because probing of the \'dummy\' regulator driver is not completed\n(\'dummy_regulator_rdev\' is still NULL).\n\nIn the JTAG debugger I can see that dummy_regulator_probe() and\nanatop_regulator_probe() can be run by different kernel threads\n(kworker/u4:*). I haven\'t further investigated whether this can be\nchanged or if there are other possibilities to force synchronization\nbetween these two probe routines. On the other hand I don\'t expect much\nboot time penalty by probing the \'dummy\' regulator synchronously.(CVE-2025-22009)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix a leak in spufs_create_context()\n\nLeak fixes back in 2008 missed one case - if we are trying to set affinity\nand spufs_mkdir() fails, we need to drop the reference to neighbor.(CVE-2025-22071)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRevert "smb: client: fix TCP timers deadlock after rmmod"\n\nThis reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.\n\nCommit e9f2517a3e18 ("smb: client: fix TCP timers deadlock after\nrmmod") is intended to fix a null-ptr-deref in LOCKDEP, which is\nmentioned as CVE-2024-54680, but is actually did not fix anything;\nThe issue can be reproduced on top of it. [0]\n\nAlso, it reverted the change by commit ef7134c7fc48 ("smb: client:\nFix use-after-free of network namespace.") and introduced a real\nissue by reviving the kernel TCP socket.\n\nWhen a reconnect happens for a CIFS connection, the socket state\ntransitions to FIN_WAIT_1. Then, inet_csk_clear_xmit_timers_sync()\nin tcp_close() stops all timers for the socket.\n\nIf an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1\nforever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.\n\nUsually, FIN can be retransmitted by the peer, but if the peer aborts\nthe connection, the issue comes into reality.\n\nI warned about this privately by pointing out the exact report [1],\nbut the bogus fix was finally merged.\n\nSo, we should not stop the timers to finally kill the connection on\nour side in that case, meaning we must not use a kernel socket for\nTCP whose sk->sk_net_refcnt is 0.\n\nThe kernel socket does not have a reference to its netns to make it\npossible to tear down netns without cleaning up every resource in it.\n\nFor example, tunnel devices use a UDP socket internally, but we can\ndestroy netns without removing such devices and let it complete\nduring exit. Otherwise, netns would be leaked when the last application\ndied.\n\nHowever, this is problematic for TCP sockets because TCP has timers to\nclose the connection gracefully even after the socket is close()d. The\nlifetime of the socket and its netns is different from the lifetime of\nthe underlying connection.\n\nIf the socket user does not maintain the netns lifetime, the timer could\nbe fired after the socket is close()d and its netns is freed up, resulting\nin use-after-free.\n\nActually, we have seen so many similar issues and converted such sockets\nto have a reference to netns.\n\nThat\'s why I converted the CIFS client socket to have a reference to\nnetns (sk->sk_net_refcnt == 1), which is somehow mentioned as out-of-scope\nof CIFS and technically wrong in e9f2517a3e18, but **is in-scope and right\nfix**.\n\nRegarding the LOCKDEP issue, we can prevent the module unload by\nbumping the module refcount when switching the LOCKDDEP key in\nsock_lock_init_class_and_name(). [2]\n\nFor a while, let\'s revert the bogus fix.\n\nNote that now we can use sk_net_refcnt_upgrade() for the socket\nconversion, but I\'ll do so later separately to make backport easy.(CVE-2025-22077)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwatch_queue: fix pipe accounting mismatch\n\nCurrently, watch_queue_set_size() modifies the pipe buffers charged to\nuser->pipe_bufs without updating the pipe->nr_accounted on the pipe\nitself, due to the if (!pipe_has_watch_queue()) test in\npipe_resize_ring(). This means that when the pipe is ultimately freed,\nwe decrement user->pipe_bufs by something other than what than we had\ncharged to it, potentially leading to an underflow. This in turn can\ncause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM.\n\nTo remedy this, explicitly account for the pipe usage in\nwatch_queue_set_size() to match the number set via account_pipe_buffers()\n\n(It\'s unclear why watch_queue_set_size() does not update nr_accounted;\nit may be due to intentional overprovisioning in watch_queue_set_size()?)(CVE-2025-23138)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: add check to avoid out of bound access\n\nThere is a possibility that init_codecs is invoked multiple times during\nmanipulated payload from video firmware. In such case, if codecs_count\ncan get incremented to value more than MAX_CODEC_NUM, there can be OOB\naccess. Reset the count so that it always starts from beginning.(CVE-2025-23157)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\njfs: add sanity check for agwidth in dbMount\n\nThe width in dmapctl of the AG is zero, it trigger a divide error when\ncalculating the control page level in dbAllocAG.\n\nTo avoid this issue, add a check for agwidth in dbAllocAG.(CVE-2025-37740)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\niommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group\n\nCurrently, mtk_iommu calls during probe iommu_device_register before\nthe hw_list from driver data is initialized. Since iommu probing issue\nfix, it leads to NULL pointer dereference in mtk_iommu_device_group when\nhw_list is accessed with list_first_entry (not null safe).\n\nSo, change the call order to ensure iommu_device_register is called\nafter the driver data are initialized.(CVE-2025-37748)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37766)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37768)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37770)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37771)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Fix dangling pointer in krb_authenticate\n\nkrb_authenticate frees sess->user and does not set the pointer\nto NULL. It calls ksmbd_krb5_authenticate to reinitialise\nsess->user but that function may return without doing so. If\nthat happens then smb2_sess_setup, which calls krb_authenticate,\nwill be accessing free\'d memory when it later uses sess->user.(CVE-2025-37778)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\navs_component_probe() does not check for this case, which results in a\nNULL pointer dereference.(CVE-2025-37793)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsound/virtio: Fix cancel_sync warnings on uninitialized work_structs\n\nBetty reported hitting the following warning:\n\n[ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182\n...\n[ 8.713282][ T221] Call trace:\n[ 8.713365][ T221] __flush_work+0x8d0/0x914\n[ 8.713468][ T221] __cancel_work_sync+0xac/0xfc\n[ 8.713570][ T221] cancel_work_sync+0x24/0x34\n[ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.714035][ T221] virtio_dev_probe+0x28c/0x390\n[ 8.714139][ T221] really_probe+0x1bc/0x4c8\n...\n\nIt seems we\'re hitting the error path in virtsnd_probe(), which\ntriggers a virtsnd_remove() which iterates over the substreams\ncalling cancel_work_sync() on the elapsed_period work_struct.\n\nLooking at the code, from earlier in:\nvirtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg()\n\nWe set snd->nsubstreams, allocate the snd->substreams, and if\nwe then hit an error on the info allocation or something in\nvirtsnd_ctl_query_info() fails, we will exit without having\ninitialized the elapsed_period work_struct.\n\nWhen that error path unwinds we then call virtsnd_remove()\nwhich as long as the substreams array is allocated, will iterate\nthrough calling cancel_work_sync() on the uninitialized work\nstruct hitting this warning.\n\nTakashi Iwai suggested this fix, which initializes the substreams\nstructure right after allocation, so that if we hit the error\npaths we avoid trying to cleanup uninitialized data.\n\nNote: I have not yet managed to reproduce the issue myself, so\nthis patch has had limited testing.\n\nFeedback or thoughts would be appreciated!(CVE-2025-37805)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration\n\nResolve kernel panic while accessing IRQ handler associated with the\ngenerated IRQ. This is done by acquiring the spinlock and storing the\ncurrent interrupt state before handling the interrupt request using\ngeneric_handle_irq.\n\nA previous fix patch was submitted where \'generic_handle_irq\' was\nreplaced with \'handle_nested_irq\'. However, this change also causes\nthe kernel panic where after determining which GPIO triggered the\ninterrupt and attempting to call handle_nested_irq with the mapped\nIRQ number, leads to a failure in locating the registered handler.(CVE-2025-37815)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check\nfor this case, which results in a NULL pointer dereference.(CVE-2025-37831)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncifs: avoid NULL pointer dereference in dbg call\n\ncifs_server_dbg() implies server to be non-NULL so\nmove call under condition to avoid NULL pointer dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37844)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: debugfs hang_hws skip GPU with MES\n\ndebugfs hang_hws is used by GPU reset test with HWS, for MES this crash\nthe kernel with NULL pointer access because dqm->packet_mgr is not setup\nfor MES path.\n\nSkip GPU with MES for now, MES hang_hws debugfs interface will be\nsupported later.(CVE-2025-37853)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()\n\nThe variable d->name, returned by devm_kasprintf(), could be NULL.\nA pointer check is added to prevent potential NULL pointer dereference.\nThis is similar to the fix in commit 3027e7b15b02\n("ice: Fix some null pointer dereference issues in ice_ptp.c").\n\nThis issue is found by our static analysis tool(CVE-2025-37881)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Consistently treat platform_max as control value\n\nThis reverts commit 9bdd10d57a88 ("ASoC: ops: Shift tested values in\nsnd_soc_put_volsw() by +min"), and makes some additional related\nupdates.\n\nThere are two ways the platform_max could be interpreted; the maximum\nregister value, or the maximum value the control can be set to. The\npatch moved from treating the value as a control value to a register\none. When the patch was applied it was technically correct as\nsnd_soc_limit_volume() also used the register interpretation. However,\neven then most of the other usages treated platform_max as a\ncontrol value, and snd_soc_limit_volume() has since been updated to\nalso do so in commit fb9ad24485087 ("ASoC: ops: add correct range\ncheck for limiting volume"). That patch however, missed updating\nsnd_soc_put_volsw() back to the control interpretation, and fixing\nsnd_soc_info_volsw_range(). The control interpretation makes more\nsense as limiting is typically done from the machine driver, so it is\nappropriate to use the customer facing representation rather than the\ninternal codec representation. Update all the code to consistently use\nthis interpretation of platform_max.\n\nFinally, also add some comments to the soc_mixer_control struct to\nhopefully avoid further patches switching between the two approaches.(CVE-2025-37889)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Balance device refcount when destroying devices\n\nUsing device_find_child() to lookup the proper SCMI device to destroy\ncauses an unbalance in device refcount, since device_find_child() calls an\nimplicit get_device(): this, in turns, inhibits the call of the provided\nrelease methods upon devices destruction.\n\nAs a consequence, one of the structures that is not freed properly upon\ndestruction is the internal struct device_private dev->p populated by the\ndrivers subsystem core.\n\nKMemleak detects this situation since loading/unloding some SCMI driver\ncauses related devices to be created/destroyed without calling any\ndevice_release method.\n\nunreferenced object 0xffff00000f583800 (size 512):\n comm "insmod", pid 227, jiffies 4294912190\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 60 36 1d 8a 00 80 ff ff ........`6......\n backtrace (crc 114e2eed):\n kmemleak_alloc+0xbc/0xd8\n __kmalloc_cache_noprof+0x2dc/0x398\n device_add+0x954/0x12d0\n device_register+0x28/0x40\n __scmi_device_create.part.0+0x1bc/0x380\n scmi_device_create+0x2d0/0x390\n scmi_create_protocol_devices+0x74/0xf8\n scmi_device_request_notifier+0x1f8/0x2a8\n notifier_call_chain+0x110/0x3b0\n blocking_notifier_call_chain+0x70/0xb0\n scmi_driver_register+0x350/0x7f0\n 0xffff80000a3b3038\n do_one_initcall+0x12c/0x730\n do_init_module+0x1dc/0x640\n load_module+0x4b20/0x5b70\n init_module_from_file+0xec/0x158\n\n$ ./scripts/faddr2line ./vmlinux device_add+0x954/0x12d0\ndevice_add+0x954/0x12d0:\nkmalloc_noprof at include/linux/slab.h:901\n(inlined by) kzalloc_noprof at include/linux/slab.h:1037\n(inlined by) device_private_init at drivers/base/core.c:3510\n(inlined by) device_add at drivers/base/core.c:3561\n\nBalance device refcount by issuing a put_device() on devices found via\ndevice_find_child().(CVE-2025-37905)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()\n\nA NULL pointer dereference can occur in skb_dequeue() when processing a\nQCA firmware crash dump on WCN7851 (0489:e0f3).\n\n[ 93.672166] Bluetooth: hci0: ACL memdump size(589824)\n\n[ 93.672475] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[ 93.672517] Workqueue: hci0 hci_devcd_rx [bluetooth]\n[ 93.672598] RIP: 0010:skb_dequeue+0x50/0x80\n\nThe issue stems from handle_dump_pkt_qca() returning 0 even when a dump\npacket is successfully processed. This is because it incorrectly\nforwards the return value of hci_devcd_init() (which returns 0 on\nsuccess). As a result, the caller (btusb_recv_acl_qca() or\nbtusb_recv_evt_qca()) assumes the packet was not handled and passes it\nto hci_recv_frame(), leading to premature kfree() of the skb.\n\nLater, hci_devcd_rx() attempts to dequeue the same skb from the dump\nqueue, resulting in a NULL pointer dereference.\n\nFix this by:\n1. Making handle_dump_pkt_qca() return 0 on success and negative errno\n on failure, consistent with kernel conventions.\n2. Splitting dump packet detection into separate functions for ACL\n and event packets for better structure and readability.\n\nThis ensures dump packets are properly identified and consumed, avoiding\ndouble handling and preventing NULL pointer access.(CVE-2025-37918)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent out-of-bounds stream writes by validating *pos\n\nksmbd_vfs_stream_write() did not validate whether the write offset\n(*pos) was within the bounds of the existing stream data length (v_len).\nIf *pos was greater than or equal to v_len, this could lead to an\nout-of-bounds memory write.\n\nThis patch adds a check to ensure *pos is less than v_len before\nproceeding. If the condition fails, -EINVAL is returned.(CVE-2025-37947)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: displayport: Fix deadlock\n\nThis patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock\nfunctions to the UCSI driver. ucsi_con_mutex_lock ensures the connector\nmutex is only locked if a connection is established and the partner pointer\nis valid. This resolves a deadlock scenario where\nucsi_displayport_remove_partner holds con->mutex waiting for\ndp_altmode_work to complete while dp_altmode_work attempts to acquire it.(CVE-2025-37967)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Refactor remove call with idxd_cleanup() helper\n\nThe idxd_cleanup() helper cleans up perfmon, interrupts, internals and\nso on. Refactor remove call with the idxd_cleanup() helper to avoid code\nduplication. Note, this also fixes the missing put_device() for idxd\ngroups, enginces and wqs.(CVE-2025-38014)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Annotate FDB data races\n\nThe \'used\' and \'updated\' fields in the FDB entry structure can be\naccessed concurrently by multiple threads, leading to reports such as\n[1]. Can be reproduced using [2].\n\nSuppress these reports by annotating these accesses using\nREAD_ONCE() / WRITE_ONCE().\n\n[1]\nBUG: KCSAN: data-race in vxlan_xmit / vxlan_xmit\n\nwrite to 0xffff942604d263a8 of 8 bytes by task 286 on cpu 0:\n vxlan_xmit+0xb29/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff942604d263a8 of 8 bytes by task 287 on cpu 2:\n vxlan_xmit+0xadf/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000000fffbac6e -> 0x00000000fffbac6f\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 2 UID: 0 PID: 287 Comm: mausezahn Not tainted 6.13.0-rc7-01544-gb4b270f11a02 #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014\n\n[2]\n #!/bin/bash\n\n set +H\n echo whitelist > /sys/kernel/debug/kcsan\n echo !vxlan_xmit > /sys/kernel/debug/kcsan\n\n ip link add name vx0 up type vxlan id 10010 dstport 4789 local 192.0.2.1\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 198.51.100.1\n taskset -c 0 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &\n taskset -c 2 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &(CVE-2025-38037)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Set dma_mask for ffa devices\n\nSet dma_mask for FFA devices, otherwise DMA allocation using the device pointer\nlead to following warning:\n\nWARNING: CPU: 1 PID: 1 at kernel/dma/mapping.c:597 dma_alloc_attrs+0xe0/0x124(CVE-2025-38043)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_fill_dirent\n\nThere is a race condition in the readdir concurrency process, which may\naccess the rsp buffer after it has been released, triggering the\nfollowing KASAN warning.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03/0xb60 [cifs]\n Read of size 4 at addr ffff8880099b819c by task a.out/342975\n\n CPU: 2 UID: 0 PID: 342975 Comm: a.out Not tainted 6.15.0-rc6+ #240 PREEMPT(full)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\n Call Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n print_report+0xce/0x640\n kasan_report+0xb8/0xf0\n cifs_fill_dirent+0xb03/0xb60 [cifs]\n cifs_readdir+0x12cb/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f996f64b9f9\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01\n f0 ff ff 0d f7 c3 0c 00 f7 d8 64 89 8\n RSP: 002b:00007f996f53de78 EFLAGS: 00000207 ORIG_RAX: 000000000000004e\n RAX: ffffffffffffffda RBX: 00007f996f53ecdc RCX: 00007f996f64b9f9\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007f996f53dea0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000207 R12: ffffffffffffff88\n R13: 0000000000000000 R14: 00007ffc8cd9a500 R15: 00007f996f51e000\n </TASK>\n\n Allocated by task 408:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x6e/0x70\n kmem_cache_alloc_noprof+0x117/0x3d0\n mempool_alloc_noprof+0xf2/0x2c0\n cifs_buf_get+0x36/0x80 [cifs]\n allocate_buffers+0x1d2/0x330 [cifs]\n cifs_demultiplex_thread+0x22b/0x2690 [cifs]\n kthread+0x394/0x720\n ret_from_fork+0x34/0x70\n ret_from_fork_asm+0x1a/0x30\n\n Freed by task 342979:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x37/0x50\n kmem_cache_free+0x2b8/0x500\n cifs_buf_release+0x3c/0x70 [cifs]\n cifs_readdir+0x1c97/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents64+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n The buggy address belongs to the object at ffff8880099b8000\n which belongs to the cache cifs_request of size 16588\n The buggy address is located 412 bytes inside of\n freed 16588-byte region [ffff8880099b8000, ffff8880099bc0cc)\n\n The buggy address belongs to the physical page:\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x99b8\n head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n anon flags: 0x80000000000040(head|node=0|zone=1)\n page_type: f5(slab)\n raw: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n raw: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n head: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000003 ffffea0000266e01 00000000ffffffff 00000000ffffffff\n head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8880099b8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8880099b8180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8880099b8200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\nPOC is available in the link [1].\n\nThe problem triggering process is as follows:\n\nProcess 1 Process 2\n-----------------------------------\n---truncated---(CVE-2025-38051)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()\n\nHongyu reported a hang on kexec in a VM. QEMU reported invalid memory\naccesses during the hang.\n\n\tInvalid read at addr 0x102877002, size 2, region \'(null)\', reason: rejected\n\tInvalid write at addr 0x102877A44, size 2, region \'(null)\', reason: rejected\n\t...\n\nIt was traced down to virtio-console. Kexec works fine if virtio-console\nis not in use.\n\nThe issue is that virtio-console continues to write to the MMIO even after\nunderlying virtio-pci device is reset.\n\nAdditionally, Eric noticed that IOMMUs are reset before devices, if\ndevices are not reset on shutdown they continue to poke at guest memory\nand get errors from the IOMMU. Some devices get wedged then.\n\nThe problem can be solved by breaking all virtio devices on virtio\nbus shutdown, then resetting them.(CVE-2025-38064)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Fix NULL pointer dereference when nosmp is used\n\nWith nosmp in cmdline, other CPUs are not brought up, leaving\ntheir cpc_desc_ptr NULL. CPU0\'s iteration via for_each_possible_cpu()\ndereferences these NULL pointers, causing panic.\n\nPanic backtrace:\n\n[ 0.401123] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b8\n...\n[ 0.403255] [<ffffffff809a5818>] cppc_allow_fast_switch+0x6a/0xd4\n...\nKernel panic - not syncing: Attempted to kill init!\n\n[ rjw: New subject ](CVE-2025-38113)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ngve: add missing NULL check for gve_alloc_pending_packet() in TX DQO\n\ngve_alloc_pending_packet() can return NULL, but gve_tx_add_skb_dqo()\ndid not check for this case before dereferencing the returned pointer.\n\nAdd a missing NULL check to prevent a potential NULL pointer\ndereference when allocation fails.\n\nThis improves robustness in low-memory scenarios.(CVE-2025-38122)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: Fix napi rx poll issue\n\nWhen driver handles the napi rx polling requests, the netdev might\nhave been released by the dellink logic triggered by the disconnect\noperation on user plane. However, in the logic of processing skb in\npolling, an invalid netdev is still being used, which causes a panic.\n\nBUG: kernel NULL pointer dereference, address: 00000000000000f1\nOops: 0000 [#1] PREEMPT SMP NOPTI\nRIP: 0010:dev_gro_receive+0x3a/0x620\n[...]\nCall Trace:\n <IRQ>\n ? __die_body+0x68/0xb0\n ? page_fault_oops+0x379/0x3e0\n ? exc_page_fault+0x4f/0xa0\n ? asm_exc_page_fault+0x22/0x30\n ? __pfx_t7xx_ccmni_recv_skb+0x10/0x10 [mtk_t7xx (HASH:1400 7)]\n ? dev_gro_receive+0x3a/0x620\n napi_gro_receive+0xad/0x170\n t7xx_ccmni_recv_skb+0x48/0x70 [mtk_t7xx (HASH:1400 7)]\n t7xx_dpmaif_napi_rx_poll+0x590/0x800 [mtk_t7xx (HASH:1400 7)]\n net_rx_action+0x103/0x470\n irq_exit_rcu+0x13a/0x310\n sysvec_apic_timer_interrupt+0x56/0x90\n </IRQ>(CVE-2025-38123)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: prevent deactivate active config while enabling the config\n\nWhile enable active config via cscfg_csdev_enable_active_config(),\nactive config could be deactivated via configfs\' sysfs interface.\nThis could make UAF issue in below scenario:\n\nCPU0 CPU1\n(sysfs enable) load module\n cscfg_load_config_sets()\n activate config. // sysfs\n (sys_active_cnt == 1)\n...\ncscfg_csdev_enable_active_config()\nlock(csdev->cscfg_csdev_lock)\n// here load config activate by CPU1\nunlock(csdev->cscfg_csdev_lock)\n\n deactivate config // sysfs\n (sys_activec_cnt == 0)\n cscfg_unload_config_sets()\n unload module\n\n// access to config_desc which freed\n// while unloading module.\ncscfg_csdev_enable_config\n\nTo address this, use cscfg_config_desc\'s active_cnt as a reference count\n which will be holded when\n - activate the config.\n - enable the activated config.\nand put the module reference when config_active_cnt == 0.(CVE-2025-38131)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: mscc: Fix memory leak when using one step timestamping\n\nFix memory leak when running one-step timestamping. When running\none-step sync timestamping, the HW is configured to insert the TX time\ninto the frame, so there is no reason to keep the skb anymore. As in\nthis case the HW will never generate an interrupt to say that the frame\nwas timestamped, then the frame will never released.\nFix this by freeing the frame in case of one-step timestamping.(CVE-2025-38148)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix error flow upon firmware failure for RQ destruction\n\nUpon RQ destruction if the firmware command fails which is the\nlast resource to be destroyed some SW resources were already cleaned\nregardless of the failure.\n\nNow properly rollback the object to its original state upon such failure.\n\nIn order to avoid a use-after free in case someone tries to destroy the\nobject again, which results in the following kernel trace:\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 0 PID: 37589 at lib/refcount.c:28 refcount_warn_saturate+0xf4/0x148\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) rfkill mlx5_core(OE) mlxdevm(OE) ib_uverbs(OE) ib_core(OE) psample mlxfw(OE) mlx_compat(OE) macsec tls pci_hyperv_intf sunrpc vfat fat virtio_net net_failover failover fuse loop nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_console virtio_gpu virtio_blk virtio_dma_buf virtio_mmio dm_mirror dm_region_hash dm_log dm_mod xpmem(OE)\nCPU: 0 UID: 0 PID: 37589 Comm: python3 Kdump: loaded Tainted: G OE ------- --- 6.12.0-54.el10.aarch64 #1\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : refcount_warn_saturate+0xf4/0x148\nlr : refcount_warn_saturate+0xf4/0x148\nsp : ffff80008b81b7e0\nx29: ffff80008b81b7e0 x28: ffff000133d51600 x27: 0000000000000001\nx26: 0000000000000000 x25: 00000000ffffffea x24: ffff00010ae80f00\nx23: ffff00010ae80f80 x22: ffff0000c66e5d08 x21: 0000000000000000\nx20: ffff0000c66e0000 x19: ffff00010ae80340 x18: 0000000000000006\nx17: 0000000000000000 x16: 0000000000000020 x15: ffff80008b81b37f\nx14: 0000000000000000 x13: 2e656572662d7265 x12: ffff80008283ef78\nx11: ffff80008257efd0 x10: ffff80008283efd0 x9 : ffff80008021ed90\nx8 : 0000000000000001 x7 : 00000000000bffe8 x6 : c0000000ffff7fff\nx5 : ffff0001fb8e3408 x4 : 0000000000000000 x3 : ffff800179993000\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000133d51600\nCall trace:\n refcount_warn_saturate+0xf4/0x148\n mlx5_core_put_rsc+0x88/0xa0 [mlx5_ib]\n mlx5_core_destroy_rq_tracked+0x64/0x98 [mlx5_ib]\n mlx5_ib_destroy_wq+0x34/0x80 [mlx5_ib]\n ib_destroy_wq_user+0x30/0xc0 [ib_core]\n uverbs_free_wq+0x28/0x58 [ib_uverbs]\n destroy_hw_idr_uobject+0x34/0x78 [ib_uverbs]\n uverbs_destroy_uobject+0x48/0x240 [ib_uverbs]\n __uverbs_cleanup_ufile+0xd4/0x1a8 [ib_uverbs]\n uverbs_destroy_ufile_hw+0x48/0x120 [ib_uverbs]\n ib_uverbs_close+0x2c/0x100 [ib_uverbs]\n __fput+0xd8/0x2f0\n __fput_sync+0x50/0x70\n __arm64_sys_close+0x40/0x90\n invoke_syscall.constprop.0+0x74/0xd0\n do_el0_svc+0x48/0xe8\n el0_svc+0x44/0x1d0\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x1a4/0x1a8(CVE-2025-38161)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()\n\nBefore calling lan743x_ptp_io_event_clock_get(), the \'channel\' value\nis checked against the maximum value of PCI11X1X_PTP_IO_MAX_CHANNELS(8).\nThis seems correct and aligns with the PTP interrupt status register\n(PTP_INT_STS) specifications.\n\nHowever, lan743x_ptp_io_event_clock_get() writes to ptp->extts[] with\nonly LAN743X_PTP_N_EXTTS(4) elements, using channel as an index:\n\n lan743x_ptp_io_event_clock_get(..., u8 channel,...)\n {\n ...\n /* Update Local timestamp */\n extts = &ptp->extts[channel];\n extts->ts.tv_sec = sec;\n ...\n }\n\nTo avoid an out-of-bounds write and utilize all the supported GPIO\ninputs, set LAN743X_PTP_N_EXTTS to 8.\n\nDetected using the static analysis tool - Svace.(CVE-2025-38183)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: reject invalid perturb period\n\nGerrard Tai reported that SFQ perturb_period has no range check yet,\nand this can be used to trigger a race condition fixed in a separate patch.\n\nWe want to make sure ctl->perturb_period * HZ will not overflow\nand is positive.\n\n\ntc qd add dev lo root sfq perturb -10 # negative value : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 1000000000 # too big : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 2000000 # acceptable value\ntc -s -d qd sh dev lo\nqdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec\n Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)\n backlog 0b 0p requeues 0(CVE-2025-38193)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\njffs2: check that raw node were preallocated before writing summary\n\nSyzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault\ninjection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn\'t\ncheck return value of jffs2_prealloc_raw_node_refs and simply lets any\nerror propagate into jffs2_sum_write_data, which eventually calls\njffs2_link_node_ref in order to link the summary to an expectedly allocated\nnode.\n\nkernel BUG at fs/jffs2/nodelist.c:592!\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:jffs2_link_node_ref+0x570/0x690 fs/jffs2/nodelist.c:592\nCall Trace:\n <TASK>\n jffs2_sum_write_data fs/jffs2/summary.c:841 [inline]\n jffs2_sum_write_sumnode+0xd1a/0x1da0 fs/jffs2/summary.c:874\n jffs2_do_reserve_space+0xa18/0xd60 fs/jffs2/nodemgmt.c:388\n jffs2_reserve_space+0x55f/0xaa0 fs/jffs2/nodemgmt.c:197\n jffs2_write_inode_range+0x246/0xb50 fs/jffs2/write.c:362\n jffs2_write_end+0x726/0x15d0 fs/jffs2/file.c:301\n generic_perform_write+0x314/0x5d0 mm/filemap.c:3856\n __generic_file_write_iter+0x2ae/0x4d0 mm/filemap.c:3973\n generic_file_write_iter+0xe3/0x350 mm/filemap.c:4005\n call_write_iter include/linux/fs.h:2265 [inline]\n do_iter_readv_writev+0x20f/0x3c0 fs/read_write.c:735\n do_iter_write+0x186/0x710 fs/read_write.c:861\n vfs_iter_write+0x70/0xa0 fs/read_write.c:902\n iter_file_splice_write+0x73b/0xc90 fs/splice.c:685\n do_splice_from fs/splice.c:763 [inline]\n direct_splice_actor+0x10c/0x170 fs/splice.c:950\n splice_direct_to_actor+0x337/0xa10 fs/splice.c:896\n do_splice_direct+0x1a9/0x280 fs/splice.c:1002\n do_sendfile+0xb13/0x12c0 fs/read_write.c:1255\n __do_sys_sendfile64 fs/read_write.c:1323 [inline]\n __se_sys_sendfile64 fs/read_write.c:1309 [inline]\n __x64_sys_sendfile64+0x1cf/0x210 fs/read_write.c:1309\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFix this issue by checking return value of jffs2_prealloc_raw_node_refs\nbefore calling jffs2_sum_write_data.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.(CVE-2025-38194)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem, swap: fix softlockup with mTHP swapin\n\nFollowing softlockup can be easily reproduced on my test machine with:\n\necho always > /sys/kernel/mm/transparent_hugepage/hugepages-64kB/enabled\nswapon /dev/zram0 # zram0 is a 48G swap device\nmkdir -p /sys/fs/cgroup/memory/test\necho 1G > /sys/fs/cgroup/test/memory.max\necho $BASHPID > /sys/fs/cgroup/test/cgroup.procs\nwhile true; do\n dd if=/dev/zero of=/tmp/test.img bs=1M count=5120\n cat /tmp/test.img > /dev/null\n rm /tmp/test.img\ndone\n\nThen after a while:\nwatchdog: BUG: soft lockup - CPU#0 stuck for 763s! [cat:5787]\nModules linked in: zram virtiofs\nCPU: 0 UID: 0 PID: 5787 Comm: cat Kdump: loaded Tainted: G L 6.15.0.orig-gf3021d9246bc-dirty #118 PREEMPT(voluntary)·\nTainted: [L]=SOFTLOCKUP\nHardware name: Red Hat KVM/RHEL-AV, BIOS 0.0.0 02/06/2015\nRIP: 0010:mpol_shared_policy_lookup+0xd/0x70\nCode: e9 b8 b4 ff ff 31 c0 c3 cc cc cc cc 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 41 54 55 53 <48> 8b 1f 48 85 db 74 41 4c 8d 67 08 48 89 fb 48 89 f5 4c 89 e7 e8\nRSP: 0018:ffffc90002b1fc28 EFLAGS: 00000202\nRAX: 00000000001c20ca RBX: 0000000000724e1e RCX: 0000000000000001\nRDX: ffff888118e214c8 RSI: 0000000000057d42 RDI: ffff888118e21518\nRBP: 000000000002bec8 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000bf4 R11: 0000000000000000 R12: 0000000000000001\nR13: 00000000001c20ca R14: 00000000001c20ca R15: 0000000000000000\nFS: 00007f03f995c740(0000) GS:ffff88a07ad9a000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f03f98f1000 CR3: 0000000144626004 CR4: 0000000000770eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n <TASK>\n shmem_alloc_folio+0x31/0xc0\n shmem_swapin_folio+0x309/0xcf0\n ? filemap_get_entry+0x117/0x1e0\n ? xas_load+0xd/0xb0\n ? filemap_get_entry+0x101/0x1e0\n shmem_get_folio_gfp+0x2ed/0x5b0\n shmem_file_read_iter+0x7f/0x2e0\n vfs_read+0x252/0x330\n ksys_read+0x68/0xf0\n do_syscall_64+0x4c/0x1c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f03f9a46991\nCode: 00 48 8b 15 81 14 10 00 f7 d8 64 89 02 b8 ff ff ff ff eb bd e8 20 ad 01 00 f3 0f 1e fa 80 3d 35 97 10 00 00 74 13 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 4f c3 66 0f 1f 44 00 00 55 48 89 e5 48 83 ec\nRSP: 002b:00007fff3c52bd28 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\nRAX: ffffffffffffffda RBX: 0000000000040000 RCX: 00007f03f9a46991\nRDX: 0000000000040000 RSI: 00007f03f98ba000 RDI: 0000000000000003\nRBP: 00007fff3c52bd50 R08: 0000000000000000 R09: 00007f03f9b9a380\nR10: 0000000000000022 R11: 0000000000000246 R12: 0000000000040000\nR13: 00007f03f98ba000 R14: 0000000000000003 R15: 0000000000000000\n </TASK>\n\nThe reason is simple, readahead brought some order 0 folio in swap cache,\nand the swapin mTHP folio being allocated is in conflict with it, so\nswapcache_prepare fails and causes shmem_swap_alloc_folio to return\n-EEXIST, and shmem simply retries again and again causing this loop.\n\nFix it by applying a similar fix for anon mTHP swapin.\n\nThe performance change is very slight, time of swapin 10g zero folios\nwith shmem (test for 12 times):\nBefore: 2.47s\nAfter: 2.48s\n\n[(CVE-2025-38241)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()\n\nWhile testing null_blk with configfs, echo 0 > poll_queues will trigger\nfollowing panic:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000010\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 27 UID: 0 PID: 920 Comm: bash Not tainted 6.15.0-02023-gadbdb95c8696-dirty #1238 PREEMPT(undef)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\nRIP: 0010:__bitmap_or+0x48/0x70\nCall Trace:\n <TASK>\n __group_cpus_evenly+0x822/0x8c0\n group_cpus_evenly+0x2d9/0x490\n blk_mq_map_queues+0x1e/0x110\n null_map_queues+0xc9/0x170 [null_blk]\n blk_mq_update_queue_map+0xdb/0x160\n blk_mq_update_nr_hw_queues+0x22b/0x560\n nullb_update_nr_hw_queues+0x71/0xf0 [null_blk]\n nullb_device_poll_queues_store+0xa4/0x130 [null_blk]\n configfs_write_iter+0x109/0x1d0\n vfs_write+0x26e/0x6f0\n ksys_write+0x79/0x180\n __x64_sys_write+0x1d/0x30\n x64_sys_call+0x45c4/0x45f0\n do_syscall_64+0xa5/0x240\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nRoot cause is that numgrps is set to 0, and ZERO_SIZE_PTR is returned from\nkcalloc(), and later ZERO_SIZE_PTR will be deferenced.\n\nFix the problem by checking numgrps first in group_cpus_evenly(), and\nreturn NULL directly if numgrps is zero.\n\n[(CVE-2025-38255)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix NULL pointer deference on eir_get_service_data\n\nThe len parameter is considered optional so it can be NULL so it cannot\nbe used for skipping to next entry of EIR_SERVICE_DATA.(CVE-2025-38304)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Verify content returned by parse_int_array()\n\nThe first element of the returned array stores its length. If it is 0,\nany manipulation beyond the element at index 0 ends with null-ptr-deref.(CVE-2025-38307)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can\'t move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a "Dentry still in use" error, so add an error\nmessage that makes it clear this is what happened:\n\n[ 495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[ 495.281595] ------------[ cut here ]------------\n[ 495.281887] BUG: Dentry ffff888115531138{i=78,n=/} still in use (2) [unmount of cifs cifs]\n[ 495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we\'re already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did.(CVE-2025-38321)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: fix acpi parse and parseext cache leaks\n\nACPICA commit 8829e70e1360c81e7a5a901b5d4f48330e021ea5\n\nI\'m Seunghun Han, and I work for National Security Research Institute of\nSouth Korea.\n\nI have been doing a research on ACPI and found an ACPI cache leak in ACPI\nearly abort cases.\n\nBoot log of ACPI cache leak is as follows:\n[ 0.352414] ACPI: Added _OSI(Module Device)\n[ 0.353182] ACPI: Added _OSI(Processor Device)\n[ 0.353182] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.353182] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.356028] ACPI: Unable to start the ACPI Interpreter\n[ 0.356799] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.360215] kmem_cache_destroy Acpi-State: Slab cache still has objects\n[ 0.360648] CPU: 0 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #10\n[ 0.361273] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.361873] Call Trace:\n[ 0.362243] ? dump_stack+0x5c/0x81\n[ 0.362591] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.362944] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.363296] ? acpi_os_delete_cache+0xa/0x10\n[ 0.363646] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.364000] ? acpi_terminate+0xa/0x14\n[ 0.364000] ? acpi_init+0x2af/0x34f\n[ 0.364000] ? __class_create+0x4c/0x80\n[ 0.364000] ? video_setup+0x7f/0x7f\n[ 0.364000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.364000] ? do_one_initcall+0x4e/0x1a0\n[ 0.364000] ? kernel_init_freeable+0x189/0x20a\n[ 0.364000] ? rest_init+0xc0/0xc0\n[ 0.364000] ? kernel_init+0xa/0x100\n[ 0.364000] ? ret_from_fork+0x25/0x30\n\nI analyzed this memory leak in detail. I found that “Acpi-State” cache and\n“Acpi-Parse” cache were merged because the size of cache objects was same\nslab cache size.\n\nI finally found “Acpi-Parse” cache and “Acpi-parse_ext” cache were leaked\nusing SLAB_NEVER_MERGE flag in kmem_cache_create() function.\n\nReal ACPI cache leak point is as follows:\n[ 0.360101] ACPI: Added _OSI(Module Device)\n[ 0.360101] ACPI: Added _OSI(Processor Device)\n[ 0.360101] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.361043] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.364016] ACPI: Unable to start the ACPI Interpreter\n[ 0.365061] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.368174] kmem_cache_destroy Acpi-Parse: Slab cache still has objects\n[ 0.369332] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.371256] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.372000] Call Trace:\n[ 0.372000] ? dump_stack+0x5c/0x81\n[ 0.372000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.372000] ? acpi_ut_delete_caches+0x56/0x7b\n[ 0.372000] ? acpi_terminate+0xa/0x14\n[ 0.372000] ? acpi_init+0x2af/0x34f\n[ 0.372000] ? __class_create+0x4c/0x80\n[ 0.372000] ? video_setup+0x7f/0x7f\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? do_one_initcall+0x4e/0x1a0\n[ 0.372000] ? kernel_init_freeable+0x189/0x20a\n[ 0.372000] ? rest_init+0xc0/0xc0\n[ 0.372000] ? kernel_init+0xa/0x100\n[ 0.372000] ? ret_from_fork+0x25/0x30\n[ 0.388039] kmem_cache_destroy Acpi-parse_ext: Slab cache still has objects\n[ 0.389063] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.390557] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.392000] Call Trace:\n[ 0.392000] ? dump_stack+0x5c/0x81\n[ 0.392000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.392000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.392000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.392000] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.392000] ? acpi_terminate+0xa/0x14\n[ 0.392000] ? acpi_init+0x2af/0x3\n---truncated---(CVE-2025-38344)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmaple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()\n\nTemporarily clear the preallocation flag when explicitly requesting\nallocations. Pre-existing allocations are already counted against the\nrequest through mas_node_count_gfp(), but the allocations will not happen\nif the MA_STATE_PREALLOC flag is set. This flag is meant to avoid\nre-allocating in bulk allocation mode, and to detect issues with\npreallocation calculations.\n\nThe MA_STATE_PREALLOC flag should also always be set on zero allocations\nso that detection of underflow allocations will print a WARN_ON() during\nconsumption.\n\nUser visible effect of this flaw is a WARN_ON() followed by a null pointer\ndereference when subsequent requests for larger number of nodes is\nignored, such as the vma merge retry in mmap_region() caused by drivers\naltering the vma flags (which happens in v6.6, at least)(CVE-2025-38364)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_* TOCTOU\n\nTransport assignment may race with module unload. Protect new_transport\nfrom becoming a stale pointer.\n\nThis also takes care of an insecure call in vsock_use_local_transport();\nadd a lockdep assert.\n\nBUG: unable to handle page fault for address: fffffbfff8056000\nOops: Oops: 0000 [#1] SMP KASAN\nRIP: 0010:vsock_assign_transport+0x366/0x600\nCall Trace:\n vsock_connect+0x59c/0xc40\n __sys_connect+0xe8/0x100\n __x64_sys_connect+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53(CVE-2025-38461)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_{g2h,h2g} TOCTOU\n\nvsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.\ntransport_{g2h,h2g} may become NULL after the NULL check.\n\nIntroduce vsock_transport_local_cid() to protect from a potential\nnull-ptr-deref.\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_find_cid+0x47/0x90\nCall Trace:\n __vsock_bind+0x4b2/0x720\n vsock_bind+0x90/0xe0\n __sys_bind+0x14d/0x1e0\n __x64_sys_bind+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_dev_do_ioctl.isra.0+0x58/0xf0\nCall Trace:\n __x64_sys_ioctl+0x12d/0x190\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53(CVE-2025-38462)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in crypt_message when using async crypto\n\nThe CVE-2024-50047 fix removed asynchronous crypto handling from\ncrypt_message(), assuming all crypto operations are synchronous.\nHowever, when hardware crypto accelerators are used, this can cause\nuse-after-free crashes:\n\n crypt_message()\n // Allocate the creq buffer containing the req\n creq = smb2_get_aead_req(..., &req);\n\n // Async encryption returns -EINPROGRESS immediately\n rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);\n\n // Free creq while async operation is still in progress\n kvfree_sensitive(creq, ...);\n\nHardware crypto modules often implement async AEAD operations for\nperformance. When crypto_aead_encrypt/decrypt() returns -EINPROGRESS,\nthe operation completes asynchronously. Without crypto_wait_req(),\nthe function immediately frees the request buffer, leading to crashes\nwhen the driver later accesses the freed memory.\n\nThis results in a use-after-free condition when the hardware crypto\ndriver later accesses the freed request structure, leading to kernel\ncrashes with NULL pointer dereferences.\n\nThe issue occurs because crypto_alloc_aead() with mask=0 doesn\'t\nguarantee synchronous operation. Even without CRYPTO_ALG_ASYNC in\nthe mask, async implementations can be selected.\n\nFix by restoring the async crypto handling:\n- DECLARE_CRYPTO_WAIT(wait) for completion tracking\n- aead_request_set_callback() for async completion notification\n- crypto_wait_req() to wait for operation completion\n\nThis ensures the request buffer isn\'t freed until the crypto operation\ncompletes, whether synchronous or asynchronous, while preserving the\nCVE-2024-50047 fix.(CVE-2025-38488)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nclone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns\n\nWhat we want is to verify there is that clone won\'t expose something\nhidden by a mount we wouldn\'t be able to undo. "Wouldn\'t be able to undo"\nmay be a result of MNT_LOCKED on a child, but it may also come from\nlacking admin rights in the userns of the namespace mount belongs to.\n\nclone_private_mnt() checks the former, but not the latter.\n\nThere\'s a number of rather confusing CAP_SYS_ADMIN checks in various\nuserns during the mount, especially with the new mount API; they serve\ndifferent purposes and in case of clone_private_mnt() they usually,\nbut not always end up covering the missing check mentioned above.(CVE-2025-38499)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: plug races between subflow fail and subflow creation\n\nWe have races similar to the one addressed by the previous patch between\nsubflow failing and additional subflow creation. They are just harder to\ntrigger.\n\nThe solution is similar. Use a separate flag to track the condition\n\'socket state prevent any additional subflow creation\' protected by the\nfallback lock.\n\nThe socket fallback makes such flag true, and also receiving or sending\nan MP_FAIL option.\n\nThe field \'allow_infinite_fallback\' is now always touched under the\nrelevant lock, we can drop the ONCE annotation on write.(CVE-2025-38552)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use aead_request_free to match aead_request_alloc\n\nUse aead_request_free() instead of kfree() to properly free memory\nallocated by aead_request_alloc(). This ensures sensitive crypto data\nis zeroed before being freed.(CVE-2025-38575)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nPM / devfreq: Check governor before using governor->name\n\nCommit 96ffcdf239de ("PM / devfreq: Remove redundant governor_name from\nstruct devfreq") removes governor_name and uses governor->name to replace\nit. But devfreq->governor may be NULL and directly using\ndevfreq->governor->name may cause null pointer exception. Move the check of\ngovernor to before using governor->name.(CVE-2025-38609)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: fix refcount leak on table dump\n\nThere is a reference count leak in ctnetlink_dump_table():\n if (res < 0) {\n nf_conntrack_get(&ct->ct_general); // HERE\n cb->args[1] = (unsigned long)ct;\n ...\n\nWhile its very unlikely, its possible that ct == last.\nIf this happens, then the refcount of ct was already incremented.\nThis 2nd increment is never undone.\n\nThis prevents the conntrack object from being released, which in turn\nkeeps prevents cnet->count from dropping back to 0.\n\nThis will then block the netns dismantle (or conntrack rmmod) as\nnf_conntrack_cleanup_net_list() will wait forever.\n\nThis can be reproduced by running conntrack_resize.sh selftest in a loop.\nIt takes ~20 minutes for me on a preemptible kernel on average before\nI see a runaway kworker spinning in nf_conntrack_cleanup_net_list.\n\nOne fix would to change this to:\n if (res < 0) {\n\t\tif (ct != last)\n\t nf_conntrack_get(&ct->ct_general);\n\nBut this reference counting isn\'t needed in the first place.\nWe can just store a cookie value instead.\n\nA followup patch will do the same for ctnetlink_exp_dump_table,\nit looks to me as if this has the same problem and like\nctnetlink_dump_table, we only need a \'skip hint\', not the actual\nobject so we can apply the same cookie strategy there as well.(CVE-2025-38721)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla4xxx: Prevent a potential error pointer dereference\n\nThe qla4xxx_get_ep_fwdb() function is supposed to return NULL on error,\nbut qla4xxx_ep_connect() returns error pointers. Propagating the error\npointers will lead to an Oops in the caller, so change the error pointers\nto NULL.(CVE-2025-39676)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix handling of zero-length records on the rx_list\n\nEach recvmsg() call must process either\n - only contiguous DATA records (any number of them)\n - one non-DATA record\n\nIf the next record has different type than what has already been\nprocessed we break out of the main processing loop. If the record\nhas already been decrypted (which may be the case for TLS 1.3 where\nwe don\'t know type until decryption) we queue the pending record\nto the rx_list. Next recvmsg() will pick it up from there.\n\nQueuing the skb to rx_list after zero-copy decrypt is not possible,\nsince in that case we decrypted directly to the user space buffer,\nand we don\'t have an skb to queue (darg.skb points to the ciphertext\nskb for access to metadata like length).\n\nOnly data records are allowed zero-copy, and we break the processing\nloop after each non-data record. So we should never zero-copy and\nthen find out that the record type has changed. The corner case\nwe missed is when the initial record comes from rx_list, and it\'s\nzero length.(CVE-2025-39682)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this.(CVE-2025-39702)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nclk: samsung: Fix UBSAN panic in samsung_clk_init()\n\nWith UBSAN_ARRAY_BOUNDS=y, I\'m hitting the below panic due to\ndereferencing `ctx->clk_data.hws` before setting\n`ctx->clk_data.num = nr_clks`. Move that up to fix the crash.\n\n UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP\n <snip>\n Call trace:\n samsung_clk_init+0x110/0x124 (P)\n samsung_clk_init+0x48/0x124 (L)\n samsung_cmu_register_one+0x3c/0xa0\n exynos_arm64_register_cmu+0x54/0x64\n __gs101_cmu_top_of_clk_init_declare+0x28/0x60\n ...(CVE-2025-39728)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfs: Prevent file descriptor table allocations exceeding INT_MAX\n\nWhen sysctl_nr_open is set to a very high value (for example, 1073741816\nas set by systemd), processes attempting to use file descriptors near\nthe limit can trigger massive memory allocation attempts that exceed\nINT_MAX, resulting in a WARNING in mm/slub.c:\n\n WARNING: CPU: 0 PID: 44 at mm/slub.c:5027 __kvmalloc_node_noprof+0x21a/0x288\n\nThis happens because kvmalloc_array() and kvmalloc() check if the\nrequested size exceeds INT_MAX and emit a warning when the allocation is\nnot flagged with __GFP_NOWARN.\n\nSpecifically, when nr_open is set to 1073741816 (0x3ffffff8) and a\nprocess calls dup2(oldfd, 1073741880), the kernel attempts to allocate:\n- File descriptor array: 1073741880 * 8 bytes = 8,589,935,040 bytes\n- Multiple bitmaps: ~400MB\n- Total allocation size: > 8GB (exceeding INT_MAX = 2,147,483,647)\n\nReproducer:\n1. Set /proc/sys/fs/nr_open to 1073741816:\n # echo 1073741816 > /proc/sys/fs/nr_open\n\n2. Run a program that uses a high file descriptor:\n #include <unistd.h>\n #include <sys/resource.h>\n\n int main() {\n struct rlimit rlim = {1073741824, 1073741824};\n setrlimit(RLIMIT_NOFILE, &rlim);\n dup2(2, 1073741880); // Triggers the warning\n return 0;\n }\n\n3. Observe WARNING in dmesg at mm/slub.c:5027\n\nsystemd commit a8b627a introduced automatic bumping of fs.nr_open to the\nmaximum possible value. The rationale was that systems with memory\ncontrol groups (memcg) no longer need separate file descriptor limits\nsince memory is properly accounted. However, this change overlooked\nthat:\n\n1. The kernel\'s allocation functions still enforce INT_MAX as a maximum\n size regardless of memcg accounting\n2. Programs and tests that legitimately test file descriptor limits can\n inadvertently trigger massive allocations\n3. The resulting allocations (>8GB) are impractical and will always fail\n\nsystemd\'s algorithm starts with INT_MAX and keeps halving the value\nuntil the kernel accepts it. On most systems, this results in nr_open\nbeing set to 1073741816 (0x3ffffff8), which is just under 1GB of file\ndescriptors.\n\nWhile processes rarely use file descriptors near this limit in normal\noperation, certain selftests (like\ntools/testing/selftests/core/unshare_test.c) and programs that test file\ndescriptor limits can trigger this issue.\n\nFix this by adding a check in alloc_fdtable() to ensure the requested\nallocation size does not exceed INT_MAX. This causes the operation to\nfail with -EMFILE instead of triggering a kernel warning and avoids the\nimpractical >8GB memory allocation request.(CVE-2025-39756)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM\n\nWhen performing Generic Segmentation Offload (GSO) on an IPv6 packet that\ncontains extension headers, the kernel incorrectly requests checksum offload\nif the egress device only advertises NETIF_F_IPV6_CSUM feature, which has\na strict contract: it supports checksum offload only for plain TCP or UDP\nover IPv6 and explicitly does not support packets with extension headers.\nThe current GSO logic violates this contract by failing to disable the feature\nfor packets with extension headers, such as those used in GREoIPv6 tunnels.\n\nThis violation results in the device being asked to perform an operation\nit cannot support, leading to a `skb_warn_bad_offload` warning and a collapse\nof network throughput. While device TSO/USO is correctly bypassed in favor\nof software GSO for these packets, the GSO stack must be explicitly told not\nto request checksum offload.\n\nMask NETIF_F_IPV6_CSUM, NETIF_F_TSO6 and NETIF_F_GSO_UDP_L4\nin gso_features_check if the IPv6 header contains extension headers to compute\nchecksum in software.\n\nThe exception is a BIG TCP extension, which, as stated in commit\n68e068cabd2c6c53 ("net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets"):\n"The feature is only enabled on devices that support BIG TCP TSO.\nThe header is only present for PF_PACKET taps like tcpdump,\nand not transmitted by physical devices."\n\nkernel log output (truncated):\nWARNING: CPU: 1 PID: 5273 at net/core/dev.c:3535 skb_warn_bad_offload+0x81/0x140\n...\nCall Trace:\n <TASK>\n skb_checksum_help+0x12a/0x1f0\n validate_xmit_skb+0x1a3/0x2d0\n validate_xmit_skb_list+0x4f/0x80\n sch_direct_xmit+0x1a2/0x380\n __dev_xmit_skb+0x242/0x670\n __dev_queue_xmit+0x3fc/0x7f0\n ip6_finish_output2+0x25e/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_tnl_xmit+0x608/0xc00 [ip6_tunnel]\n ip6gre_tunnel_xmit+0x1c0/0x390 [ip6_gre]\n dev_hard_start_xmit+0x63/0x1c0\n __dev_queue_xmit+0x6d0/0x7f0\n ip6_finish_output2+0x214/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n inet6_csk_xmit+0xeb/0x150\n __tcp_transmit_skb+0x555/0xa80\n tcp_write_xmit+0x32a/0xe90\n tcp_sendmsg_locked+0x437/0x1110\n tcp_sendmsg+0x2f/0x50\n...\nskb linear: 00000000: e4 3d 1a 7d ec 30 e4 3d 1a 7e 5d 90 86 dd 60 0e\nskb linear: 00000010: 00 0a 1b 34 3c 40 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000020: 00 00 00 00 00 12 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000030: 00 00 00 00 00 11 2f 00 04 01 04 01 01 00 00 00\nskb linear: 00000040: 86 dd 60 0e 00 0a 1b 00 06 40 20 23 00 00 00 00\nskb linear: 00000050: 00 00 00 00 00 00 00 00 00 12 20 23 00 00 00 00\nskb linear: 00000060: 00 00 00 00 00 00 00 00 00 11 bf 96 14 51 13 f9\nskb linear: 00000070: ae 27 a0 a8 2b e3 80 18 00 40 5b 6f 00 00 01 01\nskb linear: 00000080: 08 0a 42 d4 50 d5 4b 70 f8 1a(CVE-2025-39770)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: initialize more fields in sctp_v6_from_sk()\n\nsyzbot found that sin6_scope_id was not properly initialized,\nleading to undefined behavior.\n\nClear sin6_scope_id and sin6_flowinfo.\n\nBUG: KMSAN: uninit-value in __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n sctp_inet6_cmp_addr+0x4f2/0x510 net/sctp/ipv6.c:983\n sctp_bind_addr_conflict+0x22a/0x3b0 net/sctp/bind_addr.c:390\n sctp_get_port_local+0x21eb/0x2440 net/sctp/socket.c:8452\n sctp_get_port net/sctp/socket.c:8523 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x710/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930\n x64_sys_call+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls_64.h:51\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable addr.i.i created at:\n sctp_get_port net/sctp/socket.c:8515 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x650/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930(CVE-2025-39812)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix buffer free/clear order in deferred receive path\n\nFix a use-after-free window by correcting the buffer release sequence in\nthe deferred receive path. The code freed the RQ buffer first and only\nthen cleared the context pointer under the lock. Concurrent paths (e.g.,\nABTS and the repost path) also inspect and release the same pointer under\nthe lock, so the old order could lead to double-free/UAF.\n\nNote that the repost path already uses the correct pattern: detach the\npointer under the lock, then free it after dropping the lock. The\ndeferred path should do the same.(CVE-2025-39841)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm\n\nWhen send a broadcast packet to a tap device, which was added to a bridge,\nbr_nf_local_in() is called to confirm the conntrack. If another conntrack\nwith the same hash value is added to the hash table, which can be\ntriggered by a normal packet to a non-bridge device, the below warning\nmay happen.\n\n ------------[ cut here ]------------\n WARNING: CPU: 1 PID: 96 at net/bridge/br_netfilter_hooks.c:632 br_nf_local_in+0x168/0x200\n CPU: 1 UID: 0 PID: 96 Comm: tap_send Not tainted 6.17.0-rc2-dirty #44 PREEMPT(voluntary)\n RIP: 0010:br_nf_local_in+0x168/0x200\n Call Trace:\n <TASK>\n nf_hook_slow+0x3e/0xf0\n br_pass_frame_up+0x103/0x180\n br_handle_frame_finish+0x2de/0x5b0\n br_nf_hook_thresh+0xc0/0x120\n br_nf_pre_routing_finish+0x168/0x3a0\n br_nf_pre_routing+0x237/0x5e0\n br_handle_frame+0x1ec/0x3c0\n __netif_receive_skb_core+0x225/0x1210\n __netif_receive_skb_one_core+0x37/0xa0\n netif_receive_skb+0x36/0x160\n tun_get_user+0xa54/0x10c0\n tun_chr_write_iter+0x65/0xb0\n vfs_write+0x305/0x410\n ksys_write+0x60/0xd0\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n ---[ end trace 0000000000000000 ]---\n\nTo solve the hash conflict, nf_ct_resolve_clash() try to merge the\nconntracks, and update skb->_nfct. However, br_nf_local_in() still use the\nold ct from local variable \'nfct\' after confirm(), which leads to this\nwarning.\n\nIf confirm() does not insert the conntrack entry and return NF_DROP, the\nwarning may also occur. There is no need to reserve the WARN_ON_ONCE, just\nremove it.(CVE-2025-39894)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer\n\nSince commit 7d5e9737efda ("net: rfkill: gpio: get the name and type from\ndevice property") rfkill_find_type() gets called with the possibly\nuninitialized "const char *type_name;" local variable.\n\nOn x86 systems when rfkill-gpio binds to a "BCM4752" or "LNV4752"\nacpi_device, the rfkill->type is set based on the ACPI acpi_device_id:\n\n rfkill->type = (unsigned)id->driver_data;\n\nand there is no "type" property so device_property_read_string() will fail\nand leave type_name uninitialized, leading to a potential crash.\n\nrfkill_find_type() does accept a NULL pointer, fix the potential crash\nby initializing type_name to NULL.\n\nNote likely sofar this has not been caught because:\n\n1. Not many x86 machines actually have a "BCM4752"/"LNV4752" acpi_device\n2. The stack happened to contain NULL where type_name is stored(CVE-2025-39937)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().\n\nsyzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk\nin the TCP_ESTABLISHED state. [0]\n\nsyzbot reused the server-side TCP Fast Open socket as a new client before\nthe TFO socket completes 3WHS:\n\n 1. accept()\n 2. connect(AF_UNSPEC)\n 3. connect() to another destination\n\nAs of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes\nit to TCP_CLOSE and makes connect() possible, which restarts timers.\n\nSince tcp_disconnect() forgot to clear tcp_sk(sk)->fastopen_rsk, the\nretransmit timer triggered the warning and the intended packet was not\nretransmitted.\n\nLet\'s call reqsk_fastopen_remove() in tcp_disconnect().\n\n[0]:\nWARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nModules linked in:\nCPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nCode: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 <0f> 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e\nRSP: 0018:ffffc900002f8d40 EFLAGS: 00010293\nRAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017\nRDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400\nRBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8\nR10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540\nR13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0\nFS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0\nCall Trace:\n <IRQ>\n tcp_write_timer (net/ipv4/tcp_timer.c:738)\n call_timer_fn (kernel/time/timer.c:1747)\n __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2372)\n timer_expire_remote (kernel/time/timer.c:2385 kernel/time/timer.c:2376 kernel/time/timer.c:2135)\n tmigr_handle_remote_up (kernel/time/timer_migration.c:944 kernel/time/timer_migration.c:1035)\n __walk_groups.isra.0 (kernel/time/timer_migration.c:533 (discriminator 1))\n tmigr_handle_remote (kernel/time/timer_migration.c:1096)\n handle_softirqs (./arch/x86/include/asm/jump_label.h:36 ./include/trace/events/irq.h:142 kernel/softirq.c:580)\n irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680 kernel/softirq.c:696)\n sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 (discriminator 35) arch/x86/kernel/apic/apic.c:1050 (discriminator 35))\n </IRQ>(CVE-2025-39955)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Forbid FDB status change while nexthop is in a group\n\nThe kernel forbids the creation of non-FDB nexthop groups with FDB\nnexthops:\n\n # ip nexthop add id 1 via 192.0.2.1 fdb\n # ip nexthop add id 2 group 1\n Error: Non FDB nexthop group cannot have fdb nexthops.\n\nAnd vice versa:\n\n # ip nexthop add id 3 via 192.0.2.2 dev dummy1\n # ip nexthop add id 4 group 3 fdb\n Error: FDB nexthop group can only have fdb nexthops.\n\nHowever, as long as no routes are pointing to a non-FDB nexthop group,\nthe kernel allows changing the type of a nexthop from FDB to non-FDB and\nvice versa:\n\n # ip nexthop add id 5 via 192.0.2.2 dev dummy1\n # ip nexthop add id 6 group 5\n # ip nexthop replace id 5 via 192.0.2.2 fdb\n # echo $?\n 0\n\nThis configuration is invalid and can result in a NPD [1] since FDB\nnexthops are not associated with a nexthop device:\n\n # ip route add 198.51.100.1/32 nhid 6\n # ping 198.51.100.1\n\nFix by preventing nexthop FDB status change while the nexthop is in a\ngroup:\n\n # ip nexthop add id 7 via 192.0.2.2 dev dummy1\n # ip nexthop add id 8 group 7\n # ip nexthop replace id 7 via 192.0.2.2 fdb\n Error: Cannot change nexthop FDB status while in a group.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 00000000000003c0\n[...]\nOops: Oops: 0000 [#1] SMP\nCPU: 6 UID: 0 PID: 367 Comm: ping Not tainted 6.17.0-rc6-virtme-gb65678cacc03 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\nRIP: 0010:fib_lookup_good_nhc+0x1e/0x80\n[...]\nCall Trace:\n <TASK>\n fib_table_lookup+0x541/0x650\n ip_route_output_key_hash_rcu+0x2ea/0x970\n ip_route_output_key_hash+0x55/0x80\n __ip4_datagram_connect+0x250/0x330\n udp_connect+0x2b/0x60\n __sys_connect+0x9c/0xd0\n __x64_sys_connect+0x18/0x20\n do_syscall_64+0xa4/0x2a0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53(CVE-2025-39980)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipvs: Defer ip_vs_ftp unregister during netns cleanup\n\nOn the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp\nbefore connections with valid cp->app pointers are flushed, leading to a\nuse-after-free.\n\nFix this by introducing a global `exiting_module` flag, set to true in\nip_vs_ftp_exit() before unregistering the pernet subsystem. In\n__ip_vs_ftp_exit(), skip ip_vs_ftp unregister if called during netns\ncleanup (when exiting_module is false) and defer it to\n__ip_vs_cleanup_batch(), which unregisters all apps after all connections\nare flushed. If called during module exit, unregister ip_vs_ftp\nimmediately.(CVE-2025-40018)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs\n\nWhen the initialization of qm->debug.acc_diff_reg fails,\nthe probe process does not exit. However, after qm->debug.qm_diff_regs is\nfreed, it is not set to NULL. This can lead to a double free when the\nremove process attempts to free it again. Therefore, qm->debug.qm_diff_regs\nshould be set to NULL after it is freed.(CVE-2025-40062)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n 0: r0 = 0\n 1: r2 = *(u32 *)(r1 +60)\n 2: exit\n\nwhich triggers:\n\n verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn\'t rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn\'t find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch.(CVE-2025-40078)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - request reserved interrupt for virtual function\n\nThe device interrupt vector 3 is an error interrupt for\nphysical function and a reserved interrupt for virtual function.\nHowever, the driver has not registered the reserved interrupt for\nvirtual function. When allocating interrupts, the number of interrupts\nis allocated based on powers of two, which includes this interrupt.\nWhen the system enables GICv4 and the virtual function passthrough\nto the virtual machine, releasing the interrupt in the driver\ntriggers a warning.\n\nThe WARNING report is:\nWARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4\n\nTherefore, register a reserved interrupt for VF and set the\nIRQF_NO_AUTOEN flag to avoid that warning.(CVE-2025-40136)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid NULL dereference when chunk data buffer is missing\n\nchunk->skb pointer is dereferenced in the if-block where it\'s supposed\nto be NULL only.\n\nchunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list\ninstead and do it just before replacing chunk->skb. We\'re sure that\notherwise chunk->skb is non-NULL because of outer if() condition.(CVE-2025-40240)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: remove never-working support for setting nsh fields\n\nThe validation of the set(nsh(...)) action is completely wrong.\nIt runs through the nsh_key_put_from_nlattr() function that is the\nsame function that validates NSH keys for the flow match and the\npush_nsh() action. However, the set(nsh(...)) has a very different\nmemory layout. Nested attributes in there are doubled in size in\ncase of the masked set(). That makes proper validation impossible.\n\nThere is also confusion in the code between the \'masked\' flag, that\nsays that the nested attributes are doubled in size containing both\nthe value and the mask, and the \'is_mask\' that says that the value\nwe\'re parsing is the mask. This is causing kernel crash on trying to\nwrite into mask part of the match with SW_FLOW_KEY_PUT() during\nvalidation, while validate_nsh() doesn\'t allocate any memory for it:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000018\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0\n Oops: Oops: 0000 [#1] SMP NOPTI\n CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary)\n RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch]\n Call Trace:\n <TASK>\n validate_nsh+0x60/0x90 [openvswitch]\n validate_set.constprop.0+0x270/0x3c0 [openvswitch]\n __ovs_nla_copy_actions+0x477/0x860 [openvswitch]\n ovs_nla_copy_actions+0x8d/0x100 [openvswitch]\n ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch]\n genl_family_rcv_msg_doit+0xdb/0x130\n genl_family_rcv_msg+0x14b/0x220\n genl_rcv_msg+0x47/0xa0\n netlink_rcv_skb+0x53/0x100\n genl_rcv+0x24/0x40\n netlink_unicast+0x280/0x3b0\n netlink_sendmsg+0x1f7/0x430\n ____sys_sendmsg+0x36b/0x3a0\n ___sys_sendmsg+0x87/0xd0\n __sys_sendmsg+0x6d/0xd0\n do_syscall_64+0x7b/0x2c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe third issue with this process is that while trying to convert\nthe non-masked set into masked one, validate_set() copies and doubles\nthe size of the OVS_KEY_ATTR_NSH as if it didn\'t have any nested\nattributes. It should be copying each nested attribute and doubling\nthem in size independently. And the process must be properly reversed\nduring the conversion back from masked to a non-masked variant during\nthe flow dump.\n\nIn the end, the only two outcomes of trying to use this action are\neither validation failure or a kernel crash. And if somehow someone\nmanages to install a flow with such an action, it will most definitely\nnot do what it is supposed to, since all the keys and the masks are\nmixed up.\n\nFixing all the issues is a complex task as it requires re-writing\nmost of the validation code.\n\nGiven that and the fact that this functionality never worked since\nintroduction, let\'s just remove it altogether. It\'s better to\nre-introduce it later with a proper implementation instead of trying\nto fix it in stable releases.(CVE-2025-40254)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Fix use-after-free in tipc_mon_reinit_self().\n\nsyzbot reported use-after-free of tipc_net(net)->monitors[]\nin tipc_mon_reinit_self(). [0]\n\nThe array is protected by RTNL, but tipc_mon_reinit_self()\niterates over it without RTNL.\n\ntipc_mon_reinit_self() is called from tipc_net_finalize(),\nwhich is always under RTNL except for tipc_net_finalize_work().\n\nLet\'s hold RTNL in tipc_net_finalize_work().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\nBUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\nRead of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989\n\nCPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)}\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025\nWorkqueue: events tipc_net_finalize_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568\n kasan_check_byte include/linux/kasan.h:399 [inline]\n lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\n rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline]\n rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline]\n rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244\n rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243\n write_lock_bh include/linux/rwlock_rt.h:99 [inline]\n tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718\n tipc_net_finalize+0x115/0x190 net/tipc/net.c:140\n process_one_work kernel/workqueue.c:3236 [inline]\n process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319\n worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400\n kthread+0x70e/0x8a0 kernel/kthread.c:463\n ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>\n\nAllocated by task 6089:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:388 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407\n kmalloc_noprof include/linux/slab.h:905 [inline]\n kzalloc_noprof include/linux/slab.h:1039 [inline]\n tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657\n tipc_enable_bearer net/tipc/bearer.c:357 [inline]\n __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047\n __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline]\n tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393\n tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline]\n tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321\n genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]\n netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346\n netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896\n sock_sendmsg_nosec net/socket.c:714 [inline]\n __sock_sendmsg+0x21c/0x270 net/socket.c:729\n ____sys_sendmsg+0x508/0x820 net/socket.c:2614\n ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668\n __sys_sendmsg net/socket.c:2700 [inline]\n __do_sys_sendmsg net/socket.c:2705 [inline]\n __se_sys_sendmsg net/socket.c:2703 [inline]\n __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/\n---truncated---(CVE-2025-40280)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto\n\nsyzbot reported a possible shift-out-of-bounds [1]\n\nBlamed commit added rto_alpha_max and rto_beta_max set to 1000.\n\nIt is unclear if some sctp users are setting very large rto_alpha\nand/or rto_beta.\n\nIn order to prevent user regression, perform the test at run time.\n\nAlso add READ_ONCE() annotations as sysctl values can change under us.\n\n[1]\n\nUBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41\nshift exponent 64 is too large for 32-bit type \'unsigned int\'\nCPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120\n ubsan_epilogue lib/ubsan.c:233 [inline]\n __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494\n sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509\n sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502\n sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338\n sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline]\n sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline](CVE-2025-40281)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Prevent TOCTOU out-of-bounds write\n\nFor the following path not holding the sock lock,\n\n sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump()\n\nmake sure not to exceed bounds in case the address list has grown\nbetween buffer allocation (time-of-check) and write (time-of-use).(CVE-2025-40331)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: replace BUG_ON with bounds check for map->max_osd\n\nOSD indexes come from untrusted network packets. Boundary checks are\nadded to validate these against map->max_osd.\n\n[ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic\n edits ](CVE-2025-68283)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()\n\nThe len field originates from untrusted network packets. Boundary\nchecks have been added to prevent potential out-of-bounds writes when\ndecrypting the connection secret or processing service tickets.\n\n[ idryomov: changelog ](CVE-2025-68284)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix potential use-after-free in have_mon_and_osd_map()\n\nThe wait loop in __ceph_open_session() can race with the client\nreceiving a new monmap or osdmap shortly after the initial map is\nreceived. Both ceph_monc_handle_map() and handle_one_map() install\na new map immediately after freeing the old one\n\n kfree(monc->monmap);\n monc->monmap = monmap;\n\n ceph_osdmap_destroy(osdc->osdmap);\n osdc->osdmap = newmap;\n\nunder client->monc.mutex and client->osdc.lock respectively, but\nbecause neither is taken in have_mon_and_osd_map() it\'s possible for\nclient->monc.monmap->epoch and client->osdc.osdmap->epoch arms in\n\n client->monc.monmap && client->monc.monmap->epoch &&\n client->osdc.osdmap && client->osdc.osdmap->epoch;\n\ncondition to dereference an already freed map. This happens to be\nreproducible with generic/395 and generic/397 with KASAN enabled:\n\n BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70\n Read of size 4 at addr ffff88811012d810 by task mount.ceph/13305\n CPU: 2 UID: 0 PID: 13305 Comm: mount.ceph Not tainted 6.14.0-rc2-build2+ #1266\n ...\n Call Trace:\n <TASK>\n have_mon_and_osd_map+0x56/0x70\n ceph_open_session+0x182/0x290\n ceph_get_tree+0x333/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\n Allocated by task 13305:\n ceph_osdmap_alloc+0x16/0x130\n ceph_osdc_init+0x27a/0x4c0\n ceph_create_client+0x153/0x190\n create_fs_client+0x50/0x2a0\n ceph_get_tree+0xff/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 9475:\n kfree+0x212/0x290\n handle_one_map+0x23c/0x3b0\n ceph_osdc_handle_map+0x3c9/0x590\n mon_dispatch+0x655/0x6f0\n ceph_con_process_message+0xc3/0xe0\n ceph_con_v1_try_read+0x614/0x760\n ceph_con_workfn+0x2de/0x650\n process_one_work+0x486/0x7c0\n process_scheduled_works+0x73/0x90\n worker_thread+0x1c8/0x2a0\n kthread+0x2ec/0x300\n ret_from_fork+0x24/0x40\n ret_from_fork_asm+0x1a/0x30\n\nRewrite the wait loop to check the above condition directly with\nclient->monc.mutex and client->osdc.lock taken as appropriate. While\nat it, improve the timeout handling (previously mount_timeout could be\nexceeded in case wait_event_interruptible_timeout() slept more than\nonce) and access client->auth_err under client->monc.mutex to match\nhow it\'s set in finish_auth().\n\nmonmap_show() and osdmap_show() now take the respective lock before\naccessing the map as well.(CVE-2025-68285)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: lookup hci_conn on RX path on protocol side\n\nThe hdev lock/lookup/unlock/use pattern in the packet RX path doesn\'t\nensure hci_conn* is not concurrently modified/deleted. This locking\nappears to be leftover from before conn_hash started using RCU\ncommit bf4c63252490b ("Bluetooth: convert conn hash to RCU")\nand not clear if it had purpose since then.\n\nCurrently, there are code paths that delete hci_conn* from elsewhere\nthan the ordered hdev->workqueue where the RX work runs in. E.g.\ncommit 5af1f84ed13a ("Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync")\nintroduced some of these, and there probably were a few others before\nit. It\'s better to do the locking so that even if these run\nconcurrently no UAF is possible.\n\nMove the lookup of hci_conn and associated socket-specific conn to\nprotocol recv handlers, and do them within a single critical section\nto cover hci_conn* usage and lookup.\n\nsyzkaller has reported a crash that appears to be this issue:\n\n [Task hdev->workqueue] [Task 2]\n hci_disconnect_all_sync\n l2cap_recv_acldata(hcon)\n hci_conn_get(hcon)\n hci_abort_conn_sync(hcon)\n hci_dev_lock\n hci_dev_lock\n hci_conn_del(hcon)\n v-------------------------------- hci_dev_unlock\n hci_conn_put(hcon)\n conn = hcon->l2cap_data (UAF)(CVE-2025-68304)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nima: Handle error code returned by ima_filter_rule_match()\n\nIn ima_match_rules(), if ima_filter_rule_match() returns -ENOENT due to\nthe rule being NULL, the function incorrectly skips the \'if (!rc)\' check\nand sets \'result = true\'. The LSM rule is considered a match, causing\nextra files to be measured by IMA.\n\nThis issue can be reproduced in the following scenario:\nAfter unloading the SELinux policy module via \'semodule -d\', if an IMA\nmeasurement is triggered before ima_lsm_rules is updated,\nin ima_match_rules(), the first call to ima_filter_rule_match() returns\n-ESTALE. This causes the code to enter the \'if (rc == -ESTALE &&\n!rule_reinitialized)\' block, perform ima_lsm_copy_rule() and retry. In\nima_lsm_copy_rule(), since the SELinux module has been removed, the rule\nbecomes NULL, and the second call to ima_filter_rule_match() returns\n-ENOENT. This bypasses the \'if (!rc)\' check and results in a false match.\n\nCall trace:\n selinux_audit_rule_match+0x310/0x3b8\n security_audit_rule_match+0x60/0xa0\n ima_match_rules+0x2e4/0x4a0\n ima_match_policy+0x9c/0x1e8\n ima_get_action+0x48/0x60\n process_measurement+0xf8/0xa98\n ima_bprm_check+0x98/0xd8\n security_bprm_check+0x5c/0x78\n search_binary_handler+0x6c/0x318\n exec_binprm+0x58/0x1b8\n bprm_execve+0xb8/0x130\n do_execveat_common.isra.0+0x1a8/0x258\n __arm64_sys_execve+0x48/0x68\n invoke_syscall+0x50/0x128\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x44/0x200\n el0t_64_sync_handler+0x100/0x130\n el0t_64_sync+0x3c8/0x3d0\n\nFix this by changing \'if (!rc)\' to \'if (rc <= 0)\' to ensure that error\ncodes like -ENOENT do not bypass the check and accidentally result in a\nsuccessful match.(CVE-2025-68740)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix invalid prog->stats access when update_effective_progs fails\n\nSyzkaller triggers an invalid memory access issue following fault\ninjection in update_effective_progs. The issue can be described as\nfollows:\n\n__cgroup_bpf_detach\n update_effective_progs\n compute_effective_progs\n bpf_prog_array_alloc <-- fault inject\n purge_effective_progs\n /* change to dummy_bpf_prog */\n array->items[index] = &dummy_bpf_prog.prog\n\n---softirq start---\n__do_softirq\n ...\n __cgroup_bpf_run_filter_skb\n __bpf_prog_run_save_cb\n bpf_prog_run\n stats = this_cpu_ptr(prog->stats)\n /* invalid memory access */\n flags = u64_stats_update_begin_irqsave(&stats->syncp)\n---softirq end---\n\n static_branch_dec(&cgroup_bpf_enabled_key[atype])\n\nThe reason is that fault injection caused update_effective_progs to fail\nand then changed the original prog into dummy_bpf_prog.prog in\npurge_effective_progs. Then a softirq came, and accessing the members of\ndummy_bpf_prog.prog in the softirq triggers invalid mem access.\n\nTo fix it, skip updating stats when stats is NULL.(CVE-2025-68742)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nethtool: Avoid overflowing userspace buffer on stats query\n\nThe ethtool -S command operates across three ioctl calls:\nETHTOOL_GSSET_INFO for the size, ETHTOOL_GSTRINGS for the names, and\nETHTOOL_GSTATS for the values.\n\nIf the number of stats changes between these calls (e.g., due to device\nreconfiguration), userspace\'s buffer allocation will be incorrect,\npotentially leading to buffer overflow.\n\nDrivers are generally expected to maintain stable stat counts, but some\ndrivers (e.g., mlx5, bnx2x, bna, ksz884x) use dynamic counters, making\nthis scenario possible.\n\nSome drivers try to handle this internally:\n- bnad_get_ethtool_stats() returns early in case stats.n_stats is not\n equal to the driver\'s stats count.\n- micrel/ksz884x also makes sure not to write anything beyond\n stats.n_stats and overflow the buffer.\n\nHowever, both use stats.n_stats which is already assigned with the value\nreturned from get_sset_count(), hence won\'t solve the issue described\nhere.\n\nChange ethtool_get_strings(), ethtool_get_stats(),\nethtool_get_phy_stats() to not return anything in case of a mismatch\nbetween userspace\'s size and get_sset_size(), to prevent buffer\noverflow.\nThe returned n_stats value will be equal to zero, to reflect that\nnothing has been returned.\n\nThis could result in one of two cases when using upstream ethtool,\ndepending on when the size change is detected:\n1. When detected in ethtool_get_strings():\n # ethtool -S eth2\n no stats available\n\n2. When detected in get stats, all stats will be reported as zero.\n\nBoth cases are presumably transient, and a subsequent ethtool call\nshould succeed.\n\nOther than the overflow avoidance, these two cases are very evident (no\noutput/cleared stats), which is arguably better than presenting\nincorrect/shifted stats.\nI also considered returning an error instead of a "silent" response, but\nthat seems more destructive towards userspace apps.\n\nNotes:\n- This patch does not claim to fix the inherent race, it only makes sure\n that we do not overflow the userspace buffer, and makes for a more\n predictable behavior.\n\n- RTNL lock is held during each ioctl, the race window exists between\n the separate ioctl calls when the lock is released.\n\n- Userspace ethtool always fills stats.n_stats, but it is likely that\n these stats ioctls are implemented in other userspace applications\n which might not fill it. The added code checks that it\'s not zero,\n to prevent any regressions.(CVE-2025-68795)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: xattr: fix null pointer deref in ext4_raw_inode()\n\nIf ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),\niloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()\nlacks error checking, this will lead to a null pointer dereference\nin ext4_raw_inode(), called right after ext4_get_inode_loc().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-68820)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.(CVE-2025-71064)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset\n\n`qfq_class->leaf_qdisc->q.qlen > 0` does not imply that the class\nitself is active.\n\nTwo qfq_class objects may point to the same leaf_qdisc. This happens\nwhen:\n\n1. one QFQ qdisc is attached to the dev as the root qdisc, and\n\n2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get()\n/ qdisc_put()) and is pending to be destroyed, as in function\ntc_new_tfilter.\n\nWhen packets are enqueued through the root QFQ qdisc, the shared\nleaf_qdisc->q.qlen increases. At the same time, the second QFQ\nqdisc triggers qdisc_put and qdisc_destroy: the qdisc enters\nqfq_reset() with its own q->q.qlen == 0, but its class\'s leaf\nqdisc->q.qlen > 0. Therefore, the qfq_reset would wrongly deactivate\nan inactive aggregate and trigger a null-deref in qfq_deactivate_agg:\n\n[ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 0.903571] #PF: supervisor write access in kernel mode\n[ 0.903860] #PF: error_code(0x0002) - not-present page\n[ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0\n[ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI\n[ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE\n[ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2))\n[ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0\n\nCode starting with the faulting instruction\n===========================================\n 0:\t0f 84 4d 01 00 00 \tje 0x153\n 6:\t48 89 70 18 \tmov %rsi,0x18(%rax)\n a:\t8b 4b 10 \tmov 0x10(%rbx),%ecx\n d:\t48 c7 c2 ff ff ff ff \tmov $0xffffffffffffffff,%rdx\n 14:\t48 8b 78 08 \tmov 0x8(%rax),%rdi\n 18:\t48 d3 e2 \tshl %cl,%rdx\n 1b:\t48 21 f2 \tand %rsi,%rdx\n 1e:\t48 2b 13 \tsub (%rbx),%rdx\n 21:\t48 8b 30 \tmov (%rax),%rsi\n 24:\t48 d3 ea \tshr %cl,%rdx\n 27:\t8b 4b 18 \tmov 0x18(%rbx),%ecx\n\t...\n[ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246\n[ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000\n[ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000\n[ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000\n[ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880\n[ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000\n[ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0\n[ 0.910247] PKRU: 55555554\n[ 0.910391] Call Trace:\n[ 0.910527] <TASK>\n[ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485)\n[ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036)\n[ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076)\n[ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447)\n[ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\n[ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861)\n[ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550)\n[ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\n[ 0.912296] ? __alloc_skb (net/core/skbuff.c:706)\n[ 0.912484] netlink_sendmsg (net/netlink/af\n---truncated---(CVE-2026-22976)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix reference count leak in bpf_prog_test_run_xdp()\n\nsyzbot is reporting\n\n unregister_netdevice: waiting for sit0 to become free. Usage count = 2\n\nproblem. A debug printk() patch found that a refcount is obtained at\nxdp_convert_md_to_buff() from bpf_prog_test_run_xdp().\n\nAccording to commit ec94670fcb3b ("bpf: Support specifying ingress via\nxdp_md context in BPF_PROG_TEST_RUN"), the refcount obtained by\nxdp_convert_md_to_buff() will be released by xdp_convert_buff_to_md().\n\nTherefore, we can consider that the error handling path introduced by\ncommit 1c1949982524 ("bpf: introduce frags support to\nbpf_prog_test_run_xdp()") forgot to call xdp_convert_buff_to_md().(CVE-2026-22994)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a deadlock involving nfs_release_folio()\n\nWang Zhaolong reports a deadlock involving NFSv4.1 state recovery\nwaiting on kthreadd, which is attempting to reclaim memory by calling\nnfs_release_folio(). The latter cannot make progress due to state\nrecovery being needed.\n\nIt seems that the only safe thing to do here is to kick off a writeback\nof the folio, without waiting for completion, or else kicking off an\nasynchronous commit.(CVE-2026-23053)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen\n\ndvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the\nDVR device. dvb_ringbuffer_init() calls init_waitqueue_head(), which\nreinitializes the waitqueue list head to empty.\n\nSince dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the\nsame DVR device share it), this orphans any existing waitqueue entries\nfrom io_uring poll or epoll, leaving them with stale prev/next pointers\nwhile the list head is reset to {self, self}.\n\nThe waitqueue and spinlock in dvr_buffer are already properly\ninitialized once in dvb_dmxdev_init(). The open path only needs to\nreset the buffer data pointer, size, and read/write positions.\n\nReplace the dvb_ringbuffer_init() call in dvb_dvr_open() with direct\nassignment of data/size and a call to dvb_ringbuffer_reset(), which\nproperly resets pread, pwrite, and error with correct memory ordering\nwithout touching the waitqueue or spinlock.(CVE-2026-23253)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nregmap: maple: free entry on mas_store_gfp() failure\n\nregcache_maple_write() allocates a new block (\'entry\') to merge\nadjacent ranges and then stores it with mas_store_gfp().\nWhen mas_store_gfp() fails, the new \'entry\' remains allocated and\nis never freed, leaking memory.\n\nFree \'entry\' on the failure path; on success continue freeing the\nreplaced neighbor blocks (\'lower\', \'upper\').(CVE-2026-23260)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix unprivileged local user can do privileged policy management\n\nAn unprivileged local user can load, replace, and remove profiles by\nopening the apparmorfs interfaces, via a confused deputy attack, by\npassing the opened fd to a privileged process, and getting the\nprivileged process to write to the interface.\n\nThis does require a privileged target that can be manipulated to do\nthe write for the unprivileged process, but once such access is\nachieved full policy management is possible and all the possible\nimplications that implies: removing confinement, DoS of system or\ntarget applications by denying all execution, by-passing the\nunprivileged user namespace restriction, to exploiting kernel bugs for\na local privilege escalation.\n\nThe policy management interface can not have its permissions simply\nchanged from 0666 to 0600 because non-root processes need to be able\nto load policy to different policy namespaces.\n\nInstead ensure the task writing the interface has privileges that\nare a subset of the task that opened the interface. This is already\ndone via policy for confined processes, but unconfined can delegate\naccess to the opened fd, by-passing the usual policy check.(CVE-2026-23268)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix __perf_event_overflow() vs perf_remove_from_context() race\n\nMake sure that __perf_event_overflow() runs with IRQs disabled for all\npossible callchains. Specifically the software events can end up running\nit with only preemption disabled.\n\nThis opens up a race vs perf_event_exit_event() and friends that will go\nand free various things the overflow path expects to be present, like\nthe BPF program.(CVE-2026-23271)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: observe an RCU grace period in macvlan_common_newlink() error path\n\nvalis reported that a race condition still happens after my prior patch.\n\nmacvlan_common_newlink() might have made @dev visible before\ndetecting an error, and its caller will directly call free_netdev(dev).\n\nWe must respect an RCU period, either in macvlan or the core networking\nstack.\n\nAfter adding a temporary mdelay(1000) in macvlan_forward_source_one()\nto open the race window, valis repro was:\n\nip link add p1 type veth peer p2\nip link set address 00:00:00:00:00:20 dev p1\nip link set up dev p1\nip link set up dev p2\nip link add mv0 link p2 type macvlan mode source\n\n(ip link add invalid% link p2 type macvlan mode source macaddr add\n00:00:00:00:00:20 &) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4\nPING 1.2.3.4 (1.2.3.4): 56 data bytes\nRTNETLINK answers: Invalid argument\n\nBUG: KASAN: slab-use-after-free in macvlan_forward_source\n(drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nRead of size 8 at addr ffff888016bb89c0 by task e/175\n\nCPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n<IRQ>\ndump_stack_lvl (lib/dump_stack.c:123)\nprint_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nkasan_report (mm/kasan/report.c:597)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nmacvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\n? tasklet_init (kernel/softirq.c:983)\nmacvlan_handle_frame (drivers/net/macvlan.c:501)\n\nAllocated by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\n__kasan_kmalloc (mm/kasan/common.c:419)\n__kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657\nmm/slub.c:7140)\nalloc_netdev_mqs (net/core/dev.c:12012)\nrtnl_create_link (net/core/rtnetlink.c:3648)\nrtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)\n\nFreed by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\nkasan_save_free_info (mm/kasan/generic.c:587)\n__kasan_slab_free (mm/kasan/common.c:287)\nkfree (mm/slub.c:6674 mm/slub.c:6882)\nrtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)(CVE-2026-23273)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix recursive locking in __configfs_open_file()\n\nIn flush_write_buffer, &p->frag_sem is acquired and then the loaded store\nfunction is called, which, here, is target_core_item_dbroot_store(). This\nfunction called filp_open(), following which these functions were called\n(in reverse order), according to the call trace:\n\n down_read\n __configfs_open_file\n do_dentry_open\n vfs_open\n do_open\n path_openat\n do_filp_open\n file_open_name\n filp_open\n target_core_item_dbroot_store\n flush_write_buffer\n configfs_write_iter\n\ntarget_core_item_dbroot_store() tries to validate the new file path by\ntrying to open the file path provided to it; however, in this case, the bug\nreport shows:\n\ndb_root: not a directory: /sys/kernel/config/target/dbroot\n\nindicating that the same configfs file was tried to be opened, on which it\nis currently working on. Thus, it is trying to acquire frag_sem semaphore\nof the same file of which it already holds the semaphore obtained in\nflush_write_buffer(), leading to acquiring the semaphore in a nested manner\nand a possibility of recursive locking.\n\nFix this by modifying target_core_item_dbroot_store() to use kern_path()\ninstead of filp_open() to avoid opening the file using filesystem-specific\nfunction __configfs_open_file(), and further modifying it to make this fix\ncompatible.(CVE-2026-23292)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Fix refcount leak for tagset_refcnt\n\nThis leak will cause a hang when tearing down the SCSI host. For example,\niscsid hangs with the following call trace:\n\n[130120.652718] scsi_alloc_sdev: Allocation failure during SCSI scanning, some SCSI devices might not be configured\n\nPID: 2528 TASK: ffff9d0408974e00 CPU: 3 COMMAND: "iscsid"\n #0 [ffffb5b9c134b9e0] __schedule at ffffffff860657d4\n #1 [ffffb5b9c134ba28] schedule at ffffffff86065c6f\n #2 [ffffb5b9c134ba40] schedule_timeout at ffffffff86069fb0\n #3 [ffffb5b9c134bab0] __wait_for_common at ffffffff8606674f\n #4 [ffffb5b9c134bb10] scsi_remove_host at ffffffff85bfe84b\n #5 [ffffb5b9c134bb30] iscsi_sw_tcp_session_destroy at ffffffffc03031c4 [iscsi_tcp]\n #6 [ffffb5b9c134bb48] iscsi_if_recv_msg at ffffffffc0292692 [scsi_transport_iscsi]\n #7 [ffffb5b9c134bb98] iscsi_if_rx at ffffffffc02929c2 [scsi_transport_iscsi]\n #8 [ffffb5b9c134bbf0] netlink_unicast at ffffffff85e551d6\n #9 [ffffb5b9c134bc38] netlink_sendmsg at ffffffff85e554ef(CVE-2026-23296)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix preempt count leak in napi poll tracepoint\n\nUsing get_cpu() in the tracepoint assignment causes an obvious preempt\ncount leak because nothing invokes put_cpu() to undo it:\n\n softirq: huh, entered softirq 3 NET_RX with preempt_count 00000100, exited with 00000101?\n\nThis clearly has seen a lot of testing in the last 3+ years...\n\nUse smp_processor_id() instead.(CVE-2026-23313)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Return the correct value in vmw_translate_ptr functions\n\nBefore the referenced fixes these functions used a lookup function that\nreturned a pointer. This was changed to another lookup function that\nreturned an error code with the pointer becoming an out parameter.\n\nThe error path when the lookup failed was not changed to reflect this\nchange and the code continued to return the PTR_ERR of the now\nuninitialized pointer. This could cause the vmw_translate_ptr functions\nto return success when they actually failed causing further uninitialized\nand OOB accesses.(CVE-2026-23317)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim\n\nThe root cause of this bug is that when \'bpf_link_put\' reduces the\nrefcount of \'shim_link->link.link\' to zero, the resource is considered\nreleased but may still be referenced via \'tr->progs_hlist\' in\n\'cgroup_shim_find\'. The actual cleanup of \'tr->progs_hlist\' in\n\'bpf_shim_tramp_link_release\' is deferred. During this window, another\nprocess can cause a use-after-free via \'bpf_trampoline_link_cgroup_shim\'.\n\nBased on Martin KaFai Lau\'s suggestions, I have created a simple patch.\n\nTo fix this:\n Add an atomic non-zero check in \'bpf_trampoline_link_cgroup_shim\'.\n Only increment the refcount if it is not already zero.\n\nTesting:\n I verified the fix by adding a delay in\n \'bpf_shim_tramp_link_release\' to make the bug easier to trigger:\n\nstatic void bpf_shim_tramp_link_release(struct bpf_link *link)\n{\n\t/* ... */\n\tif (!shim_link->trampoline)\n\t\treturn;\n\n+\tmsleep(100);\n\tWARN_ON_ONCE(bpf_trampoline_unlink_prog(&shim_link->link,\n\t\tshim_link->trampoline, NULL));\n\tbpf_trampoline_put(shim_link->trampoline);\n}\n\nBefore the patch, running a PoC easily reproduced the crash(almost 100%)\nwith a call trace similar to KaiyanM\'s report.\nAfter the patch, the bug no longer occurs even after millions of\niterations.(CVE-2026-23319)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nx86/efi: defer freeing of boot services memory\n\nefi_free_boot_services() frees memory occupied by EFI_BOOT_SERVICES_CODE\nand EFI_BOOT_SERVICES_DATA using memblock_free_late().\n\nThere are two issue with that: memblock_free_late() should be used for\nmemory allocated with memblock_alloc() while the memory reserved with\nmemblock_reserve() should be freed with free_reserved_area().\n\nMore acutely, with CONFIG_DEFERRED_STRUCT_PAGE_INIT=y\nefi_free_boot_services() is called before deferred initialization of the\nmemory map is complete.\n\nBenjamin Herrenschmidt reports that this causes a leak of ~140MB of\nRAM on EC2 t3a.nano instances which only have 512MB or RAM.\n\nIf the freed memory resides in the areas that memory map for them is\nstill uninitialized, they won\'t be actually freed because\nmemblock_free_late() calls memblock_free_pages() and the latter skips\nuninitialized pages.\n\nUsing free_reserved_area() at this point is also problematic because\n__free_page() accesses the buddy of the freed page and that again might\nend up in uninitialized part of the memory map.\n\nDelaying the entire efi_free_boot_services() could be problematic\nbecause in addition to freeing boot services memory it updates\nefi.memmap without any synchronization and that\'s undesirable late in\nboot when there is concurrency.\n\nMore robust approach is to only defer freeing of the EFI boot services\nmemory.\n\nSplit efi_free_boot_services() in two. First efi_unmap_boot_services()\ncollects ranges that should be freed into an array then\nefi_free_boot_services() later frees them after deferred init is complete.(CVE-2026-23352)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stack-out-of-bounds write in devmap\n\nget_upper_ifindexes() iterates over all upper devices and writes their\nindices into an array without checking bounds.\n\nAlso the callers assume that the max number of upper devices is\nMAX_NEST_DEV and allocate excluded_devices[1+MAX_NEST_DEV] on the stack,\nbut that assumption is not correct and the number of upper devices could\nbe larger than MAX_NEST_DEV (e.g., many macvlans), causing a\nstack-out-of-bounds write.\n\nAdd a max parameter to get_upper_ifindexes() to avoid the issue.\nWhen there are too many upper devices, return -EOVERFLOW and abort the\nredirect.\n\nTo reproduce, create more than MAX_NEST_DEV(8) macvlans on a device with\nan XDP program attached using BPF_F_BROADCAST | BPF_F_EXCLUDE_INGRESS.\nThen send a packet to the device to trigger the XDP redirect path.(CVE-2026-23359)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix admin queue leak on controller reset\n\nWhen nvme_alloc_admin_tag_set() is called during a controller reset,\na previous admin queue may still exist. Release it properly before\nallocating a new one to avoid orphaning the old queue.\n\nThis fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix\nadmin request_queue lifetime").(CVE-2026-23360)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nblktrace: fix __this_cpu_read/write in preemptible context\n\ntracing_record_cmdline() internally uses __this_cpu_read() and\n__this_cpu_write() on the per-CPU variable trace_cmdline_save, and\ntrace_save_cmdline() explicitly asserts preemption is disabled via\nlockdep_assert_preemption_disabled(). These operations are only safe\nwhen preemption is off, as they were designed to be called from the\nscheduler context (probe_wakeup_sched_switch() / probe_wakeup()).\n\n__blk_add_trace() was calling tracing_record_cmdline(current) early in\nthe blk_tracer path, before ring buffer reservation, from process\ncontext where preemption is fully enabled. This triggers the following\nusing blktests/blktrace/002:\n\nblktrace/002 (blktrace ftrace corruption with sysfs trace) [failed]\n runtime 0.367s ... 0.437s\n something found in dmesg:\n [ 81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33\n [ 81.239580] null_blk: disk nullb1 created\n [ 81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516\n [ 81.362842] caller is tracing_record_cmdline+0x10/0x40\n [ 81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G N 7.0.0-rc1lblk+ #84 PREEMPT(full)\n [ 81.362877] Tainted: [N]=TEST\n [ 81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n [ 81.362881] Call Trace:\n [ 81.362884] <TASK>\n [ 81.362886] dump_stack_lvl+0x8d/0xb0\n ...\n (See \'/mnt/sda/blktests/results/nodev/blktrace/002.dmesg\' for the entire message)\n\n[ 81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33\n[ 81.239580] null_blk: disk nullb1 created\n[ 81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516\n[ 81.362842] caller is tracing_record_cmdline+0x10/0x40\n[ 81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G N 7.0.0-rc1lblk+ #84 PREEMPT(full)\n[ 81.362877] Tainted: [N]=TEST\n[ 81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 81.362881] Call Trace:\n[ 81.362884] <TASK>\n[ 81.362886] dump_stack_lvl+0x8d/0xb0\n[ 81.362895] check_preemption_disabled+0xce/0xe0\n[ 81.362902] tracing_record_cmdline+0x10/0x40\n[ 81.362923] __blk_add_trace+0x307/0x5d0\n[ 81.362934] ? lock_acquire+0xe0/0x300\n[ 81.362940] ? iov_iter_extract_pages+0x101/0xa30\n[ 81.362959] blk_add_trace_bio+0x106/0x1e0\n[ 81.362968] submit_bio_noacct_nocheck+0x24b/0x3a0\n[ 81.362979] ? lockdep_init_map_type+0x58/0x260\n[ 81.362988] submit_bio_wait+0x56/0x90\n[ 81.363009] __blkdev_direct_IO_simple+0x16c/0x250\n[ 81.363026] ? __pfx_submit_bio_wait_endio+0x10/0x10\n[ 81.363038] ? rcu_read_lock_any_held+0x73/0xa0\n[ 81.363051] blkdev_read_iter+0xc1/0x140\n[ 81.363059] vfs_read+0x20b/0x330\n[ 81.363083] ksys_read+0x67/0xe0\n[ 81.363090] do_syscall_64+0xbf/0xf00\n[ 81.363102] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 81.363106] RIP: 0033:0x7f281906029d\n[ 81.363111] Code: 31 c0 e9 c6 fe ff ff 50 48 8d 3d 66 63 0a 00 e8 59 ff 01 00 66 0f 1f 84 00 00 00 00 00 80 3d 41 33 0e 00 00 74 17 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 5b c3 66 2e 0f 1f 84 00 00 00 00 00 48 83 ec\n[ 81.363113] RSP: 002b:00007ffca127dd48 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n[ 81.363120] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f281906029d\n[ 81.363122] RDX: 0000000000001000 RSI: 0000559f8bfae000 RDI: 0000000000000000\n[ 81.363123] RBP: 0000000000001000 R08: 0000002863a10a81 R09: 00007f281915f000\n[ 81.363124] R10: 00007f2818f77b60 R11: 0000000000000246 R12: 0000559f8bfae000\n[ 81.363126] R13: 0000000000000000 R14: 0000000000000000 R15: 000000000000000a\n[ 81.363142] </TASK>\n\nThe same BUG fires from blk_add_trace_plug(), blk_add_trace_unplug(),\nand blk_add_trace_rq() paths as well.\n\nThe purpose of tracin\n---truncated---(CVE-2026-23374)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing\n\nstruct bpf_plt contains a u64 target field. Currently, the BPF JIT\nallocator requests an alignment of 4 bytes (sizeof(u32)) for the JIT\nbuffer.\n\nBecause the base address of the JIT buffer can be 4-byte aligned (e.g.,\nending in 0x4 or 0xc), the relative padding logic in build_plt() fails\nto ensure that target lands on an 8-byte boundary.\n\nThis leads to two issues:\n1. UBSAN reports misaligned-access warnings when dereferencing the\n structure.\n2. More critically, target is updated concurrently via WRITE_ONCE() in\n bpf_arch_text_poke() while the JIT\'d code executes ldr. On arm64,\n 64-bit loads/stores are only guaranteed to be single-copy atomic if\n they are 64-bit aligned. A misaligned target risks a torn read,\n causing the JIT to jump to a corrupted address.\n\nFix this by increasing the allocation alignment requirement to 8 bytes\n(sizeof(u64)) in bpf_jit_binary_pack_alloc(). This anchors the base of\nthe JIT buffer to an 8-byte boundary, allowing the relative padding math\nin build_plt() to correctly align the target field.(CVE-2026-23383)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: check metadata block offset is within range\n\nSyzkaller reports a "general protection fault in squashfs_copy_data"\n\nThis is ultimately caused by a corrupted index look-up table, which\nproduces a negative metadata block offset.\n\nThis is subsequently passed to squashfs_copy_data (via\nsquashfs_read_metadata) where the negative offset causes an out of bounds\naccess.\n\nThe fix is to check that the offset is within range in\nsquashfs_read_metadata. This will trap this and other cases.(CVE-2026-23388)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.(CVE-2026-31447)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report\'s feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn\'t, omit reporting the raw event and\nreturn early.(CVE-2026-43047)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <(CVE-2026-43048)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nxfs: close crash window in attr dabtree inactivation\n\nWhen inactivating an inode with node-format extended attributes,\nxfs_attr3_node_inactive() invalidates all child leaf/node blocks via\nxfs_trans_binval(), but intentionally does not remove the corresponding\nentries from their parent node blocks. The implicit assumption is that\nxfs_attr_inactive() will truncate the entire attr fork to zero extents\nafterwards, so log recovery will never reach the root node and follow\nthose stale pointers.\n\nHowever, if a log shutdown occurs after the leaf/node block cancellations\ncommit but before the attr bmap truncation commits, this assumption\nbreaks. Recovery replays the attr bmap intact (the inode still has\nattr fork extents), but suppresses replay of all cancelled leaf/node\nblocks, maybe leaving them as stale data on disk. On the next mount,\nxlog_recover_process_iunlinks() retries inactivation and attempts to\nread the root node via the attr bmap. If the root node was not replayed,\nreading the unreplayed root block triggers a metadata verification\nfailure immediately; if it was replayed, following its child pointers\nto unreplayed child blocks triggers the same failure:\n\n XFS (pmem0): Metadata corruption detected at\n xfs_da3_node_read_verify+0x53/0x220, xfs_da3_node block 0x78\n XFS (pmem0): Unmount and run xfs_repair\n XFS (pmem0): First 128 bytes of corrupted metadata buffer:\n 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n XFS (pmem0): metadata I/O error in "xfs_da_read_buf+0x104/0x190" at daddr 0x78 len 8 error 117\n\nFix this in two places:\n\nIn xfs_attr3_node_inactive(), after calling xfs_trans_binval() on a\nchild block, immediately remove the entry that references it from the\nparent node in the same transaction. This eliminates the window where\nthe parent holds a pointer to a cancelled block. Once all children are\nremoved, the now-empty root node is converted to a leaf block within the\nsame transaction. This node-to-leaf conversion is necessary for crash\nsafety. If the system shutdown after the empty node is written to the\nlog but before the second-phase bmap truncation commits, log recovery\nwill attempt to verify the root block on disk. xfs_da3_node_verify()\ndoes not permit a node block with count == 0; such a block will fail\nverification and trigger a metadata corruption shutdown. on the other\nhand, leaf blocks are allowed to have this transient state.\n\nIn xfs_attr_inactive(), split the attr fork truncation into two explicit\nphases. First, truncate all extents beyond the root block (the child\nextents whose parent references have already been removed above).\nSecond, invalidate the root block and truncate the attr bmap to zero in\na single transaction. The two operations in the second phase must be\natomic: as long as the attr bmap has any non-zero length, recovery can\nfollow it to the root block, so the root block invalidation must commit\ntogether with the bmap-to-zero truncation.(CVE-2026-43053)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRevert "PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV"\n\nThis reverts commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking\nwhen enabling/disabling SR-IOV"), which causes a deadlock by recursively\ntaking pci_rescan_remove_lock when sriov_del_vfs() is called as part of\npci_stop_and_remove_bus_device(). For example with the following sequence\nof commands:\n\n $ echo <NUM> > /sys/bus/pci/devices/<pf>/sriov_numvfs\n $ echo 1 > /sys/bus/pci/devices/<pf>/remove\n\nA trimmed trace of the deadlock on a mlx5 device is as below:\n\n zsh/5715 is trying to acquire lock:\n 000002597926ef50 (pci_rescan_remove_lock){+.+.}-{3:3}, at: sriov_disable+0x34/0x140\n\n but task is already holding lock:\n 000002597926ef50 (pci_rescan_remove_lock){+.+.}-{3:3}, at: pci_stop_and_remove_bus_device_locked+0x24/0x80\n ...\n Call Trace:\n [<00000259778c4f90>] dump_stack_lvl+0xc0/0x110\n [<00000259779c844e>] print_deadlock_bug+0x31e/0x330\n [<00000259779c1908>] __lock_acquire+0x16c8/0x32f0\n [<00000259779bffac>] lock_acquire+0x14c/0x350\n [<00000259789643a6>] __mutex_lock_common+0xe6/0x1520\n [<000002597896413c>] mutex_lock_nested+0x3c/0x50\n [<00000259784a07e4>] sriov_disable+0x34/0x140\n [<00000258f7d6dd80>] mlx5_sriov_disable+0x50/0x80 [mlx5_core]\n [<00000258f7d5745e>] remove_one+0x5e/0xf0 [mlx5_core]\n [<00000259784857fc>] pci_device_remove+0x3c/0xa0\n [<000002597851012e>] device_release_driver_internal+0x18e/0x280\n [<000002597847ae22>] pci_stop_bus_device+0x82/0xa0\n [<000002597847afce>] pci_stop_and_remove_bus_device_locked+0x5e/0x80\n [<00000259784972c2>] remove_store+0x72/0x90\n [<0000025977e6661a>] kernfs_fop_write_iter+0x15a/0x200\n [<0000025977d7241c>] vfs_write+0x24c/0x300\n [<0000025977d72696>] ksys_write+0x86/0x110\n [<000002597895b61c>] __do_syscall+0x14c/0x400\n [<000002597896e0ee>] system_call+0x6e/0x90\n\nThis alone is not a complete fix as it restores the issue the cited commit\ntried to solve. A new fix will be provided as a follow on.(CVE-2026-43147)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\narm64: Add support for TSV110 Spectre-BHB mitigation\n\nThe TSV110 processor is vulnerable to the Spectre-BHB (Branch History\nBuffer) attack, which can be exploited to leak information through\nbranch prediction side channels. This commit adds the MIDR of TSV110\nto the list for software mitigation.(CVE-2026-43261)\n\nIn the Linux kernel, the kexec_load_purgatory() function derives image->start by locating e_entry inside an SHF_EXECINSTR section. If the purgatory object contains multiple executable sections with overlapping sh_addr, the entrypoint check can match more than once and trigger a WARN. Derive the entry section from the purgatory_start symbol when present and compute image->start from its final placement. Keep the existing e_entry fallback for purgatories that do not expose the symbol.(CVE-2026-43289)\n\nIn the Linux kernel, there is a potential out-of-bounds access vulnerability in the ceph_handle_auth_reply() function of the libceph component. When processing messages of type CEPH_MSG_AUTH_REPLY, the value of the payload_len field is stored in a variable of type int. A value greater than INT_MAX leads to integer overflow and is interpreted as a negative value, which causes the pointer address to be decremented and subsequently accessed because ceph_decode_need() only checks that the memory access does not exceed the end address of the allocation. The vulnerability is fixed by changing the data type of payload_len to u32 and introducing additional sanity checks.(CVE-2026-43407)\n\nIn the Linux kernel, when an alias is found through d_splice_alias in the nfs3_proc_create function, if the alias happens to be a directory dentry, the system does not return any error but simply forgets about this alias, leaving the original dentry to be added as negative. This later causes a system crash in nfs_atomic_open_v23/finish_open since a negative dentry is supplied to do_dentry_open. This issue was observed running lustre-racer, where directories and files are created/removed concurrently with the same name and O_EXCL is not used to open files.(CVE-2026-43470)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-20.03-LTS-SP4/openEuler-24.03-LTS-SP1/openEuler-22.03-LTS-SP3/openEuler-24.03-LTS-SP2.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'kernel', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for kernel is now available for openEuler-24.03-LTS-SP1', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2418', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:06+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:06+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:06+08:00', 'initial_release_date': '2026-05-22T21:22:06+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'summary': 'openEuler-SA-2026-2418', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56611&packageName=kernel', 'summary': 'CVE-2024-56611', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-56760&packageName=kernel', 'summary': 'CVE-2024-56760', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21908&packageName=kernel', 'summary': 'CVE-2025-21908', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21931&packageName=kernel', 'summary': 'CVE-2025-21931', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21970&packageName=kernel', 'summary': 'CVE-2025-21970', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21971&packageName=kernel', 'summary': 'CVE-2025-21971', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21980&packageName=kernel', 'summary': 'CVE-2025-21980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21981&packageName=kernel', 'summary': 'CVE-2025-21981', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21986&packageName=kernel', 'summary': 'CVE-2025-21986', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-21995&packageName=kernel', 'summary': 'CVE-2025-21995', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22001&packageName=kernel', 'summary': 'CVE-2025-22001', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22009&packageName=kernel', 'summary': 'CVE-2025-22009', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22071&packageName=kernel', 'summary': 'CVE-2025-22071', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-22077&packageName=kernel', 'summary': 'CVE-2025-22077', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23138&packageName=kernel', 'summary': 'CVE-2025-23138', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-23157&packageName=kernel', 'summary': 'CVE-2025-23157', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37740&packageName=kernel', 'summary': 'CVE-2025-37740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37748&packageName=kernel', 'summary': 'CVE-2025-37748', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37766&packageName=kernel', 'summary': 'CVE-2025-37766', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37768&packageName=kernel', 'summary': 'CVE-2025-37768', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37770&packageName=kernel', 'summary': 'CVE-2025-37770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37771&packageName=kernel', 'summary': 'CVE-2025-37771', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37778&packageName=kernel', 'summary': 'CVE-2025-37778', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37793&packageName=kernel', 'summary': 'CVE-2025-37793', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37805&packageName=kernel', 'summary': 'CVE-2025-37805', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37815&packageName=kernel', 'summary': 'CVE-2025-37815', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37831&packageName=kernel', 'summary': 'CVE-2025-37831', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37844&packageName=kernel', 'summary': 'CVE-2025-37844', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37853&packageName=kernel', 'summary': 'CVE-2025-37853', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37881&packageName=kernel', 'summary': 'CVE-2025-37881', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37889&packageName=kernel', 'summary': 'CVE-2025-37889', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37905&packageName=kernel', 'summary': 'CVE-2025-37905', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37918&packageName=kernel', 'summary': 'CVE-2025-37918', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37947&packageName=kernel', 'summary': 'CVE-2025-37947', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-37967&packageName=kernel', 'summary': 'CVE-2025-37967', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38014&packageName=kernel', 'summary': 'CVE-2025-38014', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38037&packageName=kernel', 'summary': 'CVE-2025-38037', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38043&packageName=kernel', 'summary': 'CVE-2025-38043', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38051&packageName=kernel', 'summary': 'CVE-2025-38051', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38064&packageName=kernel', 'summary': 'CVE-2025-38064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38113&packageName=kernel', 'summary': 'CVE-2025-38113', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38122&packageName=kernel', 'summary': 'CVE-2025-38122', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38123&packageName=kernel', 'summary': 'CVE-2025-38123', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38131&packageName=kernel', 'summary': 'CVE-2025-38131', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38148&packageName=kernel', 'summary': 'CVE-2025-38148', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38161&packageName=kernel', 'summary': 'CVE-2025-38161', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38183&packageName=kernel', 'summary': 'CVE-2025-38183', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38193&packageName=kernel', 'summary': 'CVE-2025-38193', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38194&packageName=kernel', 'summary': 'CVE-2025-38194', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38241&packageName=kernel', 'summary': 'CVE-2025-38241', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38255&packageName=kernel', 'summary': 'CVE-2025-38255', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38304&packageName=kernel', 'summary': 'CVE-2025-38304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38307&packageName=kernel', 'summary': 'CVE-2025-38307', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38321&packageName=kernel', 'summary': 'CVE-2025-38321', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38344&packageName=kernel', 'summary': 'CVE-2025-38344', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38364&packageName=kernel', 'summary': 'CVE-2025-38364', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38461&packageName=kernel', 'summary': 'CVE-2025-38461', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38462&packageName=kernel', 'summary': 'CVE-2025-38462', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38488&packageName=kernel', 'summary': 'CVE-2025-38488', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38499&packageName=kernel', 'summary': 'CVE-2025-38499', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38552&packageName=kernel', 'summary': 'CVE-2025-38552', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38575&packageName=kernel', 'summary': 'CVE-2025-38575', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38609&packageName=kernel', 'summary': 'CVE-2025-38609', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38721&packageName=kernel', 'summary': 'CVE-2025-38721', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39676&packageName=kernel', 'summary': 'CVE-2025-39676', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39682&packageName=kernel', 'summary': 'CVE-2025-39682', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39702&packageName=kernel', 'summary': 'CVE-2025-39702', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39728&packageName=kernel', 'summary': 'CVE-2025-39728', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39756&packageName=kernel', 'summary': 'CVE-2025-39756', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39770&packageName=kernel', 'summary': 'CVE-2025-39770', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39812&packageName=kernel', 'summary': 'CVE-2025-39812', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39841&packageName=kernel', 'summary': 'CVE-2025-39841', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39894&packageName=kernel', 'summary': 'CVE-2025-39894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39937&packageName=kernel', 'summary': 'CVE-2025-39937', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39955&packageName=kernel', 'summary': 'CVE-2025-39955', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-39980&packageName=kernel', 'summary': 'CVE-2025-39980', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40018&packageName=kernel', 'summary': 'CVE-2025-40018', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40062&packageName=kernel', 'summary': 'CVE-2025-40062', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40078&packageName=kernel', 'summary': 'CVE-2025-40078', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40136&packageName=kernel', 'summary': 'CVE-2025-40136', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40240&packageName=kernel', 'summary': 'CVE-2025-40240', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40254&packageName=kernel', 'summary': 'CVE-2025-40254', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40280&packageName=kernel', 'summary': 'CVE-2025-40280', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40281&packageName=kernel', 'summary': 'CVE-2025-40281', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40331&packageName=kernel', 'summary': 'CVE-2025-40331', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68283&packageName=kernel', 'summary': 'CVE-2025-68283', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68284&packageName=kernel', 'summary': 'CVE-2025-68284', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68285&packageName=kernel', 'summary': 'CVE-2025-68285', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68304&packageName=kernel', 'summary': 'CVE-2025-68304', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68740&packageName=kernel', 'summary': 'CVE-2025-68740', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68742&packageName=kernel', 'summary': 'CVE-2025-68742', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68795&packageName=kernel', 'summary': 'CVE-2025-68795', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-68820&packageName=kernel', 'summary': 'CVE-2025-68820', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-71064&packageName=kernel', 'summary': 'CVE-2025-71064', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22976&packageName=kernel', 'summary': 'CVE-2026-22976', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-22994&packageName=kernel', 'summary': 'CVE-2026-22994', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23053&packageName=kernel', 'summary': 'CVE-2026-23053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23253&packageName=kernel', 'summary': 'CVE-2026-23253', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23260&packageName=kernel', 'summary': 'CVE-2026-23260', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23268&packageName=kernel', 'summary': 'CVE-2026-23268', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23271&packageName=kernel', 'summary': 'CVE-2026-23271', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23273&packageName=kernel', 'summary': 'CVE-2026-23273', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23292&packageName=kernel', 'summary': 'CVE-2026-23292', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23296&packageName=kernel', 'summary': 'CVE-2026-23296', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23313&packageName=kernel', 'summary': 'CVE-2026-23313', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23317&packageName=kernel', 'summary': 'CVE-2026-23317', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23319&packageName=kernel', 'summary': 'CVE-2026-23319', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23352&packageName=kernel', 'summary': 'CVE-2026-23352', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23359&packageName=kernel', 'summary': 'CVE-2026-23359', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23360&packageName=kernel', 'summary': 'CVE-2026-23360', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23374&packageName=kernel', 'summary': 'CVE-2026-23374', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23383&packageName=kernel', 'summary': 'CVE-2026-23383', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-23388&packageName=kernel', 'summary': 'CVE-2026-23388', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43053&packageName=kernel', 'summary': 'CVE-2026-43053', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43147&packageName=kernel', 'summary': 'CVE-2026-43147', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43261&packageName=kernel', 'summary': 'CVE-2026-43261', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43289&packageName=kernel', 'summary': 'CVE-2026-43289', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43407&packageName=kernel', 'summary': 'CVE-2026-43407', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43470&packageName=kernel', 'summary': 'CVE-2026-43470', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56611', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2024-56760', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21908', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21931', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21970', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21971', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21981', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21986', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-21995', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22001', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22009', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22071', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-22077', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23138', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-23157', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37748', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37766', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37768', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37771', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37778', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37793', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37805', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37815', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37831', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37844', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37853', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37881', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37889', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37905', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37947', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-37967', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38014', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38037', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38043', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38051', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38113', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38122', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38123', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38131', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38148', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38161', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38183', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38193', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38194', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38241', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38255', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38307', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38321', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38344', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38364', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38461', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38462', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38488', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38499', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38552', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38575', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38609', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-38721', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39676', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39682', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39702', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39728', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39756', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39770', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39812', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39841', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39937', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39955', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-39980', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40018', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40062', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40078', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40136', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40240', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40254', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40280', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40281', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40331', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68283', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68284', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68285', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68304', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68740', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68742', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68795', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-68820', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-71064', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22976', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-22994', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23253', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23260', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23268', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23271', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23273', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23292', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23296', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23313', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23317', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23319', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23352', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23359', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23360', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23374', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23383', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-23388', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43053', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43147', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43289', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43407', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43470', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2418.json', 'summary': 'openEuler-SA-2026-2418 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP1', 'product': {'name': 'openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product': {'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product': {'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src.rpm', 'product': {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src.rpm', 'product_id': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP1'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:perf-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64'}, 'product_reference': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:perf-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64'}, 'product_reference': 'python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1', 'product_id': 'openEuler-24.03-LTS-SP1:kernel-6.6.0-145.1.12.150.oe2403sp1.src'}, 'product_reference': 'kernel-6.6.0-145.1.12.150.oe2403sp1.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP1'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-56611', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MMWe currently assume that there is at least one VMA in a MM, which isn ttrue.So we might end up having find_vma() return NULL, to then de-referenceNULL. So properly handle find_vma() returning NULL.This fixes the report:Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTIKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194Code: ...RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8FS: 00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400Call Trace: <TASK> kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709 __do_sys_migrate_pages mm/mempolicy.c:1727 [inline] __se_sys_migrate_pages mm/mempolicy.c:1723 [inline] __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f[akpm@linux-foundation.org: add unlikely()]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56611', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP1:bpftool-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-headers-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-source-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-tools-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:perf-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:python3-perf-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.aarch64', 'openEuler-24.03-LTS-SP1:bpftool-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:bpftool-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-debugsource-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-headers-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-source-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-tools-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-tools-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-tools-devel-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:perf-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:python3-perf-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:python3-perf-debuginfo-6.6.0-145.1.12.150.oe2403sp1.x86_64', 'openEuler-24.03-LTS-SP1:kernel-6.6.0-145.1.12.150.oe2403sp1.src']}}, {'cve': 'CVE-2024-56760', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/MSI: Handle lack of irqdomain gracefully\n\nAlexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a\nRISCV platform which does not provide PCI/MSI support:\n\n WARNING: CPU: 1 PID: 1 at drivers/pci/msi/msi.h:121 pci_msi_setup_msi_irqs+0x2c/0x32\n __pci_enable_msix_range+0x30c/0x596\n pci_msi_setup_msi_irqs+0x2c/0x32\n pci_alloc_irq_vectors_affinity+0xb8/0xe2\n\nRISCV uses hierarchical interrupt domains and correctly does not implement\nthe legacy fallback. The warning triggers from the legacy fallback stub.\n\nThat warning is bogus as the PCI/MSI layer knows whether a PCI/MSI parent\ndomain is associated with the device or not. There is a check for MSI-X,\nwhich has a legacy assumption. But that legacy fallback assumption is only\nvalid when legacy support is enabled, but otherwise the check should simply\nreturn -ENOTSUPP.\n\nLoongarch tripped over the same problem and blindly enabled legacy support\nwithout implementing the legacy fallbacks. There are weak implementations\nwhich return an error, so the problem was papered over.\n\nCorrect pci_msi_domain_supports() to evaluate the legacy mode and add\nthe missing supported check into the MSI enable path to complete it.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-56760', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21908', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix nfs_release_folio() to not deadlock via kcompactd writeback\n\nAdd PF_KCOMPACTD flag and current_is_kcompactd() helper to check for it so\nnfs_release_folio() can skip calling nfs_wb_folio() from kcompactd.\n\nOtherwise NFS can deadlock waiting for kcompactd enduced writeback which\nrecurses back to NFS (which triggers writeback to NFSD via NFS loopback\nmount on the same host, NFSD blocks waiting for XFS\'s call to\n__filemap_get_folio):\n\n6070.550357] INFO: task kcompactd0:58 blocked for more than 4435 seconds.\n\n{---\n[58] "kcompactd0"\n[<0>] folio_wait_bit+0xe8/0x200\n[<0>] folio_wait_writeback+0x2b/0x80\n[<0>] nfs_wb_folio+0x80/0x1b0 [nfs]\n[<0>] nfs_release_folio+0x68/0x130 [nfs]\n[<0>] split_huge_page_to_list_to_order+0x362/0x840\n[<0>] migrate_pages_batch+0x43d/0xb90\n[<0>] migrate_pages_sync+0x9a/0x240\n[<0>] migrate_pages+0x93c/0x9f0\n[<0>] compact_zone+0x8e2/0x1030\n[<0>] compact_node+0xdb/0x120\n[<0>] kcompactd+0x121/0x2e0\n[<0>] kthread+0xcf/0x100\n[<0>] ret_from_fork+0x31/0x40\n[<0>] ret_from_fork_asm+0x1a/0x30\n---}\n\n[', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21908', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21931', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwpoison, memory_hotplug: lock folio before unmap hwpoisoned folio\n\nCommit b15c87263a69 ("hwpoison, memory_hotplug: allow hwpoisoned pages to\nbe offlined) add page poison checks in do_migrate_range in order to make\noffline hwpoisoned page possible by introducing isolate_lru_page and\ntry_to_unmap for hwpoisoned page. However folio lock must be held before\ncalling try_to_unmap. Add it to fix this problem.\n\nWarning will be produced if folio is not locked during unmap:\n\n ------------[ cut here ]------------\n kernel BUG at ./include/linux/swapops.h:400!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 4 UID: 0 PID: 411 Comm: bash Tainted: G W 6.13.0-rc1-00016-g3c434c7ee82a-dirty #41\n Tainted: [W]=WARN\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : try_to_unmap_one+0xb08/0xd3c\n lr : try_to_unmap_one+0x3dc/0xd3c\n Call trace:\n try_to_unmap_one+0xb08/0xd3c (P)\n try_to_unmap_one+0x3dc/0xd3c (L)\n rmap_walk_anon+0xdc/0x1f8\n rmap_walk+0x3c/0x58\n try_to_unmap+0x88/0x90\n unmap_poisoned_folio+0x30/0xa8\n do_migrate_range+0x4a0/0x568\n offline_pages+0x5a4/0x670\n memory_block_action+0x17c/0x374\n memory_subsys_offline+0x3c/0x78\n device_offline+0xa4/0xd0\n state_store+0x8c/0xf0\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x44/0x54\n kernfs_fop_write_iter+0x118/0x1a8\n vfs_write+0x3a8/0x4bc\n ksys_write+0x6c/0xf8\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xd0\n el0t_64_sync_handler+0xc8/0xcc\n el0t_64_sync+0x198/0x19c\n Code: f9407be0 b5fff320 d4210000 17ffff97 (d4210000)\n ---[ end trace 0000000000000000 ]---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21931', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21970', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Bridge, fix the crash caused by LAG state check\n\nWhen removing LAG device from bridge, NETDEV_CHANGEUPPER event is\ntriggered. Driver finds the lower devices (PFs) to flush all the\noffloaded entries. And mlx5_lag_is_shared_fdb is checked, it returns\nfalse if one of PF is unloaded. In such case,\nmlx5_esw_bridge_lag_rep_get() and its caller return NULL, instead of\nthe alive PF, and the flush is skipped.\n\nBesides, the bridge fdb entry\'s lastuse is updated in mlx5 bridge\nevent handler. But this SWITCHDEV_FDB_ADD_TO_BRIDGE event can be\nignored in this case because the upper interface for bond is deleted,\nand the entry will never be aged because lastuse is never updated.\n\nTo make things worse, as the entry is alive, mlx5 bridge workqueue\nkeeps sending that event, which is then handled by kernel bridge\nnotifier. It causes the following crash when accessing the passed bond\nnetdev which is already destroyed.\n\nTo fix this issue, remove such checks. LAG state is already checked in\ncommit 15f8f168952f ("net/mlx5: Bridge, verify LAG state when adding\nbond to bridge"), driver still need to skip offload if LAG becomes\ninvalid state after initialization.\n\n Oops: stack segment: 0000 [#1] SMP\n CPU: 3 UID: 0 PID: 23695 Comm: kworker/u40:3 Tainted: G OE 6.11.0_mlnx #1\n Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5_bridge_wq mlx5_esw_bridge_update_work [mlx5_core]\n RIP: 0010:br_switchdev_event+0x2c/0x110 [bridge]\n Code: 44 00 00 48 8b 02 48 f7 00 00 02 00 00 74 69 41 54 55 53 48 83 ec 08 48 8b a8 08 01 00 00 48 85 ed 74 4a 48 83 fe 02 48 89 d3 <4c> 8b 65 00 74 23 76 49 48 83 fe 05 74 7e 48 83 fe 06 75 2f 0f b7\n RSP: 0018:ffffc900092cfda0 EFLAGS: 00010297\n RAX: ffff888123bfe000 RBX: ffffc900092cfe08 RCX: 00000000ffffffff\n RDX: ffffc900092cfe08 RSI: 0000000000000001 RDI: ffffffffa0c585f0\n RBP: 6669746f6e690a30 R08: 0000000000000000 R09: ffff888123ae92c8\n R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888123ae9c60\n R13: 0000000000000001 R14: ffffc900092cfe08 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff88852c980000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f15914c8734 CR3: 0000000002830005 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n <TASK>\n ? __die_body+0x1a/0x60\n ? die+0x38/0x60\n ? do_trap+0x10b/0x120\n ? do_error_trap+0x64/0xa0\n ? exc_stack_segment+0x33/0x50\n ? asm_exc_stack_segment+0x22/0x30\n ? br_switchdev_event+0x2c/0x110 [bridge]\n ? sched_balance_newidle.isra.149+0x248/0x390\n notifier_call_chain+0x4b/0xa0\n atomic_notifier_call_chain+0x16/0x20\n mlx5_esw_bridge_update+0xec/0x170 [mlx5_core]\n mlx5_esw_bridge_update_work+0x19/0x40 [mlx5_core]\n process_scheduled_works+0x81/0x390\n worker_thread+0x106/0x250\n ? bh_worker+0x110/0x110\n kthread+0xb7/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n </TASK>', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21970', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21971', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: Prevent creation of classes with TC_H_ROOT\n\nThe function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination\ncondition when traversing up the qdisc tree to update parent backlog\ncounters. However, if a class is created with classid TC_H_ROOT, the\ntraversal terminates prematurely at this class instead of reaching the\nactual root qdisc, causing parent statistics to be incorrectly maintained.\nIn case of DRR, this could lead to a crash as reported by Mingi Cho.\n\nPrevent the creation of any Qdisc class with classid TC_H_ROOT\n(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21971', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21980', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched: address a potential NULL pointer dereference in the GRED scheduler.\n\nIf kzalloc in gred_init returns a NULL pointer, the code follows the\nerror handling path, invoking gred_destroy. This, in turn, calls\ngred_offload, where memset could receive a NULL pointer as input,\npotentially leading to a kernel crash.\n\nWhen table->opt is NULL in gred_init(), gred_change_table_def()\nis not called yet, so it is not necessary to call ->ndo_setup_tc()\nin gred_offload().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21980', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21981', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix memory leak in aRFS after reset\n\nFix aRFS (accelerated Receive Flow Steering) structures memory leak by\nadding a checker to verify if aRFS memory is already allocated while\nconfiguring VSI. aRFS objects are allocated in two cases:\n- as part of VSI initialization (at probe), and\n- as part of reset handling\n\nHowever, VSI reconfiguration executed during reset involves memory\nallocation one more time, without prior releasing already allocated\nresources. This led to the memory leak with the following signature:\n\n[root@os-delivery ~]# cat /sys/kernel/debug/kmemleak\nunreferenced object 0xff3c1ca7252e6000 (size 8192):\n comm "kworker/0:0", pid 8, jiffies 4296833052\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 0):\n [<ffffffff991ec485>] __kmalloc_cache_noprof+0x275/0x340\n [<ffffffffc0a6e06a>] ice_init_arfs+0x3a/0xe0 [ice]\n [<ffffffffc09f1027>] ice_vsi_cfg_def+0x607/0x850 [ice]\n [<ffffffffc09f244b>] ice_vsi_setup+0x5b/0x130 [ice]\n [<ffffffffc09c2131>] ice_init+0x1c1/0x460 [ice]\n [<ffffffffc09c64af>] ice_probe+0x2af/0x520 [ice]\n [<ffffffff994fbcd3>] local_pci_probe+0x43/0xa0\n [<ffffffff98f07103>] work_for_cpu_fn+0x13/0x20\n [<ffffffff98f0b6d9>] process_one_work+0x179/0x390\n [<ffffffff98f0c1e9>] worker_thread+0x239/0x340\n [<ffffffff98f14abc>] kthread+0xcc/0x100\n [<ffffffff98e45a6d>] ret_from_fork+0x2d/0x50\n [<ffffffff98e083ba>] ret_from_fork_asm+0x1a/0x30\n ...', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21981', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21986', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: switchdev: Convert blocking notification chain to a raw one\n\nA blocking notification chain uses a read-write semaphore to protect the\nintegrity of the chain. The semaphore is acquired for writing when\nadding / removing notifiers to / from the chain and acquired for reading\nwhen traversing the chain and informing notifiers about an event.\n\nIn case of the blocking switchdev notification chain, recursive\nnotifications are possible which leads to the semaphore being acquired\ntwice for reading and to lockdep warnings being generated [1].\n\nSpecifically, this can happen when the bridge driver processes a\nSWITCHDEV_BRPORT_UNOFFLOADED event which causes it to emit notifications\nabout deferred events when calling switchdev_deferred_process().\n\nFix this by converting the notification chain to a raw notification\nchain in a similar fashion to the netdev notification chain. Protect\nthe chain using the RTNL mutex by acquiring it when modifying the chain.\nEvents are always informed under the RTNL mutex, but add an assertion in\ncall_switchdev_blocking_notifiers() to make sure this is not violated in\nthe future.\n\nMaintain the "blocking" prefix as events are always emitted from process\ncontext and listeners are allowed to block.\n\n[1]:\nWARNING: possible recursive locking detected\n6.14.0-rc4-custom-g079270089484 #1 Not tainted\n--------------------------------------------\nip/52731 is trying to acquire lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nbut task is already holding lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nother info that might help us debug this:\nPossible unsafe locking scenario:\nCPU0\n----\nlock((switchdev_blocking_notif_chain).rwsem);\nlock((switchdev_blocking_notif_chain).rwsem);\n\n*** DEADLOCK ***\nMay be due to missing lock nesting notation\n3 locks held by ip/52731:\n #0: ffffffff84f795b0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x727/0x1dc0\n #1: ffffffff8731f628 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x790/0x1dc0\n #2: ffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nstack backtrace:\n...\n? __pfx_down_read+0x10/0x10\n? __pfx_mark_lock+0x10/0x10\n? __pfx_switchdev_port_attr_set_deferred+0x10/0x10\nblocking_notifier_call_chain+0x58/0xa0\nswitchdev_port_attr_notify.constprop.0+0xb3/0x1b0\n? __pfx_switchdev_port_attr_notify.constprop.0+0x10/0x10\n? mark_held_locks+0x94/0xe0\n? switchdev_deferred_process+0x11a/0x340\nswitchdev_port_attr_set_deferred+0x27/0xd0\nswitchdev_deferred_process+0x164/0x340\nbr_switchdev_port_unoffload+0xc8/0x100 [bridge]\nbr_switchdev_blocking_event+0x29f/0x580 [bridge]\nnotifier_call_chain+0xa2/0x440\nblocking_notifier_call_chain+0x6e/0xa0\nswitchdev_bridge_port_unoffload+0xde/0x1a0\n...', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21986', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-21995', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: Fix fence reference count leak\n\nThe last_scheduled fence leaks when an entity is being killed and adding\nthe cleanup callback fails.\n\nDecrement the reference count of prev when dma_fence_add_callback()\nfails, ensuring proper balance.\n\n[phasta: add git tag info for stable kernel]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-21995', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22001', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Fix integer overflow in qaic_validate_req()\n\nThese are u64 variables that come from the user via\nqaic_attach_slice_bo_ioctl(). Use check_add_overflow() to ensure that\nthe math doesn't have an integer wrapping bug.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22001', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22009', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: dummy: force synchronous probing\n\nSometimes I get a NULL pointer dereference at boot time in kobject_get()\nwith the following call stack:\n\nanatop_regulator_probe()\n devm_regulator_register()\n regulator_register()\n regulator_resolve_supply()\n kobject_get()\n\nBy placing some extra BUG_ON() statements I could verify that this is\nraised because probing of the 'dummy' regulator driver is not completed\n('dummy_regulator_rdev' is still NULL).\n\nIn the JTAG debugger I can see that dummy_regulator_probe() and\nanatop_regulator_probe() can be run by different kernel threads\n(kworker/u4:*). I haven't further investigated whether this can be\nchanged or if there are other possibilities to force synchronization\nbetween these two probe routines. On the other hand I don't expect much\nboot time penalty by probing the 'dummy' regulator synchronously.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22009', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22071', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix a leak in spufs_create_context()\n\nLeak fixes back in 2008 missed one case - if we are trying to set affinity\nand spufs_mkdir() fails, we need to drop the reference to neighbor.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22071', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-22077', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "smb: client: fix TCP timers deadlock after rmmod"\n\nThis reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.\n\nCommit e9f2517a3e18 ("smb: client: fix TCP timers deadlock after\nrmmod") is intended to fix a null-ptr-deref in LOCKDEP, which is\nmentioned as CVE-2024-54680, but is actually did not fix anything;\nThe issue can be reproduced on top of it. [0]\n\nAlso, it reverted the change by commit ef7134c7fc48 ("smb: client:\nFix use-after-free of network namespace.") and introduced a real\nissue by reviving the kernel TCP socket.\n\nWhen a reconnect happens for a CIFS connection, the socket state\ntransitions to FIN_WAIT_1. Then, inet_csk_clear_xmit_timers_sync()\nin tcp_close() stops all timers for the socket.\n\nIf an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1\nforever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.\n\nUsually, FIN can be retransmitted by the peer, but if the peer aborts\nthe connection, the issue comes into reality.\n\nI warned about this privately by pointing out the exact report [1],\nbut the bogus fix was finally merged.\n\nSo, we should not stop the timers to finally kill the connection on\nour side in that case, meaning we must not use a kernel socket for\nTCP whose sk->sk_net_refcnt is 0.\n\nThe kernel socket does not have a reference to its netns to make it\npossible to tear down netns without cleaning up every resource in it.\n\nFor example, tunnel devices use a UDP socket internally, but we can\ndestroy netns without removing such devices and let it complete\nduring exit. Otherwise, netns would be leaked when the last application\ndied.\n\nHowever, this is problematic for TCP sockets because TCP has timers to\nclose the connection gracefully even after the socket is close()d. The\nlifetime of the socket and its netns is different from the lifetime of\nthe underlying connection.\n\nIf the socket user does not maintain the netns lifetime, the timer could\nbe fired after the socket is close()d and its netns is freed up, resulting\nin use-after-free.\n\nActually, we have seen so many similar issues and converted such sockets\nto have a reference to netns.\n\nThat\'s why I converted the CIFS client socket to have a reference to\nnetns (sk->sk_net_refcnt == 1), which is somehow mentioned as out-of-scope\nof CIFS and technically wrong in e9f2517a3e18, but **is in-scope and right\nfix**.\n\nRegarding the LOCKDEP issue, we can prevent the module unload by\nbumping the module refcount when switching the LOCKDDEP key in\nsock_lock_init_class_and_name(). [2]\n\nFor a while, let\'s revert the bogus fix.\n\nNote that now we can use sk_net_refcnt_upgrade() for the socket\nconversion, but I\'ll do so later separately to make backport easy.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-22077', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-23138', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nwatch_queue: fix pipe accounting mismatch\n\nCurrently, watch_queue_set_size() modifies the pipe buffers charged to\nuser->pipe_bufs without updating the pipe->nr_accounted on the pipe\nitself, due to the if (!pipe_has_watch_queue()) test in\npipe_resize_ring(). This means that when the pipe is ultimately freed,\nwe decrement user->pipe_bufs by something other than what than we had\ncharged to it, potentially leading to an underflow. This in turn can\ncause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM.\n\nTo remedy this, explicitly account for the pipe usage in\nwatch_queue_set_size() to match the number set via account_pipe_buffers()\n\n(It's unclear why watch_queue_set_size() does not update nr_accounted;\nit may be due to intentional overprovisioning in watch_queue_set_size()?)", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-23138', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-23157', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: add check to avoid out of bound access\n\nThere is a possibility that init_codecs is invoked multiple times during\nmanipulated payload from video firmware. In such case, if codecs_count\ncan get incremented to value more than MAX_CODEC_NUM, there can be OOB\naccess. Reset the count so that it always starts from beginning.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-23157', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37740', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add sanity check for agwidth in dbMount\n\nThe width in dmapctl of the AG is zero, it trigger a divide error when\ncalculating the control page level in dbAllocAG.\n\nTo avoid this issue, add a check for agwidth in dbAllocAG.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37740', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37748', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group\n\nCurrently, mtk_iommu calls during probe iommu_device_register before\nthe hw_list from driver data is initialized. Since iommu probing issue\nfix, it leads to NULL pointer dereference in mtk_iommu_device_group when\nhw_list is accessed with list_first_entry (not null safe).\n\nSo, change the call order to ensure iommu_device_register is called\nafter the driver data are initialized.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37766', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37766', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37768', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37768', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37770', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37770', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37771', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37771', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37778', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Fix dangling pointer in krb_authenticate\n\nkrb_authenticate frees sess->user and does not set the pointer\nto NULL. It calls ksmbd_krb5_authenticate to reinitialise\nsess->user but that function may return without doing so. If\nthat happens then smb2_sess_setup, which calls krb_authenticate,\nwill be accessing free'd memory when it later uses sess->user.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37778', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37793', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\navs_component_probe() does not check for this case, which results in a\nNULL pointer dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37793', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37805', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsound/virtio: Fix cancel_sync warnings on uninitialized work_structs\n\nBetty reported hitting the following warning:\n\n[ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182\n...\n[ 8.713282][ T221] Call trace:\n[ 8.713365][ T221] __flush_work+0x8d0/0x914\n[ 8.713468][ T221] __cancel_work_sync+0xac/0xfc\n[ 8.713570][ T221] cancel_work_sync+0x24/0x34\n[ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.714035][ T221] virtio_dev_probe+0x28c/0x390\n[ 8.714139][ T221] really_probe+0x1bc/0x4c8\n...\n\nIt seems we're hitting the error path in virtsnd_probe(), which\ntriggers a virtsnd_remove() which iterates over the substreams\ncalling cancel_work_sync() on the elapsed_period work_struct.\n\nLooking at the code, from earlier in:\nvirtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg()\n\nWe set snd->nsubstreams, allocate the snd->substreams, and if\nwe then hit an error on the info allocation or something in\nvirtsnd_ctl_query_info() fails, we will exit without having\ninitialized the elapsed_period work_struct.\n\nWhen that error path unwinds we then call virtsnd_remove()\nwhich as long as the substreams array is allocated, will iterate\nthrough calling cancel_work_sync() on the uninitialized work\nstruct hitting this warning.\n\nTakashi Iwai suggested this fix, which initializes the substreams\nstructure right after allocation, so that if we hit the error\npaths we avoid trying to cleanup uninitialized data.\n\nNote: I have not yet managed to reproduce the issue myself, so\nthis patch has had limited testing.\n\nFeedback or thoughts would be appreciated!", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37805', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37815', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration\n\nResolve kernel panic while accessing IRQ handler associated with the\ngenerated IRQ. This is done by acquiring the spinlock and storing the\ncurrent interrupt state before handling the interrupt request using\ngeneric_handle_irq.\n\nA previous fix patch was submitted where 'generic_handle_irq' was\nreplaced with 'handle_nested_irq'. However, this change also causes\nthe kernel panic where after determining which GPIO triggered the\ninterrupt and attempting to call handle_nested_irq with the mapped\nIRQ number, leads to a failure in locating the registered handler.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37815', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37831', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check\nfor this case, which results in a NULL pointer dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37831', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37844', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: avoid NULL pointer dereference in dbg call\n\ncifs_server_dbg() implies server to be non-NULL so\nmove call under condition to avoid NULL pointer dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37844', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37853', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: debugfs hang_hws skip GPU with MES\n\ndebugfs hang_hws is used by GPU reset test with HWS, for MES this crash\nthe kernel with NULL pointer access because dqm->packet_mgr is not setup\nfor MES path.\n\nSkip GPU with MES for now, MES hang_hws debugfs interface will be\nsupported later.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37853', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37881', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()\n\nThe variable d->name, returned by devm_kasprintf(), could be NULL.\nA pointer check is added to prevent potential NULL pointer dereference.\nThis is similar to the fix in commit 3027e7b15b02\n("ice: Fix some null pointer dereference issues in ice_ptp.c").\n\nThis issue is found by our static analysis tool', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37881', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37889', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Consistently treat platform_max as control value\n\nThis reverts commit 9bdd10d57a88 ("ASoC: ops: Shift tested values in\nsnd_soc_put_volsw() by +min"), and makes some additional related\nupdates.\n\nThere are two ways the platform_max could be interpreted; the maximum\nregister value, or the maximum value the control can be set to. The\npatch moved from treating the value as a control value to a register\none. When the patch was applied it was technically correct as\nsnd_soc_limit_volume() also used the register interpretation. However,\neven then most of the other usages treated platform_max as a\ncontrol value, and snd_soc_limit_volume() has since been updated to\nalso do so in commit fb9ad24485087 ("ASoC: ops: add correct range\ncheck for limiting volume"). That patch however, missed updating\nsnd_soc_put_volsw() back to the control interpretation, and fixing\nsnd_soc_info_volsw_range(). The control interpretation makes more\nsense as limiting is typically done from the machine driver, so it is\nappropriate to use the customer facing representation rather than the\ninternal codec representation. Update all the code to consistently use\nthis interpretation of platform_max.\n\nFinally, also add some comments to the soc_mixer_control struct to\nhopefully avoid further patches switching between the two approaches.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37889', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37905', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Balance device refcount when destroying devices\n\nUsing device_find_child() to lookup the proper SCMI device to destroy\ncauses an unbalance in device refcount, since device_find_child() calls an\nimplicit get_device(): this, in turns, inhibits the call of the provided\nrelease methods upon devices destruction.\n\nAs a consequence, one of the structures that is not freed properly upon\ndestruction is the internal struct device_private dev->p populated by the\ndrivers subsystem core.\n\nKMemleak detects this situation since loading/unloding some SCMI driver\ncauses related devices to be created/destroyed without calling any\ndevice_release method.\n\nunreferenced object 0xffff00000f583800 (size 512):\n comm "insmod", pid 227, jiffies 4294912190\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 60 36 1d 8a 00 80 ff ff ........`6......\n backtrace (crc 114e2eed):\n kmemleak_alloc+0xbc/0xd8\n __kmalloc_cache_noprof+0x2dc/0x398\n device_add+0x954/0x12d0\n device_register+0x28/0x40\n __scmi_device_create.part.0+0x1bc/0x380\n scmi_device_create+0x2d0/0x390\n scmi_create_protocol_devices+0x74/0xf8\n scmi_device_request_notifier+0x1f8/0x2a8\n notifier_call_chain+0x110/0x3b0\n blocking_notifier_call_chain+0x70/0xb0\n scmi_driver_register+0x350/0x7f0\n 0xffff80000a3b3038\n do_one_initcall+0x12c/0x730\n do_init_module+0x1dc/0x640\n load_module+0x4b20/0x5b70\n init_module_from_file+0xec/0x158\n\n$ ./scripts/faddr2line ./vmlinux device_add+0x954/0x12d0\ndevice_add+0x954/0x12d0:\nkmalloc_noprof at include/linux/slab.h:901\n(inlined by) kzalloc_noprof at include/linux/slab.h:1037\n(inlined by) device_private_init at drivers/base/core.c:3510\n(inlined by) device_add at drivers/base/core.c:3561\n\nBalance device refcount by issuing a put_device() on devices found via\ndevice_find_child().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37905', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37918', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()\n\nA NULL pointer dereference can occur in skb_dequeue() when processing a\nQCA firmware crash dump on WCN7851 (0489:e0f3).\n\n[ 93.672166] Bluetooth: hci0: ACL memdump size(589824)\n\n[ 93.672475] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[ 93.672517] Workqueue: hci0 hci_devcd_rx [bluetooth]\n[ 93.672598] RIP: 0010:skb_dequeue+0x50/0x80\n\nThe issue stems from handle_dump_pkt_qca() returning 0 even when a dump\npacket is successfully processed. This is because it incorrectly\nforwards the return value of hci_devcd_init() (which returns 0 on\nsuccess). As a result, the caller (btusb_recv_acl_qca() or\nbtusb_recv_evt_qca()) assumes the packet was not handled and passes it\nto hci_recv_frame(), leading to premature kfree() of the skb.\n\nLater, hci_devcd_rx() attempts to dequeue the same skb from the dump\nqueue, resulting in a NULL pointer dereference.\n\nFix this by:\n1. Making handle_dump_pkt_qca() return 0 on success and negative errno\n on failure, consistent with kernel conventions.\n2. Splitting dump packet detection into separate functions for ACL\n and event packets for better structure and readability.\n\nThis ensures dump packets are properly identified and consumed, avoiding\ndouble handling and preventing NULL pointer access.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37918', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37947', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent out-of-bounds stream writes by validating *pos\n\nksmbd_vfs_stream_write() did not validate whether the write offset\n(*pos) was within the bounds of the existing stream data length (v_len).\nIf *pos was greater than or equal to v_len, this could lead to an\nout-of-bounds memory write.\n\nThis patch adds a check to ensure *pos is less than v_len before\nproceeding. If the condition fails, -EINVAL is returned.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37947', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-37967', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: displayport: Fix deadlock\n\nThis patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock\nfunctions to the UCSI driver. ucsi_con_mutex_lock ensures the connector\nmutex is only locked if a connection is established and the partner pointer\nis valid. This resolves a deadlock scenario where\nucsi_displayport_remove_partner holds con->mutex waiting for\ndp_altmode_work to complete while dp_altmode_work attempts to acquire it.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-37967', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38014', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Refactor remove call with idxd_cleanup() helper\n\nThe idxd_cleanup() helper cleans up perfmon, interrupts, internals and\nso on. Refactor remove call with the idxd_cleanup() helper to avoid code\nduplication. Note, this also fixes the missing put_device() for idxd\ngroups, enginces and wqs.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38014', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38037', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Annotate FDB data races\n\nThe 'used' and 'updated' fields in the FDB entry structure can be\naccessed concurrently by multiple threads, leading to reports such as\n[1]. Can be reproduced using [2].\n\nSuppress these reports by annotating these accesses using\nREAD_ONCE() / WRITE_ONCE().\n\n[1]\nBUG: KCSAN: data-race in vxlan_xmit / vxlan_xmit\n\nwrite to 0xffff942604d263a8 of 8 bytes by task 286 on cpu 0:\n vxlan_xmit+0xb29/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff942604d263a8 of 8 bytes by task 287 on cpu 2:\n vxlan_xmit+0xadf/0x2380\n dev_hard_start_xmit+0x84/0x2f0\n __dev_queue_xmit+0x45a/0x1650\n packet_xmit+0x100/0x150\n packet_sendmsg+0x2114/0x2ac0\n __sys_sendto+0x318/0x330\n __x64_sys_sendto+0x76/0x90\n x64_sys_call+0x14e8/0x1c00\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000000fffbac6e -> 0x00000000fffbac6f\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 2 UID: 0 PID: 287 Comm: mausezahn Not tainted 6.13.0-rc7-01544-gb4b270f11a02 #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014\n\n[2]\n #!/bin/bash\n\n set +H\n echo whitelist > /sys/kernel/debug/kcsan\n echo !vxlan_xmit > /sys/kernel/debug/kcsan\n\n ip link add name vx0 up type vxlan id 10010 dstport 4789 local 192.0.2.1\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 198.51.100.1\n taskset -c 0 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &\n taskset -c 2 mausezahn vx0 -a own -b 00:11:22:33:44:55 -c 0 -q &", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38037', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38043', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Set dma_mask for ffa devices\n\nSet dma_mask for FFA devices, otherwise DMA allocation using the device pointer\nlead to following warning:\n\nWARNING: CPU: 1 PID: 1 at kernel/dma/mapping.c:597 dma_alloc_attrs+0xe0/0x124', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38043', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38051', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_fill_dirent\n\nThere is a race condition in the readdir concurrency process, which may\naccess the rsp buffer after it has been released, triggering the\nfollowing KASAN warning.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03/0xb60 [cifs]\n Read of size 4 at addr ffff8880099b819c by task a.out/342975\n\n CPU: 2 UID: 0 PID: 342975 Comm: a.out Not tainted 6.15.0-rc6+ #240 PREEMPT(full)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\n Call Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n print_report+0xce/0x640\n kasan_report+0xb8/0xf0\n cifs_fill_dirent+0xb03/0xb60 [cifs]\n cifs_readdir+0x12cb/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f996f64b9f9\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01\n f0 ff ff 0d f7 c3 0c 00 f7 d8 64 89 8\n RSP: 002b:00007f996f53de78 EFLAGS: 00000207 ORIG_RAX: 000000000000004e\n RAX: ffffffffffffffda RBX: 00007f996f53ecdc RCX: 00007f996f64b9f9\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007f996f53dea0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000207 R12: ffffffffffffff88\n R13: 0000000000000000 R14: 00007ffc8cd9a500 R15: 00007f996f51e000\n </TASK>\n\n Allocated by task 408:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x6e/0x70\n kmem_cache_alloc_noprof+0x117/0x3d0\n mempool_alloc_noprof+0xf2/0x2c0\n cifs_buf_get+0x36/0x80 [cifs]\n allocate_buffers+0x1d2/0x330 [cifs]\n cifs_demultiplex_thread+0x22b/0x2690 [cifs]\n kthread+0x394/0x720\n ret_from_fork+0x34/0x70\n ret_from_fork_asm+0x1a/0x30\n\n Freed by task 342979:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x37/0x50\n kmem_cache_free+0x2b8/0x500\n cifs_buf_release+0x3c/0x70 [cifs]\n cifs_readdir+0x1c97/0x3190 [cifs]\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents64+0x134/0x220\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n The buggy address belongs to the object at ffff8880099b8000\n which belongs to the cache cifs_request of size 16588\n The buggy address is located 412 bytes inside of\n freed 16588-byte region [ffff8880099b8000, ffff8880099bc0cc)\n\n The buggy address belongs to the physical page:\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x99b8\n head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n anon flags: 0x80000000000040(head|node=0|zone=1)\n page_type: f5(slab)\n raw: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n raw: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000040 ffff888001e03400 0000000000000000 dead000000000001\n head: 0000000000000000 0000000000010001 00000000f5000000 0000000000000000\n head: 0080000000000003 ffffea0000266e01 00000000ffffffff 00000000ffffffff\n head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8880099b8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8880099b8180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8880099b8200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8880099b8280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\nPOC is available in the link [1].\n\nThe problem triggering process is as follows:\n\nProcess 1 Process 2\n-----------------------------------\n---truncated---', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38051', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38064', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()\n\nHongyu reported a hang on kexec in a VM. QEMU reported invalid memory\naccesses during the hang.\n\n\tInvalid read at addr 0x102877002, size 2, region '(null)', reason: rejected\n\tInvalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected\n\t...\n\nIt was traced down to virtio-console. Kexec works fine if virtio-console\nis not in use.\n\nThe issue is that virtio-console continues to write to the MMIO even after\nunderlying virtio-pci device is reset.\n\nAdditionally, Eric noticed that IOMMUs are reset before devices, if\ndevices are not reset on shutdown they continue to poke at guest memory\nand get errors from the IOMMU. Some devices get wedged then.\n\nThe problem can be solved by breaking all virtio devices on virtio\nbus shutdown, then resetting them.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38064', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38113', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Fix NULL pointer dereference when nosmp is used\n\nWith nosmp in cmdline, other CPUs are not brought up, leaving\ntheir cpc_desc_ptr NULL. CPU0's iteration via for_each_possible_cpu()\ndereferences these NULL pointers, causing panic.\n\nPanic backtrace:\n\n[ 0.401123] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b8\n...\n[ 0.403255] [<ffffffff809a5818>] cppc_allow_fast_switch+0x6a/0xd4\n...\nKernel panic - not syncing: Attempted to kill init!\n\n[ rjw: New subject ]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38113', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38122', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngve: add missing NULL check for gve_alloc_pending_packet() in TX DQO\n\ngve_alloc_pending_packet() can return NULL, but gve_tx_add_skb_dqo()\ndid not check for this case before dereferencing the returned pointer.\n\nAdd a missing NULL check to prevent a potential NULL pointer\ndereference when allocation fails.\n\nThis improves robustness in low-memory scenarios.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38122', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38123', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: Fix napi rx poll issue\n\nWhen driver handles the napi rx polling requests, the netdev might\nhave been released by the dellink logic triggered by the disconnect\noperation on user plane. However, in the logic of processing skb in\npolling, an invalid netdev is still being used, which causes a panic.\n\nBUG: kernel NULL pointer dereference, address: 00000000000000f1\nOops: 0000 [#1] PREEMPT SMP NOPTI\nRIP: 0010:dev_gro_receive+0x3a/0x620\n[...]\nCall Trace:\n <IRQ>\n ? __die_body+0x68/0xb0\n ? page_fault_oops+0x379/0x3e0\n ? exc_page_fault+0x4f/0xa0\n ? asm_exc_page_fault+0x22/0x30\n ? __pfx_t7xx_ccmni_recv_skb+0x10/0x10 [mtk_t7xx (HASH:1400 7)]\n ? dev_gro_receive+0x3a/0x620\n napi_gro_receive+0xad/0x170\n t7xx_ccmni_recv_skb+0x48/0x70 [mtk_t7xx (HASH:1400 7)]\n t7xx_dpmaif_napi_rx_poll+0x590/0x800 [mtk_t7xx (HASH:1400 7)]\n net_rx_action+0x103/0x470\n irq_exit_rcu+0x13a/0x310\n sysvec_apic_timer_interrupt+0x56/0x90\n </IRQ>', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38123', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38131', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: prevent deactivate active config while enabling the config\n\nWhile enable active config via cscfg_csdev_enable_active_config(),\nactive config could be deactivated via configfs' sysfs interface.\nThis could make UAF issue in below scenario:\n\nCPU0 CPU1\n(sysfs enable) load module\n cscfg_load_config_sets()\n activate config. // sysfs\n (sys_active_cnt == 1)\n...\ncscfg_csdev_enable_active_config()\nlock(csdev->cscfg_csdev_lock)\n// here load config activate by CPU1\nunlock(csdev->cscfg_csdev_lock)\n\n deactivate config // sysfs\n (sys_activec_cnt == 0)\n cscfg_unload_config_sets()\n unload module\n\n// access to config_desc which freed\n// while unloading module.\ncscfg_csdev_enable_config\n\nTo address this, use cscfg_config_desc's active_cnt as a reference count\n which will be holded when\n - activate the config.\n - enable the activated config.\nand put the module reference when config_active_cnt == 0.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38131', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38148', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: mscc: Fix memory leak when using one step timestamping\n\nFix memory leak when running one-step timestamping. When running\none-step sync timestamping, the HW is configured to insert the TX time\ninto the frame, so there is no reason to keep the skb anymore. As in\nthis case the HW will never generate an interrupt to say that the frame\nwas timestamped, then the frame will never released.\nFix this by freeing the frame in case of one-step timestamping.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38148', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38161', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix error flow upon firmware failure for RQ destruction\n\nUpon RQ destruction if the firmware command fails which is the\nlast resource to be destroyed some SW resources were already cleaned\nregardless of the failure.\n\nNow properly rollback the object to its original state upon such failure.\n\nIn order to avoid a use-after free in case someone tries to destroy the\nobject again, which results in the following kernel trace:\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 0 PID: 37589 at lib/refcount.c:28 refcount_warn_saturate+0xf4/0x148\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) rfkill mlx5_core(OE) mlxdevm(OE) ib_uverbs(OE) ib_core(OE) psample mlxfw(OE) mlx_compat(OE) macsec tls pci_hyperv_intf sunrpc vfat fat virtio_net net_failover failover fuse loop nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_console virtio_gpu virtio_blk virtio_dma_buf virtio_mmio dm_mirror dm_region_hash dm_log dm_mod xpmem(OE)\nCPU: 0 UID: 0 PID: 37589 Comm: python3 Kdump: loaded Tainted: G OE ------- --- 6.12.0-54.el10.aarch64 #1\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : refcount_warn_saturate+0xf4/0x148\nlr : refcount_warn_saturate+0xf4/0x148\nsp : ffff80008b81b7e0\nx29: ffff80008b81b7e0 x28: ffff000133d51600 x27: 0000000000000001\nx26: 0000000000000000 x25: 00000000ffffffea x24: ffff00010ae80f00\nx23: ffff00010ae80f80 x22: ffff0000c66e5d08 x21: 0000000000000000\nx20: ffff0000c66e0000 x19: ffff00010ae80340 x18: 0000000000000006\nx17: 0000000000000000 x16: 0000000000000020 x15: ffff80008b81b37f\nx14: 0000000000000000 x13: 2e656572662d7265 x12: ffff80008283ef78\nx11: ffff80008257efd0 x10: ffff80008283efd0 x9 : ffff80008021ed90\nx8 : 0000000000000001 x7 : 00000000000bffe8 x6 : c0000000ffff7fff\nx5 : ffff0001fb8e3408 x4 : 0000000000000000 x3 : ffff800179993000\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000133d51600\nCall trace:\n refcount_warn_saturate+0xf4/0x148\n mlx5_core_put_rsc+0x88/0xa0 [mlx5_ib]\n mlx5_core_destroy_rq_tracked+0x64/0x98 [mlx5_ib]\n mlx5_ib_destroy_wq+0x34/0x80 [mlx5_ib]\n ib_destroy_wq_user+0x30/0xc0 [ib_core]\n uverbs_free_wq+0x28/0x58 [ib_uverbs]\n destroy_hw_idr_uobject+0x34/0x78 [ib_uverbs]\n uverbs_destroy_uobject+0x48/0x240 [ib_uverbs]\n __uverbs_cleanup_ufile+0xd4/0x1a8 [ib_uverbs]\n uverbs_destroy_ufile_hw+0x48/0x120 [ib_uverbs]\n ib_uverbs_close+0x2c/0x100 [ib_uverbs]\n __fput+0xd8/0x2f0\n __fput_sync+0x50/0x70\n __arm64_sys_close+0x40/0x90\n invoke_syscall.constprop.0+0x74/0xd0\n do_el0_svc+0x48/0xe8\n el0_svc+0x44/0x1d0\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x1a4/0x1a8', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38161', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38183', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()\n\nBefore calling lan743x_ptp_io_event_clock_get(), the 'channel' value\nis checked against the maximum value of PCI11X1X_PTP_IO_MAX_CHANNELS(8).\nThis seems correct and aligns with the PTP interrupt status register\n(PTP_INT_STS) specifications.\n\nHowever, lan743x_ptp_io_event_clock_get() writes to ptp->extts[] with\nonly LAN743X_PTP_N_EXTTS(4) elements, using channel as an index:\n\n lan743x_ptp_io_event_clock_get(..., u8 channel,...)\n {\n ...\n /* Update Local timestamp */\n extts = &ptp->extts[channel];\n extts->ts.tv_sec = sec;\n ...\n }\n\nTo avoid an out-of-bounds write and utilize all the supported GPIO\ninputs, set LAN743X_PTP_N_EXTTS to 8.\n\nDetected using the static analysis tool - Svace.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38183', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38193', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: reject invalid perturb period\n\nGerrard Tai reported that SFQ perturb_period has no range check yet,\nand this can be used to trigger a race condition fixed in a separate patch.\n\nWe want to make sure ctl->perturb_period * HZ will not overflow\nand is positive.\n\n\ntc qd add dev lo root sfq perturb -10 # negative value : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 1000000000 # too big : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 2000000 # acceptable value\ntc -s -d qd sh dev lo\nqdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec\n Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)\n backlog 0b 0p requeues 0', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38193', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38194', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: check that raw node were preallocated before writing summary\n\nSyzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault\ninjection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't\ncheck return value of jffs2_prealloc_raw_node_refs and simply lets any\nerror propagate into jffs2_sum_write_data, which eventually calls\njffs2_link_node_ref in order to link the summary to an expectedly allocated\nnode.\n\nkernel BUG at fs/jffs2/nodelist.c:592!\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:jffs2_link_node_ref+0x570/0x690 fs/jffs2/nodelist.c:592\nCall Trace:\n <TASK>\n jffs2_sum_write_data fs/jffs2/summary.c:841 [inline]\n jffs2_sum_write_sumnode+0xd1a/0x1da0 fs/jffs2/summary.c:874\n jffs2_do_reserve_space+0xa18/0xd60 fs/jffs2/nodemgmt.c:388\n jffs2_reserve_space+0x55f/0xaa0 fs/jffs2/nodemgmt.c:197\n jffs2_write_inode_range+0x246/0xb50 fs/jffs2/write.c:362\n jffs2_write_end+0x726/0x15d0 fs/jffs2/file.c:301\n generic_perform_write+0x314/0x5d0 mm/filemap.c:3856\n __generic_file_write_iter+0x2ae/0x4d0 mm/filemap.c:3973\n generic_file_write_iter+0xe3/0x350 mm/filemap.c:4005\n call_write_iter include/linux/fs.h:2265 [inline]\n do_iter_readv_writev+0x20f/0x3c0 fs/read_write.c:735\n do_iter_write+0x186/0x710 fs/read_write.c:861\n vfs_iter_write+0x70/0xa0 fs/read_write.c:902\n iter_file_splice_write+0x73b/0xc90 fs/splice.c:685\n do_splice_from fs/splice.c:763 [inline]\n direct_splice_actor+0x10c/0x170 fs/splice.c:950\n splice_direct_to_actor+0x337/0xa10 fs/splice.c:896\n do_splice_direct+0x1a9/0x280 fs/splice.c:1002\n do_sendfile+0xb13/0x12c0 fs/read_write.c:1255\n __do_sys_sendfile64 fs/read_write.c:1323 [inline]\n __se_sys_sendfile64 fs/read_write.c:1309 [inline]\n __x64_sys_sendfile64+0x1cf/0x210 fs/read_write.c:1309\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFix this issue by checking return value of jffs2_prealloc_raw_node_refs\nbefore calling jffs2_sum_write_data.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38194', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38241', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem, swap: fix softlockup with mTHP swapin\n\nFollowing softlockup can be easily reproduced on my test machine with:\n\necho always > /sys/kernel/mm/transparent_hugepage/hugepages-64kB/enabled\nswapon /dev/zram0 # zram0 is a 48G swap device\nmkdir -p /sys/fs/cgroup/memory/test\necho 1G > /sys/fs/cgroup/test/memory.max\necho $BASHPID > /sys/fs/cgroup/test/cgroup.procs\nwhile true; do\n dd if=/dev/zero of=/tmp/test.img bs=1M count=5120\n cat /tmp/test.img > /dev/null\n rm /tmp/test.img\ndone\n\nThen after a while:\nwatchdog: BUG: soft lockup - CPU#0 stuck for 763s! [cat:5787]\nModules linked in: zram virtiofs\nCPU: 0 UID: 0 PID: 5787 Comm: cat Kdump: loaded Tainted: G L 6.15.0.orig-gf3021d9246bc-dirty #118 PREEMPT(voluntary)·\nTainted: [L]=SOFTLOCKUP\nHardware name: Red Hat KVM/RHEL-AV, BIOS 0.0.0 02/06/2015\nRIP: 0010:mpol_shared_policy_lookup+0xd/0x70\nCode: e9 b8 b4 ff ff 31 c0 c3 cc cc cc cc 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 41 54 55 53 <48> 8b 1f 48 85 db 74 41 4c 8d 67 08 48 89 fb 48 89 f5 4c 89 e7 e8\nRSP: 0018:ffffc90002b1fc28 EFLAGS: 00000202\nRAX: 00000000001c20ca RBX: 0000000000724e1e RCX: 0000000000000001\nRDX: ffff888118e214c8 RSI: 0000000000057d42 RDI: ffff888118e21518\nRBP: 000000000002bec8 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000bf4 R11: 0000000000000000 R12: 0000000000000001\nR13: 00000000001c20ca R14: 00000000001c20ca R15: 0000000000000000\nFS: 00007f03f995c740(0000) GS:ffff88a07ad9a000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f03f98f1000 CR3: 0000000144626004 CR4: 0000000000770eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n <TASK>\n shmem_alloc_folio+0x31/0xc0\n shmem_swapin_folio+0x309/0xcf0\n ? filemap_get_entry+0x117/0x1e0\n ? xas_load+0xd/0xb0\n ? filemap_get_entry+0x101/0x1e0\n shmem_get_folio_gfp+0x2ed/0x5b0\n shmem_file_read_iter+0x7f/0x2e0\n vfs_read+0x252/0x330\n ksys_read+0x68/0xf0\n do_syscall_64+0x4c/0x1c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f03f9a46991\nCode: 00 48 8b 15 81 14 10 00 f7 d8 64 89 02 b8 ff ff ff ff eb bd e8 20 ad 01 00 f3 0f 1e fa 80 3d 35 97 10 00 00 74 13 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 4f c3 66 0f 1f 44 00 00 55 48 89 e5 48 83 ec\nRSP: 002b:00007fff3c52bd28 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\nRAX: ffffffffffffffda RBX: 0000000000040000 RCX: 00007f03f9a46991\nRDX: 0000000000040000 RSI: 00007f03f98ba000 RDI: 0000000000000003\nRBP: 00007fff3c52bd50 R08: 0000000000000000 R09: 00007f03f9b9a380\nR10: 0000000000000022 R11: 0000000000000246 R12: 0000000000040000\nR13: 00007f03f98ba000 R14: 0000000000000003 R15: 0000000000000000\n </TASK>\n\nThe reason is simple, readahead brought some order 0 folio in swap cache,\nand the swapin mTHP folio being allocated is in conflict with it, so\nswapcache_prepare fails and causes shmem_swap_alloc_folio to return\n-EEXIST, and shmem simply retries again and again causing this loop.\n\nFix it by applying a similar fix for anon mTHP swapin.\n\nThe performance change is very slight, time of swapin 10g zero folios\nwith shmem (test for 12 times):\nBefore: 2.47s\nAfter: 2.48s\n\n[', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38241', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38255', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()\n\nWhile testing null_blk with configfs, echo 0 > poll_queues will trigger\nfollowing panic:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000010\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 27 UID: 0 PID: 920 Comm: bash Not tainted 6.15.0-02023-gadbdb95c8696-dirty #1238 PREEMPT(undef)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014\nRIP: 0010:__bitmap_or+0x48/0x70\nCall Trace:\n <TASK>\n __group_cpus_evenly+0x822/0x8c0\n group_cpus_evenly+0x2d9/0x490\n blk_mq_map_queues+0x1e/0x110\n null_map_queues+0xc9/0x170 [null_blk]\n blk_mq_update_queue_map+0xdb/0x160\n blk_mq_update_nr_hw_queues+0x22b/0x560\n nullb_update_nr_hw_queues+0x71/0xf0 [null_blk]\n nullb_device_poll_queues_store+0xa4/0x130 [null_blk]\n configfs_write_iter+0x109/0x1d0\n vfs_write+0x26e/0x6f0\n ksys_write+0x79/0x180\n __x64_sys_write+0x1d/0x30\n x64_sys_call+0x45c4/0x45f0\n do_syscall_64+0xa5/0x240\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nRoot cause is that numgrps is set to 0, and ZERO_SIZE_PTR is returned from\nkcalloc(), and later ZERO_SIZE_PTR will be deferenced.\n\nFix the problem by checking numgrps first in group_cpus_evenly(), and\nreturn NULL directly if numgrps is zero.\n\n[', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38255', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38304', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix NULL pointer deference on eir_get_service_data\n\nThe len parameter is considered optional so it can be NULL so it cannot\nbe used for skipping to next entry of EIR_SERVICE_DATA.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38307', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Verify content returned by parse_int_array()\n\nThe first element of the returned array stores its length. If it is 0,\nany manipulation beyond the element at index 0 ends with null-ptr-deref.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38307', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38321', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can\'t move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a "Dentry still in use" error, so add an error\nmessage that makes it clear this is what happened:\n\n[ 495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[ 495.281595] ------------[ cut here ]------------\n[ 495.281887] BUG: Dentry ffff888115531138{i=78,n=/} still in use (2) [unmount of cifs cifs]\n[ 495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we\'re already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38321', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38344', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: fix acpi parse and parseext cache leaks\n\nACPICA commit 8829e70e1360c81e7a5a901b5d4f48330e021ea5\n\nI'm Seunghun Han, and I work for National Security Research Institute of\nSouth Korea.\n\nI have been doing a research on ACPI and found an ACPI cache leak in ACPI\nearly abort cases.\n\nBoot log of ACPI cache leak is as follows:\n[ 0.352414] ACPI: Added _OSI(Module Device)\n[ 0.353182] ACPI: Added _OSI(Processor Device)\n[ 0.353182] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.353182] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.356028] ACPI: Unable to start the ACPI Interpreter\n[ 0.356799] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.360215] kmem_cache_destroy Acpi-State: Slab cache still has objects\n[ 0.360648] CPU: 0 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #10\n[ 0.361273] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.361873] Call Trace:\n[ 0.362243] ? dump_stack+0x5c/0x81\n[ 0.362591] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.362944] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.363296] ? acpi_os_delete_cache+0xa/0x10\n[ 0.363646] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.364000] ? acpi_terminate+0xa/0x14\n[ 0.364000] ? acpi_init+0x2af/0x34f\n[ 0.364000] ? __class_create+0x4c/0x80\n[ 0.364000] ? video_setup+0x7f/0x7f\n[ 0.364000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.364000] ? do_one_initcall+0x4e/0x1a0\n[ 0.364000] ? kernel_init_freeable+0x189/0x20a\n[ 0.364000] ? rest_init+0xc0/0xc0\n[ 0.364000] ? kernel_init+0xa/0x100\n[ 0.364000] ? ret_from_fork+0x25/0x30\n\nI analyzed this memory leak in detail. I found that “Acpi-State” cache and\n“Acpi-Parse” cache were merged because the size of cache objects was same\nslab cache size.\n\nI finally found “Acpi-Parse” cache and “Acpi-parse_ext” cache were leaked\nusing SLAB_NEVER_MERGE flag in kmem_cache_create() function.\n\nReal ACPI cache leak point is as follows:\n[ 0.360101] ACPI: Added _OSI(Module Device)\n[ 0.360101] ACPI: Added _OSI(Processor Device)\n[ 0.360101] ACPI: Added _OSI(3.0 _SCP Extensions)\n[ 0.361043] ACPI: Added _OSI(Processor Aggregator Device)\n[ 0.364016] ACPI: Unable to start the ACPI Interpreter\n[ 0.365061] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)\n[ 0.368174] kmem_cache_destroy Acpi-Parse: Slab cache still has objects\n[ 0.369332] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.371256] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.372000] Call Trace:\n[ 0.372000] ? dump_stack+0x5c/0x81\n[ 0.372000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.372000] ? acpi_ut_delete_caches+0x56/0x7b\n[ 0.372000] ? acpi_terminate+0xa/0x14\n[ 0.372000] ? acpi_init+0x2af/0x34f\n[ 0.372000] ? __class_create+0x4c/0x80\n[ 0.372000] ? video_setup+0x7f/0x7f\n[ 0.372000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.372000] ? do_one_initcall+0x4e/0x1a0\n[ 0.372000] ? kernel_init_freeable+0x189/0x20a\n[ 0.372000] ? rest_init+0xc0/0xc0\n[ 0.372000] ? kernel_init+0xa/0x100\n[ 0.372000] ? ret_from_fork+0x25/0x30\n[ 0.388039] kmem_cache_destroy Acpi-parse_ext: Slab cache still has objects\n[ 0.389063] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G W\n4.12.0-rc4-next-20170608+ #8\n[ 0.390557] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS\nvirtual_box 12/01/2006\n[ 0.392000] Call Trace:\n[ 0.392000] ? dump_stack+0x5c/0x81\n[ 0.392000] ? kmem_cache_destroy+0x1aa/0x1c0\n[ 0.392000] ? acpi_sleep_proc_init+0x27/0x27\n[ 0.392000] ? acpi_os_delete_cache+0xa/0x10\n[ 0.392000] ? acpi_ut_delete_caches+0x6d/0x7b\n[ 0.392000] ? acpi_terminate+0xa/0x14\n[ 0.392000] ? acpi_init+0x2af/0x3\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38344', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38364', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmaple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()\n\nTemporarily clear the preallocation flag when explicitly requesting\nallocations. Pre-existing allocations are already counted against the\nrequest through mas_node_count_gfp(), but the allocations will not happen\nif the MA_STATE_PREALLOC flag is set. This flag is meant to avoid\nre-allocating in bulk allocation mode, and to detect issues with\npreallocation calculations.\n\nThe MA_STATE_PREALLOC flag should also always be set on zero allocations\nso that detection of underflow allocations will print a WARN_ON() during\nconsumption.\n\nUser visible effect of this flaw is a WARN_ON() followed by a null pointer\ndereference when subsequent requests for larger number of nodes is\nignored, such as the vma merge retry in mmap_region() caused by drivers\naltering the vma flags (which happens in v6.6, at least)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38364', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38461', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_* TOCTOU\n\nTransport assignment may race with module unload. Protect new_transport\nfrom becoming a stale pointer.\n\nThis also takes care of an insecure call in vsock_use_local_transport();\nadd a lockdep assert.\n\nBUG: unable to handle page fault for address: fffffbfff8056000\nOops: Oops: 0000 [#1] SMP KASAN\nRIP: 0010:vsock_assign_transport+0x366/0x600\nCall Trace:\n vsock_connect+0x59c/0xc40\n __sys_connect+0xe8/0x100\n __x64_sys_connect+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38461', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38462', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix transport_{g2h,h2g} TOCTOU\n\nvsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.\ntransport_{g2h,h2g} may become NULL after the NULL check.\n\nIntroduce vsock_transport_local_cid() to protect from a potential\nnull-ptr-deref.\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_find_cid+0x47/0x90\nCall Trace:\n __vsock_bind+0x4b2/0x720\n vsock_bind+0x90/0xe0\n __sys_bind+0x14d/0x1e0\n __x64_sys_bind+0x6e/0xc0\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nKASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\nRIP: 0010:vsock_dev_do_ioctl.isra.0+0x58/0xf0\nCall Trace:\n __x64_sys_ioctl+0x12d/0x190\n do_syscall_64+0x92/0x1c0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38462', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38488', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in crypt_message when using async crypto\n\nThe CVE-2024-50047 fix removed asynchronous crypto handling from\ncrypt_message(), assuming all crypto operations are synchronous.\nHowever, when hardware crypto accelerators are used, this can cause\nuse-after-free crashes:\n\n crypt_message()\n // Allocate the creq buffer containing the req\n creq = smb2_get_aead_req(..., &req);\n\n // Async encryption returns -EINPROGRESS immediately\n rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);\n\n // Free creq while async operation is still in progress\n kvfree_sensitive(creq, ...);\n\nHardware crypto modules often implement async AEAD operations for\nperformance. When crypto_aead_encrypt/decrypt() returns -EINPROGRESS,\nthe operation completes asynchronously. Without crypto_wait_req(),\nthe function immediately frees the request buffer, leading to crashes\nwhen the driver later accesses the freed memory.\n\nThis results in a use-after-free condition when the hardware crypto\ndriver later accesses the freed request structure, leading to kernel\ncrashes with NULL pointer dereferences.\n\nThe issue occurs because crypto_alloc_aead() with mask=0 doesn't\nguarantee synchronous operation. Even without CRYPTO_ALG_ASYNC in\nthe mask, async implementations can be selected.\n\nFix by restoring the async crypto handling:\n- DECLARE_CRYPTO_WAIT(wait) for completion tracking\n- aead_request_set_callback() for async completion notification\n- crypto_wait_req() to wait for operation completion\n\nThis ensures the request buffer isn't freed until the crypto operation\ncompletes, whether synchronous or asynchronous, while preserving the\nCVE-2024-50047 fix.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38488', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38499', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nclone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns\n\nWhat we want is to verify there is that clone won\'t expose something\nhidden by a mount we wouldn\'t be able to undo. "Wouldn\'t be able to undo"\nmay be a result of MNT_LOCKED on a child, but it may also come from\nlacking admin rights in the userns of the namespace mount belongs to.\n\nclone_private_mnt() checks the former, but not the latter.\n\nThere\'s a number of rather confusing CAP_SYS_ADMIN checks in various\nuserns during the mount, especially with the new mount API; they serve\ndifferent purposes and in case of clone_private_mnt() they usually,\nbut not always end up covering the missing check mentioned above.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38499', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38552', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: plug races between subflow fail and subflow creation\n\nWe have races similar to the one addressed by the previous patch between\nsubflow failing and additional subflow creation. They are just harder to\ntrigger.\n\nThe solution is similar. Use a separate flag to track the condition\n'socket state prevent any additional subflow creation' protected by the\nfallback lock.\n\nThe socket fallback makes such flag true, and also receiving or sending\nan MP_FAIL option.\n\nThe field 'allow_infinite_fallback' is now always touched under the\nrelevant lock, we can drop the ONCE annotation on write.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38552', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38575', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use aead_request_free to match aead_request_alloc\n\nUse aead_request_free() instead of kfree() to properly free memory\nallocated by aead_request_alloc(). This ensures sensitive crypto data\nis zeroed before being freed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38575', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38609', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPM / devfreq: Check governor before using governor->name\n\nCommit 96ffcdf239de ("PM / devfreq: Remove redundant governor_name from\nstruct devfreq") removes governor_name and uses governor->name to replace\nit. But devfreq->governor may be NULL and directly using\ndevfreq->governor->name may cause null pointer exception. Move the check of\ngovernor to before using governor->name.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38609', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-38721', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: fix refcount leak on table dump\n\nThere is a reference count leak in ctnetlink_dump_table():\n if (res < 0) {\n nf_conntrack_get(&ct->ct_general); // HERE\n cb->args[1] = (unsigned long)ct;\n ...\n\nWhile its very unlikely, its possible that ct == last.\nIf this happens, then the refcount of ct was already incremented.\nThis 2nd increment is never undone.\n\nThis prevents the conntrack object from being released, which in turn\nkeeps prevents cnet->count from dropping back to 0.\n\nThis will then block the netns dismantle (or conntrack rmmod) as\nnf_conntrack_cleanup_net_list() will wait forever.\n\nThis can be reproduced by running conntrack_resize.sh selftest in a loop.\nIt takes ~20 minutes for me on a preemptible kernel on average before\nI see a runaway kworker spinning in nf_conntrack_cleanup_net_list.\n\nOne fix would to change this to:\n if (res < 0) {\n\t\tif (ct != last)\n\t nf_conntrack_get(&ct->ct_general);\n\nBut this reference counting isn't needed in the first place.\nWe can just store a cookie value instead.\n\nA followup patch will do the same for ctnetlink_exp_dump_table,\nit looks to me as if this has the same problem and like\nctnetlink_dump_table, we only need a 'skip hint', not the actual\nobject so we can apply the same cookie strategy there as well.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-38721', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39676', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla4xxx: Prevent a potential error pointer dereference\n\nThe qla4xxx_get_ep_fwdb() function is supposed to return NULL on error,\nbut qla4xxx_ep_connect() returns error pointers. Propagating the error\npointers will lead to an Oops in the caller, so change the error pointers\nto NULL.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39676', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39682', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix handling of zero-length records on the rx_list\n\nEach recvmsg() call must process either\n - only contiguous DATA records (any number of them)\n - one non-DATA record\n\nIf the next record has different type than what has already been\nprocessed we break out of the main processing loop. If the record\nhas already been decrypted (which may be the case for TLS 1.3 where\nwe don't know type until decryption) we queue the pending record\nto the rx_list. Next recvmsg() will pick it up from there.\n\nQueuing the skb to rx_list after zero-copy decrypt is not possible,\nsince in that case we decrypted directly to the user space buffer,\nand we don't have an skb to queue (darg.skb points to the ciphertext\nskb for access to metadata like length).\n\nOnly data records are allowed zero-copy, and we break the processing\nloop after each non-data record. So we should never zero-copy and\nthen find out that the record type has changed. The corner case\nwe missed is when the initial record comes from rx_list, and it's\nzero length.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39682', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39702', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39702', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39728', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: samsung: Fix UBSAN panic in samsung_clk_init()\n\nWith UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to\ndereferencing `ctx->clk_data.hws` before setting\n`ctx->clk_data.num = nr_clks`. Move that up to fix the crash.\n\n UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP\n <snip>\n Call trace:\n samsung_clk_init+0x110/0x124 (P)\n samsung_clk_init+0x48/0x124 (L)\n samsung_cmu_register_one+0x3c/0xa0\n exynos_arm64_register_cmu+0x54/0x64\n __gs101_cmu_top_of_clk_init_declare+0x28/0x60\n ...", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39728', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39756', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Prevent file descriptor table allocations exceeding INT_MAX\n\nWhen sysctl_nr_open is set to a very high value (for example, 1073741816\nas set by systemd), processes attempting to use file descriptors near\nthe limit can trigger massive memory allocation attempts that exceed\nINT_MAX, resulting in a WARNING in mm/slub.c:\n\n WARNING: CPU: 0 PID: 44 at mm/slub.c:5027 __kvmalloc_node_noprof+0x21a/0x288\n\nThis happens because kvmalloc_array() and kvmalloc() check if the\nrequested size exceeds INT_MAX and emit a warning when the allocation is\nnot flagged with __GFP_NOWARN.\n\nSpecifically, when nr_open is set to 1073741816 (0x3ffffff8) and a\nprocess calls dup2(oldfd, 1073741880), the kernel attempts to allocate:\n- File descriptor array: 1073741880 * 8 bytes = 8,589,935,040 bytes\n- Multiple bitmaps: ~400MB\n- Total allocation size: > 8GB (exceeding INT_MAX = 2,147,483,647)\n\nReproducer:\n1. Set /proc/sys/fs/nr_open to 1073741816:\n # echo 1073741816 > /proc/sys/fs/nr_open\n\n2. Run a program that uses a high file descriptor:\n #include <unistd.h>\n #include <sys/resource.h>\n\n int main() {\n struct rlimit rlim = {1073741824, 1073741824};\n setrlimit(RLIMIT_NOFILE, &rlim);\n dup2(2, 1073741880); // Triggers the warning\n return 0;\n }\n\n3. Observe WARNING in dmesg at mm/slub.c:5027\n\nsystemd commit a8b627a introduced automatic bumping of fs.nr_open to the\nmaximum possible value. The rationale was that systems with memory\ncontrol groups (memcg) no longer need separate file descriptor limits\nsince memory is properly accounted. However, this change overlooked\nthat:\n\n1. The kernel's allocation functions still enforce INT_MAX as a maximum\n size regardless of memcg accounting\n2. Programs and tests that legitimately test file descriptor limits can\n inadvertently trigger massive allocations\n3. The resulting allocations (>8GB) are impractical and will always fail\n\nsystemd's algorithm starts with INT_MAX and keeps halving the value\nuntil the kernel accepts it. On most systems, this results in nr_open\nbeing set to 1073741816 (0x3ffffff8), which is just under 1GB of file\ndescriptors.\n\nWhile processes rarely use file descriptors near this limit in normal\noperation, certain selftests (like\ntools/testing/selftests/core/unshare_test.c) and programs that test file\ndescriptor limits can trigger this issue.\n\nFix this by adding a check in alloc_fdtable() to ensure the requested\nallocation size does not exceed INT_MAX. This causes the operation to\nfail with -EMFILE instead of triggering a kernel warning and avoids the\nimpractical >8GB memory allocation request.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39756', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39770', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM\n\nWhen performing Generic Segmentation Offload (GSO) on an IPv6 packet that\ncontains extension headers, the kernel incorrectly requests checksum offload\nif the egress device only advertises NETIF_F_IPV6_CSUM feature, which has\na strict contract: it supports checksum offload only for plain TCP or UDP\nover IPv6 and explicitly does not support packets with extension headers.\nThe current GSO logic violates this contract by failing to disable the feature\nfor packets with extension headers, such as those used in GREoIPv6 tunnels.\n\nThis violation results in the device being asked to perform an operation\nit cannot support, leading to a `skb_warn_bad_offload` warning and a collapse\nof network throughput. While device TSO/USO is correctly bypassed in favor\nof software GSO for these packets, the GSO stack must be explicitly told not\nto request checksum offload.\n\nMask NETIF_F_IPV6_CSUM, NETIF_F_TSO6 and NETIF_F_GSO_UDP_L4\nin gso_features_check if the IPv6 header contains extension headers to compute\nchecksum in software.\n\nThe exception is a BIG TCP extension, which, as stated in commit\n68e068cabd2c6c53 ("net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets"):\n"The feature is only enabled on devices that support BIG TCP TSO.\nThe header is only present for PF_PACKET taps like tcpdump,\nand not transmitted by physical devices."\n\nkernel log output (truncated):\nWARNING: CPU: 1 PID: 5273 at net/core/dev.c:3535 skb_warn_bad_offload+0x81/0x140\n...\nCall Trace:\n <TASK>\n skb_checksum_help+0x12a/0x1f0\n validate_xmit_skb+0x1a3/0x2d0\n validate_xmit_skb_list+0x4f/0x80\n sch_direct_xmit+0x1a2/0x380\n __dev_xmit_skb+0x242/0x670\n __dev_queue_xmit+0x3fc/0x7f0\n ip6_finish_output2+0x25e/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_tnl_xmit+0x608/0xc00 [ip6_tunnel]\n ip6gre_tunnel_xmit+0x1c0/0x390 [ip6_gre]\n dev_hard_start_xmit+0x63/0x1c0\n __dev_queue_xmit+0x6d0/0x7f0\n ip6_finish_output2+0x214/0x5d0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n ip6_finish_output+0x1fc/0x3f0\n ip6_xmit+0x2ca/0x6f0\n inet6_csk_xmit+0xeb/0x150\n __tcp_transmit_skb+0x555/0xa80\n tcp_write_xmit+0x32a/0xe90\n tcp_sendmsg_locked+0x437/0x1110\n tcp_sendmsg+0x2f/0x50\n...\nskb linear: 00000000: e4 3d 1a 7d ec 30 e4 3d 1a 7e 5d 90 86 dd 60 0e\nskb linear: 00000010: 00 0a 1b 34 3c 40 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000020: 00 00 00 00 00 12 20 11 00 00 00 00 00 00 00 00\nskb linear: 00000030: 00 00 00 00 00 11 2f 00 04 01 04 01 01 00 00 00\nskb linear: 00000040: 86 dd 60 0e 00 0a 1b 00 06 40 20 23 00 00 00 00\nskb linear: 00000050: 00 00 00 00 00 00 00 00 00 12 20 23 00 00 00 00\nskb linear: 00000060: 00 00 00 00 00 00 00 00 00 11 bf 96 14 51 13 f9\nskb linear: 00000070: ae 27 a0 a8 2b e3 80 18 00 40 5b 6f 00 00 01 01\nskb linear: 00000080: 08 0a 42 d4 50 d5 4b 70 f8 1a', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39770', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39812', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: initialize more fields in sctp_v6_from_sk()\n\nsyzbot found that sin6_scope_id was not properly initialized,\nleading to undefined behavior.\n\nClear sin6_scope_id and sin6_flowinfo.\n\nBUG: KMSAN: uninit-value in __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649\n sctp_inet6_cmp_addr+0x4f2/0x510 net/sctp/ipv6.c:983\n sctp_bind_addr_conflict+0x22a/0x3b0 net/sctp/bind_addr.c:390\n sctp_get_port_local+0x21eb/0x2440 net/sctp/socket.c:8452\n sctp_get_port net/sctp/socket.c:8523 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x710/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930\n x64_sys_call+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls_64.h:51\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable addr.i.i created at:\n sctp_get_port net/sctp/socket.c:8515 [inline]\n sctp_listen_start net/sctp/socket.c:8567 [inline]\n sctp_inet_listen+0x650/0xfd0 net/sctp/socket.c:8636\n __sys_listen_socket net/socket.c:1912 [inline]\n __sys_listen net/socket.c:1927 [inline]\n __do_sys_listen net/socket.c:1932 [inline]\n __se_sys_listen net/socket.c:1930 [inline]\n __x64_sys_listen+0x343/0x4c0 net/socket.c:1930', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39812', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39841', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix buffer free/clear order in deferred receive path\n\nFix a use-after-free window by correcting the buffer release sequence in\nthe deferred receive path. The code freed the RQ buffer first and only\nthen cleared the context pointer under the lock. Concurrent paths (e.g.,\nABTS and the repost path) also inspect and release the same pointer under\nthe lock, so the old order could lead to double-free/UAF.\n\nNote that the repost path already uses the correct pattern: detach the\npointer under the lock, then free it after dropping the lock. The\ndeferred path should do the same.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39841', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39894', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm\n\nWhen send a broadcast packet to a tap device, which was added to a bridge,\nbr_nf_local_in() is called to confirm the conntrack. If another conntrack\nwith the same hash value is added to the hash table, which can be\ntriggered by a normal packet to a non-bridge device, the below warning\nmay happen.\n\n ------------[ cut here ]------------\n WARNING: CPU: 1 PID: 96 at net/bridge/br_netfilter_hooks.c:632 br_nf_local_in+0x168/0x200\n CPU: 1 UID: 0 PID: 96 Comm: tap_send Not tainted 6.17.0-rc2-dirty #44 PREEMPT(voluntary)\n RIP: 0010:br_nf_local_in+0x168/0x200\n Call Trace:\n <TASK>\n nf_hook_slow+0x3e/0xf0\n br_pass_frame_up+0x103/0x180\n br_handle_frame_finish+0x2de/0x5b0\n br_nf_hook_thresh+0xc0/0x120\n br_nf_pre_routing_finish+0x168/0x3a0\n br_nf_pre_routing+0x237/0x5e0\n br_handle_frame+0x1ec/0x3c0\n __netif_receive_skb_core+0x225/0x1210\n __netif_receive_skb_one_core+0x37/0xa0\n netif_receive_skb+0x36/0x160\n tun_get_user+0xa54/0x10c0\n tun_chr_write_iter+0x65/0xb0\n vfs_write+0x305/0x410\n ksys_write+0x60/0xd0\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n ---[ end trace 0000000000000000 ]---\n\nTo solve the hash conflict, nf_ct_resolve_clash() try to merge the\nconntracks, and update skb->_nfct. However, br_nf_local_in() still use the\nold ct from local variable 'nfct' after confirm(), which leads to this\nwarning.\n\nIf confirm() does not insert the conntrack entry and return NF_DROP, the\nwarning may also occur. There is no need to reserve the WARN_ON_ONCE, just\nremove it.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39894', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39937', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer\n\nSince commit 7d5e9737efda ("net: rfkill: gpio: get the name and type from\ndevice property") rfkill_find_type() gets called with the possibly\nuninitialized "const char *type_name;" local variable.\n\nOn x86 systems when rfkill-gpio binds to a "BCM4752" or "LNV4752"\nacpi_device, the rfkill->type is set based on the ACPI acpi_device_id:\n\n rfkill->type = (unsigned)id->driver_data;\n\nand there is no "type" property so device_property_read_string() will fail\nand leave type_name uninitialized, leading to a potential crash.\n\nrfkill_find_type() does accept a NULL pointer, fix the potential crash\nby initializing type_name to NULL.\n\nNote likely sofar this has not been caught because:\n\n1. Not many x86 machines actually have a "BCM4752"/"LNV4752" acpi_device\n2. The stack happened to contain NULL where type_name is stored', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39937', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39955', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().\n\nsyzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk\nin the TCP_ESTABLISHED state. [0]\n\nsyzbot reused the server-side TCP Fast Open socket as a new client before\nthe TFO socket completes 3WHS:\n\n 1. accept()\n 2. connect(AF_UNSPEC)\n 3. connect() to another destination\n\nAs of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes\nit to TCP_CLOSE and makes connect() possible, which restarts timers.\n\nSince tcp_disconnect() forgot to clear tcp_sk(sk)->fastopen_rsk, the\nretransmit timer triggered the warning and the intended packet was not\nretransmitted.\n\nLet's call reqsk_fastopen_remove() in tcp_disconnect().\n\n[0]:\nWARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nModules linked in:\nCPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))\nCode: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 <0f> 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e\nRSP: 0018:ffffc900002f8d40 EFLAGS: 00010293\nRAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017\nRDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400\nRBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8\nR10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540\nR13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0\nFS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0\nCall Trace:\n <IRQ>\n tcp_write_timer (net/ipv4/tcp_timer.c:738)\n call_timer_fn (kernel/time/timer.c:1747)\n __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2372)\n timer_expire_remote (kernel/time/timer.c:2385 kernel/time/timer.c:2376 kernel/time/timer.c:2135)\n tmigr_handle_remote_up (kernel/time/timer_migration.c:944 kernel/time/timer_migration.c:1035)\n __walk_groups.isra.0 (kernel/time/timer_migration.c:533 (discriminator 1))\n tmigr_handle_remote (kernel/time/timer_migration.c:1096)\n handle_softirqs (./arch/x86/include/asm/jump_label.h:36 ./include/trace/events/irq.h:142 kernel/softirq.c:580)\n irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680 kernel/softirq.c:696)\n sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 (discriminator 35) arch/x86/kernel/apic/apic.c:1050 (discriminator 35))\n </IRQ>", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39955', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-39980', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Forbid FDB status change while nexthop is in a group\n\nThe kernel forbids the creation of non-FDB nexthop groups with FDB\nnexthops:\n\n # ip nexthop add id 1 via 192.0.2.1 fdb\n # ip nexthop add id 2 group 1\n Error: Non FDB nexthop group cannot have fdb nexthops.\n\nAnd vice versa:\n\n # ip nexthop add id 3 via 192.0.2.2 dev dummy1\n # ip nexthop add id 4 group 3 fdb\n Error: FDB nexthop group can only have fdb nexthops.\n\nHowever, as long as no routes are pointing to a non-FDB nexthop group,\nthe kernel allows changing the type of a nexthop from FDB to non-FDB and\nvice versa:\n\n # ip nexthop add id 5 via 192.0.2.2 dev dummy1\n # ip nexthop add id 6 group 5\n # ip nexthop replace id 5 via 192.0.2.2 fdb\n # echo $?\n 0\n\nThis configuration is invalid and can result in a NPD [1] since FDB\nnexthops are not associated with a nexthop device:\n\n # ip route add 198.51.100.1/32 nhid 6\n # ping 198.51.100.1\n\nFix by preventing nexthop FDB status change while the nexthop is in a\ngroup:\n\n # ip nexthop add id 7 via 192.0.2.2 dev dummy1\n # ip nexthop add id 8 group 7\n # ip nexthop replace id 7 via 192.0.2.2 fdb\n Error: Cannot change nexthop FDB status while in a group.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 00000000000003c0\n[...]\nOops: Oops: 0000 [#1] SMP\nCPU: 6 UID: 0 PID: 367 Comm: ping Not tainted 6.17.0-rc6-virtme-gb65678cacc03 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\nRIP: 0010:fib_lookup_good_nhc+0x1e/0x80\n[...]\nCall Trace:\n <TASK>\n fib_table_lookup+0x541/0x650\n ip_route_output_key_hash_rcu+0x2ea/0x970\n ip_route_output_key_hash+0x55/0x80\n __ip4_datagram_connect+0x250/0x330\n udp_connect+0x2b/0x60\n __sys_connect+0x9c/0xd0\n __x64_sys_connect+0x18/0x20\n do_syscall_64+0xa4/0x2a0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-39980', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40018', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: Defer ip_vs_ftp unregister during netns cleanup\n\nOn the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp\nbefore connections with valid cp->app pointers are flushed, leading to a\nuse-after-free.\n\nFix this by introducing a global `exiting_module` flag, set to true in\nip_vs_ftp_exit() before unregistering the pernet subsystem. In\n__ip_vs_ftp_exit(), skip ip_vs_ftp unregister if called during netns\ncleanup (when exiting_module is false) and defer it to\n__ip_vs_cleanup_batch(), which unregisters all apps after all connections\nare flushed. If called during module exit, unregister ip_vs_ftp\nimmediately.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40018', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40062', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs\n\nWhen the initialization of qm->debug.acc_diff_reg fails,\nthe probe process does not exit. However, after qm->debug.qm_diff_regs is\nfreed, it is not set to NULL. This can lead to a double free when the\nremove process attempts to free it again. Therefore, qm->debug.qm_diff_regs\nshould be set to NULL after it is freed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40062', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40078', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n 0: r0 = 0\n 1: r2 = *(u32 *)(r1 +60)\n 2: exit\n\nwhich triggers:\n\n verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn't rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn't find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40078', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40136', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - request reserved interrupt for virtual function\n\nThe device interrupt vector 3 is an error interrupt for\nphysical function and a reserved interrupt for virtual function.\nHowever, the driver has not registered the reserved interrupt for\nvirtual function. When allocating interrupts, the number of interrupts\nis allocated based on powers of two, which includes this interrupt.\nWhen the system enables GICv4 and the virtual function passthrough\nto the virtual machine, releasing the interrupt in the driver\ntriggers a warning.\n\nThe WARNING report is:\nWARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4\n\nTherefore, register a reserved interrupt for VF and set the\nIRQF_NO_AUTOEN flag to avoid that warning.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40136', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40240', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid NULL dereference when chunk data buffer is missing\n\nchunk->skb pointer is dereferenced in the if-block where it's supposed\nto be NULL only.\n\nchunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list\ninstead and do it just before replacing chunk->skb. We're sure that\notherwise chunk->skb is non-NULL because of outer if() condition.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40240', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40254', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: remove never-working support for setting nsh fields\n\nThe validation of the set(nsh(...)) action is completely wrong.\nIt runs through the nsh_key_put_from_nlattr() function that is the\nsame function that validates NSH keys for the flow match and the\npush_nsh() action. However, the set(nsh(...)) has a very different\nmemory layout. Nested attributes in there are doubled in size in\ncase of the masked set(). That makes proper validation impossible.\n\nThere is also confusion in the code between the 'masked' flag, that\nsays that the nested attributes are doubled in size containing both\nthe value and the mask, and the 'is_mask' that says that the value\nwe're parsing is the mask. This is causing kernel crash on trying to\nwrite into mask part of the match with SW_FLOW_KEY_PUT() during\nvalidation, while validate_nsh() doesn't allocate any memory for it:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000018\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0\n Oops: Oops: 0000 [#1] SMP NOPTI\n CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary)\n RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch]\n Call Trace:\n <TASK>\n validate_nsh+0x60/0x90 [openvswitch]\n validate_set.constprop.0+0x270/0x3c0 [openvswitch]\n __ovs_nla_copy_actions+0x477/0x860 [openvswitch]\n ovs_nla_copy_actions+0x8d/0x100 [openvswitch]\n ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch]\n genl_family_rcv_msg_doit+0xdb/0x130\n genl_family_rcv_msg+0x14b/0x220\n genl_rcv_msg+0x47/0xa0\n netlink_rcv_skb+0x53/0x100\n genl_rcv+0x24/0x40\n netlink_unicast+0x280/0x3b0\n netlink_sendmsg+0x1f7/0x430\n ____sys_sendmsg+0x36b/0x3a0\n ___sys_sendmsg+0x87/0xd0\n __sys_sendmsg+0x6d/0xd0\n do_syscall_64+0x7b/0x2c0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe third issue with this process is that while trying to convert\nthe non-masked set into masked one, validate_set() copies and doubles\nthe size of the OVS_KEY_ATTR_NSH as if it didn't have any nested\nattributes. It should be copying each nested attribute and doubling\nthem in size independently. And the process must be properly reversed\nduring the conversion back from masked to a non-masked variant during\nthe flow dump.\n\nIn the end, the only two outcomes of trying to use this action are\neither validation failure or a kernel crash. And if somehow someone\nmanages to install a flow with such an action, it will most definitely\nnot do what it is supposed to, since all the keys and the masks are\nmixed up.\n\nFixing all the issues is a complex task as it requires re-writing\nmost of the validation code.\n\nGiven that and the fact that this functionality never worked since\nintroduction, let's just remove it altogether. It's better to\nre-introduce it later with a proper implementation instead of trying\nto fix it in stable releases.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40254', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40280', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Fix use-after-free in tipc_mon_reinit_self().\n\nsyzbot reported use-after-free of tipc_net(net)->monitors[]\nin tipc_mon_reinit_self(). [0]\n\nThe array is protected by RTNL, but tipc_mon_reinit_self()\niterates over it without RTNL.\n\ntipc_mon_reinit_self() is called from tipc_net_finalize(),\nwhich is always under RTNL except for tipc_net_finalize_work().\n\nLet's hold RTNL in tipc_net_finalize_work().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\nBUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\nRead of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989\n\nCPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)}\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025\nWorkqueue: events tipc_net_finalize_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568\n kasan_check_byte include/linux/kasan.h:399 [inline]\n lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162\n rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline]\n rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline]\n rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244\n rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243\n write_lock_bh include/linux/rwlock_rt.h:99 [inline]\n tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718\n tipc_net_finalize+0x115/0x190 net/tipc/net.c:140\n process_one_work kernel/workqueue.c:3236 [inline]\n process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319\n worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400\n kthread+0x70e/0x8a0 kernel/kthread.c:463\n ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>\n\nAllocated by task 6089:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:388 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407\n kmalloc_noprof include/linux/slab.h:905 [inline]\n kzalloc_noprof include/linux/slab.h:1039 [inline]\n tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657\n tipc_enable_bearer net/tipc/bearer.c:357 [inline]\n __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047\n __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline]\n tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393\n tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline]\n tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321\n genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]\n netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346\n netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896\n sock_sendmsg_nosec net/socket.c:714 [inline]\n __sock_sendmsg+0x21c/0x270 net/socket.c:729\n ____sys_sendmsg+0x508/0x820 net/socket.c:2614\n ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668\n __sys_sendmsg net/socket.c:2700 [inline]\n __do_sys_sendmsg net/socket.c:2705 [inline]\n __se_sys_sendmsg net/socket.c:2703 [inline]\n __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40280', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40281', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto\n\nsyzbot reported a possible shift-out-of-bounds [1]\n\nBlamed commit added rto_alpha_max and rto_beta_max set to 1000.\n\nIt is unclear if some sctp users are setting very large rto_alpha\nand/or rto_beta.\n\nIn order to prevent user regression, perform the test at run time.\n\nAlso add READ_ONCE() annotations as sysctl values can change under us.\n\n[1]\n\nUBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41\nshift exponent 64 is too large for 32-bit type 'unsigned int'\nCPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120\n ubsan_epilogue lib/ubsan.c:233 [inline]\n __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494\n sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509\n sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502\n sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338\n sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline]\n sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40281', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-40331', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Prevent TOCTOU out-of-bounds write\n\nFor the following path not holding the sock lock,\n\n sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump()\n\nmake sure not to exceed bounds in case the address list has grown\nbetween buffer allocation (time-of-check) and write (time-of-use).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40331', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68283', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: replace BUG_ON with bounds check for map->max_osd\n\nOSD indexes come from untrusted network packets. Boundary checks are\nadded to validate these against map->max_osd.\n\n[ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic\n edits ]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68283', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68284', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()\n\nThe len field originates from untrusted network packets. Boundary\nchecks have been added to prevent potential out-of-bounds writes when\ndecrypting the connection secret or processing service tickets.\n\n[ idryomov: changelog ]', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68284', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68285', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix potential use-after-free in have_mon_and_osd_map()\n\nThe wait loop in __ceph_open_session() can race with the client\nreceiving a new monmap or osdmap shortly after the initial map is\nreceived. Both ceph_monc_handle_map() and handle_one_map() install\na new map immediately after freeing the old one\n\n kfree(monc->monmap);\n monc->monmap = monmap;\n\n ceph_osdmap_destroy(osdc->osdmap);\n osdc->osdmap = newmap;\n\nunder client->monc.mutex and client->osdc.lock respectively, but\nbecause neither is taken in have_mon_and_osd_map() it's possible for\nclient->monc.monmap->epoch and client->osdc.osdmap->epoch arms in\n\n client->monc.monmap && client->monc.monmap->epoch &&\n client->osdc.osdmap && client->osdc.osdmap->epoch;\n\ncondition to dereference an already freed map. This happens to be\nreproducible with generic/395 and generic/397 with KASAN enabled:\n\n BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70\n Read of size 4 at addr ffff88811012d810 by task mount.ceph/13305\n CPU: 2 UID: 0 PID: 13305 Comm: mount.ceph Not tainted 6.14.0-rc2-build2+ #1266\n ...\n Call Trace:\n <TASK>\n have_mon_and_osd_map+0x56/0x70\n ceph_open_session+0x182/0x290\n ceph_get_tree+0x333/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n </TASK>\n\n Allocated by task 13305:\n ceph_osdmap_alloc+0x16/0x130\n ceph_osdc_init+0x27a/0x4c0\n ceph_create_client+0x153/0x190\n create_fs_client+0x50/0x2a0\n ceph_get_tree+0xff/0x680\n vfs_get_tree+0x49/0x180\n do_new_mount+0x1a3/0x2d0\n path_mount+0x6dd/0x730\n do_mount+0x99/0xe0\n __do_sys_mount+0x141/0x180\n do_syscall_64+0x9f/0x100\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 9475:\n kfree+0x212/0x290\n handle_one_map+0x23c/0x3b0\n ceph_osdc_handle_map+0x3c9/0x590\n mon_dispatch+0x655/0x6f0\n ceph_con_process_message+0xc3/0xe0\n ceph_con_v1_try_read+0x614/0x760\n ceph_con_workfn+0x2de/0x650\n process_one_work+0x486/0x7c0\n process_scheduled_works+0x73/0x90\n worker_thread+0x1c8/0x2a0\n kthread+0x2ec/0x300\n ret_from_fork+0x24/0x40\n ret_from_fork_asm+0x1a/0x30\n\nRewrite the wait loop to check the above condition directly with\nclient->monc.mutex and client->osdc.lock taken as appropriate. While\nat it, improve the timeout handling (previously mount_timeout could be\nexceeded in case wait_event_interruptible_timeout() slept more than\nonce) and access client->auth_err under client->monc.mutex to match\nhow it's set in finish_auth().\n\nmonmap_show() and osdmap_show() now take the respective lock before\naccessing the map as well.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68285', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68304', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: lookup hci_conn on RX path on protocol side\n\nThe hdev lock/lookup/unlock/use pattern in the packet RX path doesn\'t\nensure hci_conn* is not concurrently modified/deleted. This locking\nappears to be leftover from before conn_hash started using RCU\ncommit bf4c63252490b ("Bluetooth: convert conn hash to RCU")\nand not clear if it had purpose since then.\n\nCurrently, there are code paths that delete hci_conn* from elsewhere\nthan the ordered hdev->workqueue where the RX work runs in. E.g.\ncommit 5af1f84ed13a ("Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync")\nintroduced some of these, and there probably were a few others before\nit. It\'s better to do the locking so that even if these run\nconcurrently no UAF is possible.\n\nMove the lookup of hci_conn and associated socket-specific conn to\nprotocol recv handlers, and do them within a single critical section\nto cover hci_conn* usage and lookup.\n\nsyzkaller has reported a crash that appears to be this issue:\n\n [Task hdev->workqueue] [Task 2]\n hci_disconnect_all_sync\n l2cap_recv_acldata(hcon)\n hci_conn_get(hcon)\n hci_abort_conn_sync(hcon)\n hci_dev_lock\n hci_dev_lock\n hci_conn_del(hcon)\n v-------------------------------- hci_dev_unlock\n hci_conn_put(hcon)\n conn = hcon->l2cap_data (UAF)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68304', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68740', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nima: Handle error code returned by ima_filter_rule_match()\n\nIn ima_match_rules(), if ima_filter_rule_match() returns -ENOENT due to\nthe rule being NULL, the function incorrectly skips the 'if (!rc)' check\nand sets 'result = true'. The LSM rule is considered a match, causing\nextra files to be measured by IMA.\n\nThis issue can be reproduced in the following scenario:\nAfter unloading the SELinux policy module via 'semodule -d', if an IMA\nmeasurement is triggered before ima_lsm_rules is updated,\nin ima_match_rules(), the first call to ima_filter_rule_match() returns\n-ESTALE. This causes the code to enter the 'if (rc == -ESTALE &&\n!rule_reinitialized)' block, perform ima_lsm_copy_rule() and retry. In\nima_lsm_copy_rule(), since the SELinux module has been removed, the rule\nbecomes NULL, and the second call to ima_filter_rule_match() returns\n-ENOENT. This bypasses the 'if (!rc)' check and results in a false match.\n\nCall trace:\n selinux_audit_rule_match+0x310/0x3b8\n security_audit_rule_match+0x60/0xa0\n ima_match_rules+0x2e4/0x4a0\n ima_match_policy+0x9c/0x1e8\n ima_get_action+0x48/0x60\n process_measurement+0xf8/0xa98\n ima_bprm_check+0x98/0xd8\n security_bprm_check+0x5c/0x78\n search_binary_handler+0x6c/0x318\n exec_binprm+0x58/0x1b8\n bprm_execve+0xb8/0x130\n do_execveat_common.isra.0+0x1a8/0x258\n __arm64_sys_execve+0x48/0x68\n invoke_syscall+0x50/0x128\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x44/0x200\n el0t_64_sync_handler+0x100/0x130\n el0t_64_sync+0x3c8/0x3d0\n\nFix this by changing 'if (!rc)' to 'if (rc <= 0)' to ensure that error\ncodes like -ENOENT do not bypass the check and accidentally result in a\nsuccessful match.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68740', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68742', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix invalid prog->stats access when update_effective_progs fails\n\nSyzkaller triggers an invalid memory access issue following fault\ninjection in update_effective_progs. The issue can be described as\nfollows:\n\n__cgroup_bpf_detach\n update_effective_progs\n compute_effective_progs\n bpf_prog_array_alloc <-- fault inject\n purge_effective_progs\n /* change to dummy_bpf_prog */\n array->items[index] = &dummy_bpf_prog.prog\n\n---softirq start---\n__do_softirq\n ...\n __cgroup_bpf_run_filter_skb\n __bpf_prog_run_save_cb\n bpf_prog_run\n stats = this_cpu_ptr(prog->stats)\n /* invalid memory access */\n flags = u64_stats_update_begin_irqsave(&stats->syncp)\n---softirq end---\n\n static_branch_dec(&cgroup_bpf_enabled_key[atype])\n\nThe reason is that fault injection caused update_effective_progs to fail\nand then changed the original prog into dummy_bpf_prog.prog in\npurge_effective_progs. Then a softirq came, and accessing the members of\ndummy_bpf_prog.prog in the softirq triggers invalid mem access.\n\nTo fix it, skip updating stats when stats is NULL.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68742', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68795', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: Avoid overflowing userspace buffer on stats query\n\nThe ethtool -S command operates across three ioctl calls:\nETHTOOL_GSSET_INFO for the size, ETHTOOL_GSTRINGS for the names, and\nETHTOOL_GSTATS for the values.\n\nIf the number of stats changes between these calls (e.g., due to device\nreconfiguration), userspace\'s buffer allocation will be incorrect,\npotentially leading to buffer overflow.\n\nDrivers are generally expected to maintain stable stat counts, but some\ndrivers (e.g., mlx5, bnx2x, bna, ksz884x) use dynamic counters, making\nthis scenario possible.\n\nSome drivers try to handle this internally:\n- bnad_get_ethtool_stats() returns early in case stats.n_stats is not\n equal to the driver\'s stats count.\n- micrel/ksz884x also makes sure not to write anything beyond\n stats.n_stats and overflow the buffer.\n\nHowever, both use stats.n_stats which is already assigned with the value\nreturned from get_sset_count(), hence won\'t solve the issue described\nhere.\n\nChange ethtool_get_strings(), ethtool_get_stats(),\nethtool_get_phy_stats() to not return anything in case of a mismatch\nbetween userspace\'s size and get_sset_size(), to prevent buffer\noverflow.\nThe returned n_stats value will be equal to zero, to reflect that\nnothing has been returned.\n\nThis could result in one of two cases when using upstream ethtool,\ndepending on when the size change is detected:\n1. When detected in ethtool_get_strings():\n # ethtool -S eth2\n no stats available\n\n2. When detected in get stats, all stats will be reported as zero.\n\nBoth cases are presumably transient, and a subsequent ethtool call\nshould succeed.\n\nOther than the overflow avoidance, these two cases are very evident (no\noutput/cleared stats), which is arguably better than presenting\nincorrect/shifted stats.\nI also considered returning an error instead of a "silent" response, but\nthat seems more destructive towards userspace apps.\n\nNotes:\n- This patch does not claim to fix the inherent race, it only makes sure\n that we do not overflow the userspace buffer, and makes for a more\n predictable behavior.\n\n- RTNL lock is held during each ioctl, the race window exists between\n the separate ioctl calls when the lock is released.\n\n- Userspace ethtool always fills stats.n_stats, but it is likely that\n these stats ioctls are implemented in other userspace applications\n which might not fill it. The added code checks that it\'s not zero,\n to prevent any regressions.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68795', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-68820', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: xattr: fix null pointer deref in ext4_raw_inode()\n\nIf ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),\niloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()\nlacks error checking, this will lead to a null pointer dereference\nin ext4_raw_inode(), called right after ext4_get_inode_loc().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-68820', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2025-71064', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-71064', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-22976', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset\n\n`qfq_class->leaf_qdisc->q.qlen > 0` does not imply that the class\nitself is active.\n\nTwo qfq_class objects may point to the same leaf_qdisc. This happens\nwhen:\n\n1. one QFQ qdisc is attached to the dev as the root qdisc, and\n\n2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get()\n/ qdisc_put()) and is pending to be destroyed, as in function\ntc_new_tfilter.\n\nWhen packets are enqueued through the root QFQ qdisc, the shared\nleaf_qdisc->q.qlen increases. At the same time, the second QFQ\nqdisc triggers qdisc_put and qdisc_destroy: the qdisc enters\nqfq_reset() with its own q->q.qlen == 0, but its class's leaf\nqdisc->q.qlen > 0. Therefore, the qfq_reset would wrongly deactivate\nan inactive aggregate and trigger a null-deref in qfq_deactivate_agg:\n\n[ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 0.903571] #PF: supervisor write access in kernel mode\n[ 0.903860] #PF: error_code(0x0002) - not-present page\n[ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0\n[ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI\n[ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE\n[ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2))\n[ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0\n\nCode starting with the faulting instruction\n===========================================\n 0:\t0f 84 4d 01 00 00 \tje 0x153\n 6:\t48 89 70 18 \tmov %rsi,0x18(%rax)\n a:\t8b 4b 10 \tmov 0x10(%rbx),%ecx\n d:\t48 c7 c2 ff ff ff ff \tmov $0xffffffffffffffff,%rdx\n 14:\t48 8b 78 08 \tmov 0x8(%rax),%rdi\n 18:\t48 d3 e2 \tshl %cl,%rdx\n 1b:\t48 21 f2 \tand %rsi,%rdx\n 1e:\t48 2b 13 \tsub (%rbx),%rdx\n 21:\t48 8b 30 \tmov (%rax),%rsi\n 24:\t48 d3 ea \tshr %cl,%rdx\n 27:\t8b 4b 18 \tmov 0x18(%rbx),%ecx\n\t...\n[ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246\n[ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000\n[ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000\n[ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000\n[ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880\n[ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000\n[ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0\n[ 0.910247] PKRU: 55555554\n[ 0.910391] Call Trace:\n[ 0.910527] <TASK>\n[ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485)\n[ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036)\n[ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076)\n[ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447)\n[ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\n[ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861)\n[ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550)\n[ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\n[ 0.912296] ? __alloc_skb (net/core/skbuff.c:706)\n[ 0.912484] netlink_sendmsg (net/netlink/af\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-22976', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-22994', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix reference count leak in bpf_prog_test_run_xdp()\n\nsyzbot is reporting\n\n unregister_netdevice: waiting for sit0 to become free. Usage count = 2\n\nproblem. A debug printk() patch found that a refcount is obtained at\nxdp_convert_md_to_buff() from bpf_prog_test_run_xdp().\n\nAccording to commit ec94670fcb3b ("bpf: Support specifying ingress via\nxdp_md context in BPF_PROG_TEST_RUN"), the refcount obtained by\nxdp_convert_md_to_buff() will be released by xdp_convert_buff_to_md().\n\nTherefore, we can consider that the error handling path introduced by\ncommit 1c1949982524 ("bpf: introduce frags support to\nbpf_prog_test_run_xdp()") forgot to call xdp_convert_buff_to_md().', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-22994', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23053', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a deadlock involving nfs_release_folio()\n\nWang Zhaolong reports a deadlock involving NFSv4.1 state recovery\nwaiting on kthreadd, which is attempting to reclaim memory by calling\nnfs_release_folio(). The latter cannot make progress due to state\nrecovery being needed.\n\nIt seems that the only safe thing to do here is to kick off a writeback\nof the folio, without waiting for completion, or else kicking off an\nasynchronous commit.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23053', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23253', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen\n\ndvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the\nDVR device. dvb_ringbuffer_init() calls init_waitqueue_head(), which\nreinitializes the waitqueue list head to empty.\n\nSince dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the\nsame DVR device share it), this orphans any existing waitqueue entries\nfrom io_uring poll or epoll, leaving them with stale prev/next pointers\nwhile the list head is reset to {self, self}.\n\nThe waitqueue and spinlock in dvr_buffer are already properly\ninitialized once in dvb_dmxdev_init(). The open path only needs to\nreset the buffer data pointer, size, and read/write positions.\n\nReplace the dvb_ringbuffer_init() call in dvb_dvr_open() with direct\nassignment of data/size and a call to dvb_ringbuffer_reset(), which\nproperly resets pread, pwrite, and error with correct memory ordering\nwithout touching the waitqueue or spinlock.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23253', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23260', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: maple: free entry on mas_store_gfp() failure\n\nregcache_maple_write() allocates a new block ('entry') to merge\nadjacent ranges and then stores it with mas_store_gfp().\nWhen mas_store_gfp() fails, the new 'entry' remains allocated and\nis never freed, leaking memory.\n\nFree 'entry' on the failure path; on success continue freeing the\nreplaced neighbor blocks ('lower', 'upper').", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23260', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23268', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix unprivileged local user can do privileged policy management\n\nAn unprivileged local user can load, replace, and remove profiles by\nopening the apparmorfs interfaces, via a confused deputy attack, by\npassing the opened fd to a privileged process, and getting the\nprivileged process to write to the interface.\n\nThis does require a privileged target that can be manipulated to do\nthe write for the unprivileged process, but once such access is\nachieved full policy management is possible and all the possible\nimplications that implies: removing confinement, DoS of system or\ntarget applications by denying all execution, by-passing the\nunprivileged user namespace restriction, to exploiting kernel bugs for\na local privilege escalation.\n\nThe policy management interface can not have its permissions simply\nchanged from 0666 to 0600 because non-root processes need to be able\nto load policy to different policy namespaces.\n\nInstead ensure the task writing the interface has privileges that\nare a subset of the task that opened the interface. This is already\ndone via policy for confined processes, but unconfined can delegate\naccess to the opened fd, by-passing the usual policy check.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23268', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23271', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix __perf_event_overflow() vs perf_remove_from_context() race\n\nMake sure that __perf_event_overflow() runs with IRQs disabled for all\npossible callchains. Specifically the software events can end up running\nit with only preemption disabled.\n\nThis opens up a race vs perf_event_exit_event() and friends that will go\nand free various things the overflow path expects to be present, like\nthe BPF program.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23271', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23273', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: observe an RCU grace period in macvlan_common_newlink() error path\n\nvalis reported that a race condition still happens after my prior patch.\n\nmacvlan_common_newlink() might have made @dev visible before\ndetecting an error, and its caller will directly call free_netdev(dev).\n\nWe must respect an RCU period, either in macvlan or the core networking\nstack.\n\nAfter adding a temporary mdelay(1000) in macvlan_forward_source_one()\nto open the race window, valis repro was:\n\nip link add p1 type veth peer p2\nip link set address 00:00:00:00:00:20 dev p1\nip link set up dev p1\nip link set up dev p2\nip link add mv0 link p2 type macvlan mode source\n\n(ip link add invalid% link p2 type macvlan mode source macaddr add\n00:00:00:00:00:20 &) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4\nPING 1.2.3.4 (1.2.3.4): 56 data bytes\nRTNETLINK answers: Invalid argument\n\nBUG: KASAN: slab-use-after-free in macvlan_forward_source\n(drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nRead of size 8 at addr ffff888016bb89c0 by task e/175\n\nCPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n<IRQ>\ndump_stack_lvl (lib/dump_stack.c:123)\nprint_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nkasan_report (mm/kasan/report.c:597)\n? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\nmacvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444)\n? tasklet_init (kernel/softirq.c:983)\nmacvlan_handle_frame (drivers/net/macvlan.c:501)\n\nAllocated by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\n__kasan_kmalloc (mm/kasan/common.c:419)\n__kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657\nmm/slub.c:7140)\nalloc_netdev_mqs (net/core/dev.c:12012)\nrtnl_create_link (net/core/rtnetlink.c:3648)\nrtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)\n\nFreed by task 169:\nkasan_save_stack (mm/kasan/common.c:58)\nkasan_save_track (./arch/x86/include/asm/current.h:25\nmm/kasan/common.c:70 mm/kasan/common.c:79)\nkasan_save_free_info (mm/kasan/generic.c:587)\n__kasan_slab_free (mm/kasan/common.c:287)\nkfree (mm/slub.c:6674 mm/slub.c:6882)\nrtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957\nnet/core/rtnetlink.c:4072)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:6958)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206)\n__x64_sys_sendto (net/socket.c:2209)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23273', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23292', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix recursive locking in __configfs_open_file()\n\nIn flush_write_buffer, &p->frag_sem is acquired and then the loaded store\nfunction is called, which, here, is target_core_item_dbroot_store(). This\nfunction called filp_open(), following which these functions were called\n(in reverse order), according to the call trace:\n\n down_read\n __configfs_open_file\n do_dentry_open\n vfs_open\n do_open\n path_openat\n do_filp_open\n file_open_name\n filp_open\n target_core_item_dbroot_store\n flush_write_buffer\n configfs_write_iter\n\ntarget_core_item_dbroot_store() tries to validate the new file path by\ntrying to open the file path provided to it; however, in this case, the bug\nreport shows:\n\ndb_root: not a directory: /sys/kernel/config/target/dbroot\n\nindicating that the same configfs file was tried to be opened, on which it\nis currently working on. Thus, it is trying to acquire frag_sem semaphore\nof the same file of which it already holds the semaphore obtained in\nflush_write_buffer(), leading to acquiring the semaphore in a nested manner\nand a possibility of recursive locking.\n\nFix this by modifying target_core_item_dbroot_store() to use kern_path()\ninstead of filp_open() to avoid opening the file using filesystem-specific\nfunction __configfs_open_file(), and further modifying it to make this fix\ncompatible.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23292', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23296', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Fix refcount leak for tagset_refcnt\n\nThis leak will cause a hang when tearing down the SCSI host. For example,\niscsid hangs with the following call trace:\n\n[130120.652718] scsi_alloc_sdev: Allocation failure during SCSI scanning, some SCSI devices might not be configured\n\nPID: 2528 TASK: ffff9d0408974e00 CPU: 3 COMMAND: "iscsid"\n #0 [ffffb5b9c134b9e0] __schedule at ffffffff860657d4\n #1 [ffffb5b9c134ba28] schedule at ffffffff86065c6f\n #2 [ffffb5b9c134ba40] schedule_timeout at ffffffff86069fb0\n #3 [ffffb5b9c134bab0] __wait_for_common at ffffffff8606674f\n #4 [ffffb5b9c134bb10] scsi_remove_host at ffffffff85bfe84b\n #5 [ffffb5b9c134bb30] iscsi_sw_tcp_session_destroy at ffffffffc03031c4 [iscsi_tcp]\n #6 [ffffb5b9c134bb48] iscsi_if_recv_msg at ffffffffc0292692 [scsi_transport_iscsi]\n #7 [ffffb5b9c134bb98] iscsi_if_rx at ffffffffc02929c2 [scsi_transport_iscsi]\n #8 [ffffb5b9c134bbf0] netlink_unicast at ffffffff85e551d6\n #9 [ffffb5b9c134bc38] netlink_sendmsg at ffffffff85e554ef', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23296', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23313', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix preempt count leak in napi poll tracepoint\n\nUsing get_cpu() in the tracepoint assignment causes an obvious preempt\ncount leak because nothing invokes put_cpu() to undo it:\n\n softirq: huh, entered softirq 3 NET_RX with preempt_count 00000100, exited with 00000101?\n\nThis clearly has seen a lot of testing in the last 3+ years...\n\nUse smp_processor_id() instead.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23313', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23317', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Return the correct value in vmw_translate_ptr functions\n\nBefore the referenced fixes these functions used a lookup function that\nreturned a pointer. This was changed to another lookup function that\nreturned an error code with the pointer becoming an out parameter.\n\nThe error path when the lookup failed was not changed to reflect this\nchange and the code continued to return the PTR_ERR of the now\nuninitialized pointer. This could cause the vmw_translate_ptr functions\nto return success when they actually failed causing further uninitialized\nand OOB accesses.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23317', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23319', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim\n\nThe root cause of this bug is that when 'bpf_link_put' reduces the\nrefcount of 'shim_link->link.link' to zero, the resource is considered\nreleased but may still be referenced via 'tr->progs_hlist' in\n'cgroup_shim_find'. The actual cleanup of 'tr->progs_hlist' in\n'bpf_shim_tramp_link_release' is deferred. During this window, another\nprocess can cause a use-after-free via 'bpf_trampoline_link_cgroup_shim'.\n\nBased on Martin KaFai Lau's suggestions, I have created a simple patch.\n\nTo fix this:\n Add an atomic non-zero check in 'bpf_trampoline_link_cgroup_shim'.\n Only increment the refcount if it is not already zero.\n\nTesting:\n I verified the fix by adding a delay in\n 'bpf_shim_tramp_link_release' to make the bug easier to trigger:\n\nstatic void bpf_shim_tramp_link_release(struct bpf_link *link)\n{\n\t/* ... */\n\tif (!shim_link->trampoline)\n\t\treturn;\n\n+\tmsleep(100);\n\tWARN_ON_ONCE(bpf_trampoline_unlink_prog(&shim_link->link,\n\t\tshim_link->trampoline, NULL));\n\tbpf_trampoline_put(shim_link->trampoline);\n}\n\nBefore the patch, running a PoC easily reproduced the crash(almost 100%)\nwith a call trace similar to KaiyanM's report.\nAfter the patch, the bug no longer occurs even after millions of\niterations.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23319', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23352', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/efi: defer freeing of boot services memory\n\nefi_free_boot_services() frees memory occupied by EFI_BOOT_SERVICES_CODE\nand EFI_BOOT_SERVICES_DATA using memblock_free_late().\n\nThere are two issue with that: memblock_free_late() should be used for\nmemory allocated with memblock_alloc() while the memory reserved with\nmemblock_reserve() should be freed with free_reserved_area().\n\nMore acutely, with CONFIG_DEFERRED_STRUCT_PAGE_INIT=y\nefi_free_boot_services() is called before deferred initialization of the\nmemory map is complete.\n\nBenjamin Herrenschmidt reports that this causes a leak of ~140MB of\nRAM on EC2 t3a.nano instances which only have 512MB or RAM.\n\nIf the freed memory resides in the areas that memory map for them is\nstill uninitialized, they won't be actually freed because\nmemblock_free_late() calls memblock_free_pages() and the latter skips\nuninitialized pages.\n\nUsing free_reserved_area() at this point is also problematic because\n__free_page() accesses the buddy of the freed page and that again might\nend up in uninitialized part of the memory map.\n\nDelaying the entire efi_free_boot_services() could be problematic\nbecause in addition to freeing boot services memory it updates\nefi.memmap without any synchronization and that's undesirable late in\nboot when there is concurrency.\n\nMore robust approach is to only defer freeing of the EFI boot services\nmemory.\n\nSplit efi_free_boot_services() in two. First efi_unmap_boot_services()\ncollects ranges that should be freed into an array then\nefi_free_boot_services() later frees them after deferred init is complete.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23352', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23359', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stack-out-of-bounds write in devmap\n\nget_upper_ifindexes() iterates over all upper devices and writes their\nindices into an array without checking bounds.\n\nAlso the callers assume that the max number of upper devices is\nMAX_NEST_DEV and allocate excluded_devices[1+MAX_NEST_DEV] on the stack,\nbut that assumption is not correct and the number of upper devices could\nbe larger than MAX_NEST_DEV (e.g., many macvlans), causing a\nstack-out-of-bounds write.\n\nAdd a max parameter to get_upper_ifindexes() to avoid the issue.\nWhen there are too many upper devices, return -EOVERFLOW and abort the\nredirect.\n\nTo reproduce, create more than MAX_NEST_DEV(8) macvlans on a device with\nan XDP program attached using BPF_F_BROADCAST | BPF_F_EXCLUDE_INGRESS.\nThen send a packet to the device to trigger the XDP redirect path.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23359', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23360', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix admin queue leak on controller reset\n\nWhen nvme_alloc_admin_tag_set() is called during a controller reset,\na previous admin queue may still exist. Release it properly before\nallocating a new one to avoid orphaning the old queue.\n\nThis fixes a regression introduced by commit 03b3bcd319b3 ("nvme: fix\nadmin request_queue lifetime").', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23360', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23374', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nblktrace: fix __this_cpu_read/write in preemptible context\n\ntracing_record_cmdline() internally uses __this_cpu_read() and\n__this_cpu_write() on the per-CPU variable trace_cmdline_save, and\ntrace_save_cmdline() explicitly asserts preemption is disabled via\nlockdep_assert_preemption_disabled(). These operations are only safe\nwhen preemption is off, as they were designed to be called from the\nscheduler context (probe_wakeup_sched_switch() / probe_wakeup()).\n\n__blk_add_trace() was calling tracing_record_cmdline(current) early in\nthe blk_tracer path, before ring buffer reservation, from process\ncontext where preemption is fully enabled. This triggers the following\nusing blktests/blktrace/002:\n\nblktrace/002 (blktrace ftrace corruption with sysfs trace) [failed]\n runtime 0.367s ... 0.437s\n something found in dmesg:\n [ 81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33\n [ 81.239580] null_blk: disk nullb1 created\n [ 81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516\n [ 81.362842] caller is tracing_record_cmdline+0x10/0x40\n [ 81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G N 7.0.0-rc1lblk+ #84 PREEMPT(full)\n [ 81.362877] Tainted: [N]=TEST\n [ 81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n [ 81.362881] Call Trace:\n [ 81.362884] <TASK>\n [ 81.362886] dump_stack_lvl+0x8d/0xb0\n ...\n (See '/mnt/sda/blktests/results/nodev/blktrace/002.dmesg' for the entire message)\n\n[ 81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33\n[ 81.239580] null_blk: disk nullb1 created\n[ 81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516\n[ 81.362842] caller is tracing_record_cmdline+0x10/0x40\n[ 81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G N 7.0.0-rc1lblk+ #84 PREEMPT(full)\n[ 81.362877] Tainted: [N]=TEST\n[ 81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 81.362881] Call Trace:\n[ 81.362884] <TASK>\n[ 81.362886] dump_stack_lvl+0x8d/0xb0\n[ 81.362895] check_preemption_disabled+0xce/0xe0\n[ 81.362902] tracing_record_cmdline+0x10/0x40\n[ 81.362923] __blk_add_trace+0x307/0x5d0\n[ 81.362934] ? lock_acquire+0xe0/0x300\n[ 81.362940] ? iov_iter_extract_pages+0x101/0xa30\n[ 81.362959] blk_add_trace_bio+0x106/0x1e0\n[ 81.362968] submit_bio_noacct_nocheck+0x24b/0x3a0\n[ 81.362979] ? lockdep_init_map_type+0x58/0x260\n[ 81.362988] submit_bio_wait+0x56/0x90\n[ 81.363009] __blkdev_direct_IO_simple+0x16c/0x250\n[ 81.363026] ? __pfx_submit_bio_wait_endio+0x10/0x10\n[ 81.363038] ? rcu_read_lock_any_held+0x73/0xa0\n[ 81.363051] blkdev_read_iter+0xc1/0x140\n[ 81.363059] vfs_read+0x20b/0x330\n[ 81.363083] ksys_read+0x67/0xe0\n[ 81.363090] do_syscall_64+0xbf/0xf00\n[ 81.363102] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 81.363106] RIP: 0033:0x7f281906029d\n[ 81.363111] Code: 31 c0 e9 c6 fe ff ff 50 48 8d 3d 66 63 0a 00 e8 59 ff 01 00 66 0f 1f 84 00 00 00 00 00 80 3d 41 33 0e 00 00 74 17 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 5b c3 66 2e 0f 1f 84 00 00 00 00 00 48 83 ec\n[ 81.363113] RSP: 002b:00007ffca127dd48 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n[ 81.363120] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f281906029d\n[ 81.363122] RDX: 0000000000001000 RSI: 0000559f8bfae000 RDI: 0000000000000000\n[ 81.363123] RBP: 0000000000001000 R08: 0000002863a10a81 R09: 00007f281915f000\n[ 81.363124] R10: 00007f2818f77b60 R11: 0000000000000246 R12: 0000559f8bfae000\n[ 81.363126] R13: 0000000000000000 R14: 0000000000000000 R15: 000000000000000a\n[ 81.363142] </TASK>\n\nThe same BUG fires from blk_add_trace_plug(), blk_add_trace_unplug(),\nand blk_add_trace_rq() paths as well.\n\nThe purpose of tracin\n---truncated---", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23374', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23383', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing\n\nstruct bpf_plt contains a u64 target field. Currently, the BPF JIT\nallocator requests an alignment of 4 bytes (sizeof(u32)) for the JIT\nbuffer.\n\nBecause the base address of the JIT buffer can be 4-byte aligned (e.g.,\nending in 0x4 or 0xc), the relative padding logic in build_plt() fails\nto ensure that target lands on an 8-byte boundary.\n\nThis leads to two issues:\n1. UBSAN reports misaligned-access warnings when dereferencing the\n structure.\n2. More critically, target is updated concurrently via WRITE_ONCE() in\n bpf_arch_text_poke() while the JIT'd code executes ldr. On arm64,\n 64-bit loads/stores are only guaranteed to be single-copy atomic if\n they are 64-bit aligned. A misaligned target risks a torn read,\n causing the JIT to jump to a corrupted address.\n\nFix this by increasing the allocation alignment requirement to 8 bytes\n(sizeof(u64)) in bpf_jit_binary_pack_alloc(). This anchors the base of\nthe JIT buffer to an 8-byte boundary, allowing the relative padding math\nin build_plt() to correctly align the target field.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23383', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-23388', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: check metadata block offset is within range\n\nSyzkaller reports a "general protection fault in squashfs_copy_data"\n\nThis is ultimately caused by a corrupted index look-up table, which\nproduces a negative metadata block offset.\n\nThis is subsequently passed to squashfs_copy_data (via\nsquashfs_read_metadata) where the negative offset causes an out of bounds\naccess.\n\nThe fix is to check that the offset is within range in\nsquashfs_read_metadata. This will trap this and other cases.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-23388', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-31447', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31447', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43047', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report's feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn't, omit reporting the raw event and\nreturn early.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43047', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43048', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43048', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43053', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: close crash window in attr dabtree inactivation\n\nWhen inactivating an inode with node-format extended attributes,\nxfs_attr3_node_inactive() invalidates all child leaf/node blocks via\nxfs_trans_binval(), but intentionally does not remove the corresponding\nentries from their parent node blocks. The implicit assumption is that\nxfs_attr_inactive() will truncate the entire attr fork to zero extents\nafterwards, so log recovery will never reach the root node and follow\nthose stale pointers.\n\nHowever, if a log shutdown occurs after the leaf/node block cancellations\ncommit but before the attr bmap truncation commits, this assumption\nbreaks. Recovery replays the attr bmap intact (the inode still has\nattr fork extents), but suppresses replay of all cancelled leaf/node\nblocks, maybe leaving them as stale data on disk. On the next mount,\nxlog_recover_process_iunlinks() retries inactivation and attempts to\nread the root node via the attr bmap. If the root node was not replayed,\nreading the unreplayed root block triggers a metadata verification\nfailure immediately; if it was replayed, following its child pointers\nto unreplayed child blocks triggers the same failure:\n\n XFS (pmem0): Metadata corruption detected at\n xfs_da3_node_read_verify+0x53/0x220, xfs_da3_node block 0x78\n XFS (pmem0): Unmount and run xfs_repair\n XFS (pmem0): First 128 bytes of corrupted metadata buffer:\n 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n XFS (pmem0): metadata I/O error in "xfs_da_read_buf+0x104/0x190" at daddr 0x78 len 8 error 117\n\nFix this in two places:\n\nIn xfs_attr3_node_inactive(), after calling xfs_trans_binval() on a\nchild block, immediately remove the entry that references it from the\nparent node in the same transaction. This eliminates the window where\nthe parent holds a pointer to a cancelled block. Once all children are\nremoved, the now-empty root node is converted to a leaf block within the\nsame transaction. This node-to-leaf conversion is necessary for crash\nsafety. If the system shutdown after the empty node is written to the\nlog but before the second-phase bmap truncation commits, log recovery\nwill attempt to verify the root block on disk. xfs_da3_node_verify()\ndoes not permit a node block with count == 0; such a block will fail\nverification and trigger a metadata corruption shutdown. on the other\nhand, leaf blocks are allowed to have this transient state.\n\nIn xfs_attr_inactive(), split the attr fork truncation into two explicit\nphases. First, truncate all extents beyond the root block (the child\nextents whose parent references have already been removed above).\nSecond, invalidate the root block and truncate the attr bmap to zero in\na single transaction. The two operations in the second phase must be\natomic: as long as the attr bmap has any non-zero length, recovery can\nfollow it to the root block, so the root block invalidation must commit\ntogether with the bmap-to-zero truncation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43053', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43147', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV"\n\nThis reverts commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking\nwhen enabling/disabling SR-IOV"), which causes a deadlock by recursively\ntaking pci_rescan_remove_lock when sriov_del_vfs() is called as part of\npci_stop_and_remove_bus_device(). For example with the following sequence\nof commands:\n\n $ echo <NUM> > /sys/bus/pci/devices/<pf>/sriov_numvfs\n $ echo 1 > /sys/bus/pci/devices/<pf>/remove\n\nA trimmed trace of the deadlock on a mlx5 device is as below:\n\n zsh/5715 is trying to acquire lock:\n 000002597926ef50 (pci_rescan_remove_lock){+.+.}-{3:3}, at: sriov_disable+0x34/0x140\n\n but task is already holding lock:\n 000002597926ef50 (pci_rescan_remove_lock){+.+.}-{3:3}, at: pci_stop_and_remove_bus_device_locked+0x24/0x80\n ...\n Call Trace:\n [<00000259778c4f90>] dump_stack_lvl+0xc0/0x110\n [<00000259779c844e>] print_deadlock_bug+0x31e/0x330\n [<00000259779c1908>] __lock_acquire+0x16c8/0x32f0\n [<00000259779bffac>] lock_acquire+0x14c/0x350\n [<00000259789643a6>] __mutex_lock_common+0xe6/0x1520\n [<000002597896413c>] mutex_lock_nested+0x3c/0x50\n [<00000259784a07e4>] sriov_disable+0x34/0x140\n [<00000258f7d6dd80>] mlx5_sriov_disable+0x50/0x80 [mlx5_core]\n [<00000258f7d5745e>] remove_one+0x5e/0xf0 [mlx5_core]\n [<00000259784857fc>] pci_device_remove+0x3c/0xa0\n [<000002597851012e>] device_release_driver_internal+0x18e/0x280\n [<000002597847ae22>] pci_stop_bus_device+0x82/0xa0\n [<000002597847afce>] pci_stop_and_remove_bus_device_locked+0x5e/0x80\n [<00000259784972c2>] remove_store+0x72/0x90\n [<0000025977e6661a>] kernfs_fop_write_iter+0x15a/0x200\n [<0000025977d7241c>] vfs_write+0x24c/0x300\n [<0000025977d72696>] ksys_write+0x86/0x110\n [<000002597895b61c>] __do_syscall+0x14c/0x400\n [<000002597896e0ee>] system_call+0x6e/0x90\n\nThis alone is not a complete fix as it restores the issue the cited commit\ntried to solve. A new fix will be provided as a follow on.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43147', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43261', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: Add support for TSV110 Spectre-BHB mitigation\n\nThe TSV110 processor is vulnerable to the Spectre-BHB (Branch History\nBuffer) attack, which can be exploited to leak information through\nbranch prediction side channels. This commit adds the MIDR of TSV110\nto the list for software mitigation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43289', 'notes': [{'text': 'In the Linux kernel, the kexec_load_purgatory() function derives image->start by locating e_entry inside an SHF_EXECINSTR section. If the purgatory object contains multiple executable sections with overlapping sh_addr, the entrypoint check can match more than once and trigger a WARN. Derive the entry section from the purgatory_start symbol when present and compute image->start from its final placement. Keep the existing e_entry fallback for purgatories that do not expose the symbol.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43289', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43407', 'notes': [{'text': 'In the Linux kernel, there is a potential out-of-bounds access vulnerability in the ceph_handle_auth_reply() function of the libceph component. When processing messages of type CEPH_MSG_AUTH_REPLY, the value of the payload_len field is stored in a variable of type int. A value greater than INT_MAX leads to integer overflow and is interpreted as a negative value, which causes the pointer address to be decremented and subsequently accessed because ceph_decode_need() only checks that the memory access does not exceed the end address of the allocation. The vulnerability is fixed by changing the data type of payload_len to u32 and introducing additional sanity checks.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43407', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43470', 'notes': [{'text': 'In the Linux kernel, when an alias is found through d_splice_alias in the nfs3_proc_create function, if the alias happens to be a directory dentry, the system does not return any error but simply forgets about this alias, leaving the original dentry to be added as negative. This later causes a system crash in nfs_atomic_open_v23/finish_open since a negative dentry is supplied to do_dentry_open. This issue was observed running lustre-racer, where directories and files are created/removed concurrently with the same name and O_EXCL is not used to open files.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43470', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2418', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
35c678b4ff55494d3a7c3181f527fb23ff9a7ad7a31b93d8ae3e87d37116686a
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2419
An update for kernel is now available for openEuler-24.03-LTS-SP3
Critical
2026-05-22 16:22:07+03:00
2026-05-22 16:22:07+03:00
['CVE-2026-31393', 'CVE-2026-31447', 'CVE-2026-43047', 'CVE-2026-43048', 'CVE-2026-43407']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src.rpm', 'product_id': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'summary': 'openEuler-SA-2026-2419', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31393&packageName=kernel', 'summary': 'CVE-2026-31393', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43407&packageName=kernel', 'summary': 'CVE-2026-43407', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31393', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43407', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2419.json', 'summary': 'openEuler-SA-2026-2419 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'kernel security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': "The Linux Kernel, the operating system core itself.\n\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access\n\nl2cap_information_rsp() checks that cmd_len covers the fixed\nl2cap_info_rsp header (type + result, 4 bytes) but then reads\nrsp->data without verifying that the payload is present:\n\n - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads\n 4 bytes past the header (needs cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header\n (needs cmd_len >= 5).\n\nA truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an\nout-of-bounds read of adjacent skb data.\n\nGuard each data access with the required payload length check. If the\npayload is too short, skip the read and let the state machine complete\nwith safe defaults (feat_mask and remote_fixed_chan remain zero from\nkzalloc), so the info timer cleanup and l2cap_conn_start() still run\nand the connection is not stalled.(CVE-2026-31393)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.(CVE-2026-31447)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report's feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn't, omit reporting the raw event and\nreturn early.(CVE-2026-43047)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <(CVE-2026-43048)\n\nIn the Linux kernel, there is a potential out-of-bounds access vulnerability in the ceph_handle_auth_reply() function of the libceph component. When processing messages of type CEPH_MSG_AUTH_REPLY, the value of the payload_len field is stored in a variable of type int. A value greater than INT_MAX leads to integer overflow and is interpreted as a negative value, which causes the pointer address to be decremented and subsequently accessed because ceph_decode_need() only checks that the memory access does not exceed the end address of the allocation. The vulnerability is fixed by changing the data type of payload_len to u32 and introducing additional sanity checks.(CVE-2026-43407)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for kernel is now available for openEuler-20.03-LTS-SP4/openEuler-24.03-LTS-SP3/openEuler-22.03-LTS-SP3/openEuler-24.03-LTS-SP2.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'kernel', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for kernel is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2419', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:07+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:07+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:07+08:00', 'initial_release_date': '2026-05-22T21:22:07+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'summary': 'openEuler-SA-2026-2419', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31393&packageName=kernel', 'summary': 'CVE-2026-31393', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31447&packageName=kernel', 'summary': 'CVE-2026-31447', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43047&packageName=kernel', 'summary': 'CVE-2026-43047', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43048&packageName=kernel', 'summary': 'CVE-2026-43048', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43407&packageName=kernel', 'summary': 'CVE-2026-43407', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31393', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31447', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43047', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43048', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43407', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2419.json', 'summary': 'openEuler-SA-2026-2419 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_id': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src.rpm', 'product': {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src.rpm', 'product_id': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perf-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64'}, 'product_reference': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perf-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64'}, 'product_reference': 'python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:kernel-6.6.0-145.3.12.142.oe2403sp3.src'}, 'product_reference': 'kernel-6.6.0-145.3.12.142.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31393', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access\n\nl2cap_information_rsp() checks that cmd_len covers the fixed\nl2cap_info_rsp header (type + result, 4 bytes) but then reads\nrsp->data without verifying that the payload is present:\n\n - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads\n 4 bytes past the header (needs cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header\n (needs cmd_len >= 5).\n\nA truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an\nout-of-bounds read of adjacent skb data.\n\nGuard each data access with the required payload length check. If the\npayload is too short, skip the read and let the state machine complete\nwith safe defaults (feat_mask and remote_fixed_chan remain zero from\nkzalloc), so the info timer cleanup and l2cap_conn_start() still run\nand the connection is not stalled.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31393', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:bpftool-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-headers-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-source-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-tools-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:perf-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-perf-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:bpftool-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:bpftool-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-debugsource-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-extra-modules-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-headers-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-source-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-tools-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-tools-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-tools-devel-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:perf-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-perf-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-perf-debuginfo-6.6.0-145.3.12.142.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:kernel-6.6.0-145.3.12.142.oe2403sp3.src']}}, {'cve': 'CVE-2026-31447', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-31447', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43047', 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Check to ensure report responses match the request\n\nIt is possible for a malicious (or clumsy) device to respond to a\nspecific report's feature request using a completely different report\nID. This can cause confusion in the HID core resulting in nasty\nside-effects such as OOB writes.\n\nAdd a check to ensure that the report ID in the response, matches the\none that was requested. If it doesn't, omit reporting the raw event and\nreturn early.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43047', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43048', 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer. However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43048', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43407', 'notes': [{'text': 'In the Linux kernel, there is a potential out-of-bounds access vulnerability in the ceph_handle_auth_reply() function of the libceph component. When processing messages of type CEPH_MSG_AUTH_REPLY, the value of the payload_len field is stored in a variable of type int. A value greater than INT_MAX leads to integer overflow and is interpreted as a negative value, which causes the pointer address to be decremented and subsequently accessed because ceph_decode_need() only checks that the memory access does not exceed the end address of the allocation. The vulnerability is fixed by changing the data type of payload_len to u32 and introducing additional sanity checks.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43407', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2419', 'details': 'kernel security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
45fa05dc2d951ace2df14e557be09d9e07bb05b9e0cd92d5ca186cf0b610342b
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2420
An update for php is now available for openEuler-20.03-LTS-SP4
Critical
2026-05-22 16:22:07+03:00
2026-05-22 16:22:07+03:00
['CVE-2025-14179', 'CVE-2026-6735', 'CVE-2026-7258', 'CVE-2026-7261']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-cli-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-common-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dba-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dbg-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-devel-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-embedded-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-enchant-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ffi-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-fpm-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-intl-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ldap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-odbc-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-opcache-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pdo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-process-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-snmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-soap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-sodium-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-tidy-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-xml-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-8.0.30-13.oe2003sp4.src.rpm', 'product_id': 'php-8.0.30-13.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-cli-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-common-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dba-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-dbg-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-devel-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-embedded-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-enchant-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ffi-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-fpm-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-gmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-intl-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-ldap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-odbc-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-opcache-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pdo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-process-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-snmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-soap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-sodium-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-tidy-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-xml-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'php-help-8.0.30-13.oe2003sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-13.oe2003sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2420', 'summary': 'openEuler-SA-2026-2420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2420.json', 'summary': 'openEuler-SA-2026-2420 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.(CVE-2025-14179)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.(CVE-2026-6735)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.(CVE-2026-7258)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.(CVE-2026-7261)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2420', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:07+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:07+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:07+08:00', 'initial_release_date': '2026-05-22T21:22:07+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2420', 'summary': 'openEuler-SA-2026-2420', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2420.json', 'summary': 'openEuler-SA-2026-2420 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-cli-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-common-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-dba-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-dbg-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-devel-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-embedded-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-enchant-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-ffi-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-fpm-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-gd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-gmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-intl-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-ldap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-odbc-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-opcache-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-pdo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-process-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-snmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-soap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-sodium-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-tidy-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-13.oe2003sp4.aarch64.rpm', 'product': {'name': 'php-xml-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.0.30-13.oe2003sp4.src.rpm', 'product': {'name': 'php-8.0.30-13.oe2003sp4.src.rpm', 'product_id': 'php-8.0.30-13.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-cli-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-common-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-dba-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-dbg-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-devel-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-embedded-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-enchant-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-ffi-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-fpm-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-gd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-gmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-intl-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-ldap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-odbc-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-opcache-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-pdo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-process-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-snmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-soap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-sodium-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-tidy-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-13.oe2003sp4.x86_64.rpm', 'product': {'name': 'php-xml-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.0.30-13.oe2003sp4.noarch.rpm', 'product': {'name': 'php-help-8.0.30-13.oe2003sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-13.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-bcmath-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-cli-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-common-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-common-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-dba-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-dbg-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-debuginfo-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-debugsource-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-devel-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-embedded-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-enchant-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-ffi-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-fpm-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-gd-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-gmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-intl-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-ldap-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-mbstring-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-mysqlnd-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-odbc-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-opcache-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-pdo-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-pgsql-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-process-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-process-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-snmp-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-soap-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-sodium-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-tidy-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-13.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-13.oe2003sp4.aarch64'}, 'product_reference': 'php-xml-8.0.30-13.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-13.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-8.0.30-13.oe2003sp4.src'}, 'product_reference': 'php-8.0.30-13.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-bcmath-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-cli-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-common-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-common-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-dba-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-dbg-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-debuginfo-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-debugsource-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-devel-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-embedded-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-enchant-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-ffi-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-fpm-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-gd-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-gmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-intl-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-ldap-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-mbstring-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-mysqlnd-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-odbc-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-opcache-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-pdo-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-pgsql-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-process-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-process-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-snmp-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-soap-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-sodium-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-tidy-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-13.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-13.oe2003sp4.x86_64'}, 'product_reference': 'php-xml-8.0.30-13.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.0.30-13.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:php-help-8.0.30-13.oe2003sp4.noarch'}, 'product_reference': 'php-help-8.0.30-13.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14179', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14179', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2420', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:php-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-common-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-process-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-13.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:php-8.0.30-13.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:php-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-bcmath-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-cli-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-common-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-dba-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-dbg-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-debugsource-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-devel-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-embedded-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-enchant-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-ffi-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-fpm-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-gd-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-gmp-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-intl-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-ldap-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-mbstring-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-odbc-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-opcache-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-pdo-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-pgsql-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-process-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-snmp-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-soap-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-sodium-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-tidy-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-xml-8.0.30-13.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:php-help-8.0.30-13.oe2003sp4.noarch']}}, {'cve': 'CVE-2026-6735', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6735', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2420', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7258', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7258', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2420', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7261', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2420', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
bba53366e6ef1da573b2ac5b0ace84159f2e5556661d869689d2fb86103d4676
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2421
An update for php is now available for openEuler-22.03-LTS-SP4
Critical
2026-05-22 16:22:07+03:00
2026-05-22 16:22:07+03:00
['CVE-2025-14179', 'CVE-2026-6735', 'CVE-2026-7258', 'CVE-2026-7261']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-cli-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-common-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dba-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dbg-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-devel-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-embedded-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-enchant-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ffi-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-fpm-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-intl-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ldap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-odbc-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-opcache-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pdo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-process-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-snmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-soap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-sodium-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-tidy-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-xml-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-8.0.30-13.oe2203sp4.src.rpm', 'product_id': 'php-8.0.30-13.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-cli-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-common-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dba-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-dbg-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-devel-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-embedded-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-enchant-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ffi-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-fpm-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-gmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-intl-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-ldap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-odbc-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-opcache-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pdo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-process-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-snmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-soap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-sodium-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-tidy-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-xml-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'php-help-8.0.30-13.oe2203sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-13.oe2203sp4.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2421', 'summary': 'openEuler-SA-2026-2421', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2421.json', 'summary': 'openEuler-SA-2026-2421 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'php security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.\n\nSecurity Fix(es):\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.(CVE-2025-14179)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.(CVE-2026-6735)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.(CVE-2026-7258)\n\nIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.(CVE-2026-7261)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for php is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Critical', 'title': 'Severity', 'category': 'general'}, {'text': 'php', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for php is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2421', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:07+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:07+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:07+08:00', 'initial_release_date': '2026-05-22T21:22:07+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2421', 'summary': 'openEuler-SA-2026-2421', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-14179&packageName=php', 'summary': 'CVE-2025-14179', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-6735&packageName=php', 'summary': 'CVE-2026-6735', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7258&packageName=php', 'summary': 'CVE-2026-7258', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-7261&packageName=php', 'summary': 'CVE-2026-7261', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-14179', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-6735', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7258', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-7261', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2421.json', 'summary': 'openEuler-SA-2026-2421 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'php-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-cli-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-common-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-common-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-dba-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-dbg-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-devel-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-embedded-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-enchant-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-ffi-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-fpm-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-gd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-gmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-intl-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-ldap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-odbc-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-opcache-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-pdo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-process-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-process-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-snmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-soap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-sodium-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-tidy-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-13.oe2203sp4.aarch64.rpm', 'product': {'name': 'php-xml-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'php-8.0.30-13.oe2203sp4.src.rpm', 'product': {'name': 'php-8.0.30-13.oe2203sp4.src.rpm', 'product_id': 'php-8.0.30-13.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'php-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-cli-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-cli-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-cli-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-common-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-common-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-common-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dba-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-dba-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-dba-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-dbg-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-dbg-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-dbg-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-devel-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-devel-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-devel-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-embedded-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-embedded-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-embedded-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-enchant-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-enchant-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-enchant-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ffi-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-ffi-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-ffi-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-fpm-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-fpm-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-fpm-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-gd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-gd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-gmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-gmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-gmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-intl-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-intl-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-intl-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-ldap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-ldap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-ldap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-odbc-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-odbc-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-odbc-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-opcache-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-opcache-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-opcache-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pdo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-pdo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-pdo-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-process-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-process-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-process-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-snmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-snmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-snmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-soap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-soap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-soap-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-sodium-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-sodium-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-sodium-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-tidy-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-tidy-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-tidy-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'php-xml-8.0.30-13.oe2203sp4.x86_64.rpm', 'product': {'name': 'php-xml-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_id': 'php-xml-8.0.30-13.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'php-help-8.0.30-13.oe2203sp4.noarch.rpm', 'product': {'name': 'php-help-8.0.30-13.oe2203sp4.noarch.rpm', 'product_id': 'php-help-8.0.30-13.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-bcmath-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-cli-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-common-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-common-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-dba-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-dbg-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-debuginfo-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-debugsource-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-devel-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-embedded-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-enchant-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-ffi-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-fpm-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-gd-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-gmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-intl-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-ldap-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-mbstring-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-mysqlnd-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-odbc-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-opcache-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-pdo-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-pgsql-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-process-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-process-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-snmp-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-soap-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-sodium-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-tidy-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-13.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-13.oe2203sp4.aarch64'}, 'product_reference': 'php-xml-8.0.30-13.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-13.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-8.0.30-13.oe2203sp4.src'}, 'product_reference': 'php-8.0.30-13.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-bcmath-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-cli-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-cli-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-common-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-common-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-common-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dba-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-dba-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-dbg-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-dbg-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-debuginfo-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-debugsource-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-devel-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-devel-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-embedded-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-embedded-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-enchant-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-enchant-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ffi-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-ffi-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-fpm-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-fpm-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gd-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-gd-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-gmp-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-gmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-intl-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-intl-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-ldap-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-ldap-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-mbstring-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-mysqlnd-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-odbc-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-odbc-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-opcache-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-opcache-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pdo-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-pdo-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-pgsql-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-process-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-process-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-process-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-snmp-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-snmp-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-soap-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-soap-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-sodium-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-sodium-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-tidy-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-tidy-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-xml-8.0.30-13.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-13.oe2203sp4.x86_64'}, 'product_reference': 'php-xml-8.0.30-13.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'php-help-8.0.30-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:php-help-8.0.30-13.oe2203sp4.noarch'}, 'product_reference': 'php-help-8.0.30-13.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14179', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL\xa0statements.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-14179', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2421', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:php-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-common-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-process-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-13.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:php-8.0.30-13.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:php-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-bcmath-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-cli-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-common-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-dba-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-dbg-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-debuginfo-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-debugsource-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-devel-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-embedded-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-enchant-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-ffi-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-fpm-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-gd-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-gmp-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-intl-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-ldap-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-mbstring-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-mysqlnd-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-odbc-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-opcache-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-pdo-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-pgsql-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-process-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-snmp-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-soap-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-sodium-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-tidy-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-xml-8.0.30-13.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:php-help-8.0.30-13.oe2203sp4.noarch']}}, {'cve': 'CVE-2026-6735', 'notes': [{'text': "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it\xa0allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the\xa0PHP-FPM status page.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-6735', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2421', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7258', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like\xa0isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which\xa0can trigger a denial of service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7258', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2421', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-7261', 'notes': [{'text': 'In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-7261', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Critical', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2421', 'details': 'php security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
437d9977503d28a8eb0b0310fa57829e6fe3c2e2c3793c76811663cbefde17d6
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2422
An update for perl-Authen-SASL is now available for openEuler-24.03-LTS
Medium
2026-05-22 16:22:07+03:00
2026-05-22 16:22:07+03:00
['CVE-2025-40918']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perl-Authen-SASL-2.1700-2.oe2403.noarch.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch.rpm', 'product_id': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'perl-Authen-SASL-2.1700-2.oe2403.src.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2422', 'summary': 'openEuler-SA-2026-2422', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40918&packageName=perl-Authen-SASL', 'summary': 'CVE-2025-40918', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2422.json', 'summary': 'openEuler-SA-2026-2422 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'perl-Authen-SASL security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for perl-Authen-SASL is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Authen::SASL::Perl is the pure Perl implementation of SASL mechanisms in the Authen::SASL framework, At the time of this writing it provides the client part implementation for the following SASL mechanisms.\n\nSecurity Fix(es):\n\nAuthen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.(CVE-2025-40918)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for perl-Authen-SASL is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'perl-Authen-SASL', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for perl-Authen-SASL is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2422', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:07+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:07+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:07+08:00', 'initial_release_date': '2026-05-22T21:22:07+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2422', 'summary': 'openEuler-SA-2026-2422', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40918&packageName=perl-Authen-SASL', 'summary': 'CVE-2025-40918', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2422.json', 'summary': 'openEuler-SA-2026-2422 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'perl-Authen-SASL-2.1700-2.oe2403.noarch.rpm', 'product': {'name': 'perl-Authen-SASL-2.1700-2.oe2403.noarch.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch.rpm', 'product': {'name': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch.rpm', 'product_id': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'perl-Authen-SASL-2.1700-2.oe2403.src.rpm', 'product': {'name': 'perl-Authen-SASL-2.1700-2.oe2403.src.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'perl-Authen-SASL-2.1700-2.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perl-Authen-SASL-2.1700-2.oe2403.noarch'}, 'product_reference': 'perl-Authen-SASL-2.1700-2.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perl-Authen-SASL-help-2.1700-2.oe2403.noarch'}, 'product_reference': 'perl-Authen-SASL-help-2.1700-2.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-Authen-SASL-2.1700-2.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:perl-Authen-SASL-2.1700-2.oe2403.src'}, 'product_reference': 'perl-Authen-SASL-2.1700-2.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-40918', 'notes': [{'text': 'Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40918', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2422', 'details': 'perl-Authen-SASL security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:perl-Authen-SASL-2.1700-2.oe2403.noarch', 'openEuler-24.03-LTS:perl-Authen-SASL-help-2.1700-2.oe2403.noarch', 'openEuler-24.03-LTS:perl-Authen-SASL-2.1700-2.oe2403.src']}}]}
20ee28eab3ab0b0a06e8e1304ee6bacaeb2d332fbaf891d9a9e2bcc809a40ece
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2423
An update for perl-Authen-SASL is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-22 16:22:07+03:00
2026-05-22 16:22:07+03:00
['CVE-2025-40918']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2423', 'summary': 'openEuler-SA-2026-2423', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40918&packageName=perl-Authen-SASL', 'summary': 'CVE-2025-40918', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2423.json', 'summary': 'openEuler-SA-2026-2423 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'perl-Authen-SASL security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for perl-Authen-SASL is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Authen::SASL::Perl is the pure Perl implementation of SASL mechanisms in the Authen::SASL framework, At the time of this writing it provides the client part implementation for the following SASL mechanisms.\n\nSecurity Fix(es):\n\nAuthen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.(CVE-2025-40918)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for perl-Authen-SASL is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'perl-Authen-SASL', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for perl-Authen-SASL is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2423', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:07+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:07+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:07+08:00', 'initial_release_date': '2026-05-22T21:22:07+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2423', 'summary': 'openEuler-SA-2026-2423', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-40918&packageName=perl-Authen-SASL', 'summary': 'CVE-2025-40918', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-40918', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2423.json', 'summary': 'openEuler-SA-2026-2423 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch.rpm', 'product': {'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch.rpm', 'product': {'name': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch.rpm', 'product_id': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src.rpm', 'product': {'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src.rpm', 'product_id': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perl-Authen-SASL-2.1700-2.oe2403sp3.noarch'}, 'product_reference': 'perl-Authen-SASL-2.1700-2.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch'}, 'product_reference': 'perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:perl-Authen-SASL-2.1700-2.oe2403sp3.src'}, 'product_reference': 'perl-Authen-SASL-2.1700-2.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-40918', 'notes': [{'text': 'Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-40918', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2423', 'details': 'perl-Authen-SASL security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:perl-Authen-SASL-2.1700-2.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:perl-Authen-SASL-help-2.1700-2.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:perl-Authen-SASL-2.1700-2.oe2403sp3.src']}}]}
5b9412d46a941abf9e70a62cccc64edb43ebcf7684ed529b9138a022679955b8
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2424
An update for jq is now available for openEuler-20.03-LTS-SP4
Medium
2026-05-22 16:22:08+03:00
2026-05-22 16:22:08+03:00
['CVE-2026-40612', 'CVE-2026-41256', 'CVE-2026-41257', 'CVE-2026-43894', 'CVE-2026-43895', 'CVE-2026-43896', 'CVE-2026-44777']
[{'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-1.8.0-4.oe2003sp4.src.rpm', 'product_id': 'jq-1.8.0-4.oe2003sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-devel-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2003sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-help-1.8.0-4.oe2003sp4.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2003sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4', 'name': 'jq-devel-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2003sp4.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'summary': 'openEuler-SA-2026-2424', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2424.json', 'summary': 'openEuler-SA-2026-2424 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'jq security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-20.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.\n\nSecurity Fix(es):\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.(CVE-2026-40612)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.(CVE-2026-41256)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.(CVE-2026-41257)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).(CVE-2026-43894)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.(CVE-2026-43895)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.(CVE-2026-43896)\n\njq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.(CVE-2026-44777)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-20.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'jq', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for jq is now available for openEuler-20.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2424', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:08+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:08+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:08+08:00', 'initial_release_date': '2026-05-22T21:22:08+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'summary': 'openEuler-SA-2026-2424', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2424.json', 'summary': 'openEuler-SA-2026-2424 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-20.03-LTS-SP4', 'product': {'name': 'openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'jq-1.8.0-4.oe2003sp4.src.rpm', 'product': {'name': 'jq-1.8.0-4.oe2003sp4.src.rpm', 'product_id': 'jq-1.8.0-4.oe2003sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'jq-1.8.0-4.oe2003sp4.x86_64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2003sp4.x86_64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2003sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'jq-help-1.8.0-4.oe2003sp4.noarch.rpm', 'product': {'name': 'jq-help-1.8.0-4.oe2003sp4.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2003sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'jq-1.8.0-4.oe2003sp4.aarch64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2003sp4.aarch64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2003sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:20.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2003sp4.src as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-1.8.0-4.oe2003sp4.src'}, 'product_reference': 'jq-1.8.0-4.oe2003sp4.src.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-1.8.0-4.oe2003sp4.x86_64'}, 'product_reference': 'jq-1.8.0-4.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2003sp4.x86_64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2003sp4.x86_64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2003sp4.x86_64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-devel-1.8.0-4.oe2003sp4.x86_64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2003sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-help-1.8.0-4.oe2003sp4.noarch as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-help-1.8.0-4.oe2003sp4.noarch'}, 'product_reference': 'jq-help-1.8.0-4.oe2003sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-1.8.0-4.oe2003sp4.aarch64'}, 'product_reference': 'jq-1.8.0-4.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2003sp4.aarch64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2003sp4.aarch64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2003sp4.aarch64 as a component of openEuler-20.03-LTS-SP4', 'product_id': 'openEuler-20.03-LTS-SP4:jq-devel-1.8.0-4.oe2003sp4.aarch64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2003sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-20.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40612', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40612', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-20.03-LTS-SP4:jq-1.8.0-4.oe2003sp4.src', 'openEuler-20.03-LTS-SP4:jq-1.8.0-4.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:jq-devel-1.8.0-4.oe2003sp4.x86_64', 'openEuler-20.03-LTS-SP4:jq-help-1.8.0-4.oe2003sp4.noarch', 'openEuler-20.03-LTS-SP4:jq-1.8.0-4.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2003sp4.aarch64', 'openEuler-20.03-LTS-SP4:jq-devel-1.8.0-4.oe2003sp4.aarch64']}}, {'cve': 'CVE-2026-41256', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41256', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-41257', 'notes': [{'text': "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41257', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43894', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43894', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43895', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43895', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43896', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43896', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-44777', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-44777', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2424', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
cc84de2df4267e1e77a2d7c8f84c5e14e63cbdde2d80c6f1c9d09bd159514158
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2425
An update for jq is now available for openEuler-22.03-LTS-SP4
Medium
2026-05-22 16:22:08+03:00
2026-05-22 16:22:08+03:00
['CVE-2026-40612', 'CVE-2026-41256', 'CVE-2026-41257', 'CVE-2026-43894', 'CVE-2026-43895', 'CVE-2026-43896', 'CVE-2026-44777']
[{'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-1.8.0-4.oe2203sp4.src.rpm', 'product_id': 'jq-1.8.0-4.oe2203sp4.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-devel-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2203sp4.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-help-1.8.0-4.oe2203sp4.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2203sp4.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4', 'name': 'jq-devel-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2203sp4.aarch64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'summary': 'openEuler-SA-2026-2425', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2425.json', 'summary': 'openEuler-SA-2026-2425 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'jq security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-22.03-LTS-SP4', 'title': 'Summary', 'category': 'general'}, {'text': "jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.\n\nSecurity Fix(es):\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.(CVE-2026-40612)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.(CVE-2026-41256)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.(CVE-2026-41257)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).(CVE-2026-43894)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.(CVE-2026-43895)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.(CVE-2026-43896)\n\njq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.(CVE-2026-44777)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'jq', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for jq is now available for openEuler-22.03-LTS-SP4', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2425', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:08+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:08+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:08+08:00', 'initial_release_date': '2026-05-22T21:22:08+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'summary': 'openEuler-SA-2026-2425', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2425.json', 'summary': 'openEuler-SA-2026-2425 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-22.03-LTS-SP4', 'product': {'name': 'openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'jq-1.8.0-4.oe2203sp4.src.rpm', 'product': {'name': 'jq-1.8.0-4.oe2203sp4.src.rpm', 'product_id': 'jq-1.8.0-4.oe2203sp4.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'jq-1.8.0-4.oe2203sp4.x86_64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2203sp4.x86_64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2203sp4.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'jq-help-1.8.0-4.oe2203sp4.noarch.rpm', 'product': {'name': 'jq-help-1.8.0-4.oe2203sp4.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2203sp4.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'jq-1.8.0-4.oe2203sp4.aarch64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2203sp4.aarch64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2203sp4.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:22.03-LTS-SP4'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-1.8.0-4.oe2203sp4.src'}, 'product_reference': 'jq-1.8.0-4.oe2203sp4.src.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-1.8.0-4.oe2203sp4.x86_64'}, 'product_reference': 'jq-1.8.0-4.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2203sp4.x86_64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2203sp4.x86_64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2203sp4.x86_64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-devel-1.8.0-4.oe2203sp4.x86_64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2203sp4.x86_64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-help-1.8.0-4.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-help-1.8.0-4.oe2203sp4.noarch'}, 'product_reference': 'jq-help-1.8.0-4.oe2203sp4.noarch.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-1.8.0-4.oe2203sp4.aarch64'}, 'product_reference': 'jq-1.8.0-4.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2203sp4.aarch64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2203sp4.aarch64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2203sp4.aarch64 as a component of openEuler-22.03-LTS-SP4', 'product_id': 'openEuler-22.03-LTS-SP4:jq-devel-1.8.0-4.oe2203sp4.aarch64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2203sp4.aarch64.rpm', 'relates_to_product_reference': 'openEuler-22.03-LTS-SP4'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40612', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40612', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-22.03-LTS-SP4:jq-1.8.0-4.oe2203sp4.src', 'openEuler-22.03-LTS-SP4:jq-1.8.0-4.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:jq-devel-1.8.0-4.oe2203sp4.x86_64', 'openEuler-22.03-LTS-SP4:jq-help-1.8.0-4.oe2203sp4.noarch', 'openEuler-22.03-LTS-SP4:jq-1.8.0-4.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:jq-debuginfo-1.8.0-4.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:jq-debugsource-1.8.0-4.oe2203sp4.aarch64', 'openEuler-22.03-LTS-SP4:jq-devel-1.8.0-4.oe2203sp4.aarch64']}}, {'cve': 'CVE-2026-41256', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41256', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-41257', 'notes': [{'text': "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41257', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43894', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43894', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43895', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43895', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43896', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43896', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-44777', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-44777', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2425', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
26341c4db76012b06ba436f970ab19fb70bd8e7a1d9beab5e1e18779ab6c5361
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2426
An update for jq is now available for openEuler-24.03-LTS
Medium
2026-05-22 16:22:08+03:00
2026-05-22 16:22:08+03:00
['CVE-2026-40612', 'CVE-2026-41256', 'CVE-2026-41257', 'CVE-2026-43894', 'CVE-2026-43895', 'CVE-2026-43896', 'CVE-2026-44777']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-debuginfo-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-debugsource-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-devel-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-1.8.0-4.oe2403.src.rpm', 'product_id': 'jq-1.8.0-4.oe2403.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-debuginfo-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-debugsource-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-devel-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'jq-help-1.8.0-4.oe2403.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2403.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'summary': 'openEuler-SA-2026-2426', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2426.json', 'summary': 'openEuler-SA-2026-2426 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'jq security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': "jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.\n\nSecurity Fix(es):\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.(CVE-2026-40612)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.(CVE-2026-41256)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.(CVE-2026-41257)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).(CVE-2026-43894)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.(CVE-2026-43895)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.(CVE-2026-43896)\n\njq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.(CVE-2026-44777)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'jq', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for jq is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2426', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:08+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:08+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:08+08:00', 'initial_release_date': '2026-05-22T21:22:08+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'summary': 'openEuler-SA-2026-2426', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2426.json', 'summary': 'openEuler-SA-2026-2426 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'jq-1.8.0-4.oe2403.aarch64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2403.aarch64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2403.aarch64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2403.aarch64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2403.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'jq-1.8.0-4.oe2403.src.rpm', 'product': {'name': 'jq-1.8.0-4.oe2403.src.rpm', 'product_id': 'jq-1.8.0-4.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'jq-1.8.0-4.oe2403.x86_64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2403.x86_64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2403.x86_64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2403.x86_64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2403.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'jq-help-1.8.0-4.oe2403.noarch.rpm', 'product': {'name': 'jq-help-1.8.0-4.oe2403.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-1.8.0-4.oe2403.aarch64'}, 'product_reference': 'jq-1.8.0-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-debuginfo-1.8.0-4.oe2403.aarch64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-debugsource-1.8.0-4.oe2403.aarch64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-devel-1.8.0-4.oe2403.aarch64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-1.8.0-4.oe2403.src'}, 'product_reference': 'jq-1.8.0-4.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-1.8.0-4.oe2403.x86_64'}, 'product_reference': 'jq-1.8.0-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-debuginfo-1.8.0-4.oe2403.x86_64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-debugsource-1.8.0-4.oe2403.x86_64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-devel-1.8.0-4.oe2403.x86_64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-help-1.8.0-4.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:jq-help-1.8.0-4.oe2403.noarch'}, 'product_reference': 'jq-help-1.8.0-4.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40612', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40612', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:jq-1.8.0-4.oe2403.aarch64', 'openEuler-24.03-LTS:jq-debuginfo-1.8.0-4.oe2403.aarch64', 'openEuler-24.03-LTS:jq-debugsource-1.8.0-4.oe2403.aarch64', 'openEuler-24.03-LTS:jq-devel-1.8.0-4.oe2403.aarch64', 'openEuler-24.03-LTS:jq-1.8.0-4.oe2403.src', 'openEuler-24.03-LTS:jq-1.8.0-4.oe2403.x86_64', 'openEuler-24.03-LTS:jq-debuginfo-1.8.0-4.oe2403.x86_64', 'openEuler-24.03-LTS:jq-debugsource-1.8.0-4.oe2403.x86_64', 'openEuler-24.03-LTS:jq-devel-1.8.0-4.oe2403.x86_64', 'openEuler-24.03-LTS:jq-help-1.8.0-4.oe2403.noarch']}}, {'cve': 'CVE-2026-41256', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41256', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-41257', 'notes': [{'text': "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41257', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43894', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43894', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43895', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43895', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43896', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43896', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-44777', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-44777', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2426', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
44d47d885795190a28d319f421f4b5c8d806c83c2fa10b8012e48ad8acd5a9e1
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2427
An update for jq is now available for openEuler-24.03-LTS-SP3
Medium
2026-05-22 16:22:08+03:00
2026-05-22 16:22:08+03:00
['CVE-2026-40612', 'CVE-2026-41256', 'CVE-2026-41257', 'CVE-2026-43894', 'CVE-2026-43895', 'CVE-2026-43896', 'CVE-2026-44777']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-help-1.8.0-4.oe2403sp3.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2403sp3.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-devel-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-1.8.0-4.oe2403sp3.src.rpm', 'product_id': 'jq-1.8.0-4.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'jq-devel-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403sp3.x86_64.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'summary': 'openEuler-SA-2026-2427', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2427.json', 'summary': 'openEuler-SA-2026-2427 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'jq security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': "jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.\n\nSecurity Fix(es):\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.(CVE-2026-40612)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.(CVE-2026-41256)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.(CVE-2026-41257)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).(CVE-2026-43894)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.(CVE-2026-43895)\n\njq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.(CVE-2026-43896)\n\njq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.(CVE-2026-44777)", 'title': 'Description', 'category': 'general'}, {'text': 'An update for jq is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'Medium', 'title': 'Severity', 'category': 'general'}, {'text': 'jq', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for jq is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2427', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:08+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:08+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:08+08:00', 'initial_release_date': '2026-05-22T21:22:08+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'summary': 'openEuler-SA-2026-2427', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-40612&packageName=jq', 'summary': 'CVE-2026-40612', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41256&packageName=jq', 'summary': 'CVE-2026-41256', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-41257&packageName=jq', 'summary': 'CVE-2026-41257', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43894&packageName=jq', 'summary': 'CVE-2026-43894', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43895&packageName=jq', 'summary': 'CVE-2026-43895', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-43896&packageName=jq', 'summary': 'CVE-2026-43896', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44777&packageName=jq', 'summary': 'CVE-2026-44777', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-40612', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41256', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-41257', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43894', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43895', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43896', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-44777', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2427.json', 'summary': 'openEuler-SA-2026-2427 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'noarch', 'branches': [{'name': 'jq-help-1.8.0-4.oe2403sp3.noarch.rpm', 'product': {'name': 'jq-help-1.8.0-4.oe2403sp3.noarch.rpm', 'product_id': 'jq-help-1.8.0-4.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'jq-1.8.0-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2403sp3.aarch64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'jq-1.8.0-4.oe2403sp3.src.rpm', 'product': {'name': 'jq-1.8.0-4.oe2403sp3.src.rpm', 'product_id': 'jq-1.8.0-4.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'jq-1.8.0-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'jq-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'jq-devel-1.8.0-4.oe2403sp3.x86_64.rpm', 'product': {'name': 'jq-devel-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_id': 'jq-devel-1.8.0-4.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'jq-help-1.8.0-4.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-help-1.8.0-4.oe2403sp3.noarch'}, 'product_reference': 'jq-help-1.8.0-4.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-1.8.0-4.oe2403sp3.aarch64'}, 'product_reference': 'jq-1.8.0-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-debuginfo-1.8.0-4.oe2403sp3.aarch64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-debugsource-1.8.0-4.oe2403sp3.aarch64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-devel-1.8.0-4.oe2403sp3.aarch64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-1.8.0-4.oe2403sp3.src'}, 'product_reference': 'jq-1.8.0-4.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-1.8.0-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-1.8.0-4.oe2403sp3.x86_64'}, 'product_reference': 'jq-1.8.0-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-debuginfo-1.8.0-4.oe2403sp3.x86_64'}, 'product_reference': 'jq-debuginfo-1.8.0-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-debugsource-1.8.0-4.oe2403sp3.x86_64'}, 'product_reference': 'jq-debugsource-1.8.0-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'jq-devel-1.8.0-4.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:jq-devel-1.8.0-4.oe2403sp3.x86_64'}, 'product_reference': 'jq-devel-1.8.0-4.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40612', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-40612', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:jq-help-1.8.0-4.oe2403sp3.noarch', 'openEuler-24.03-LTS-SP3:jq-1.8.0-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:jq-debuginfo-1.8.0-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:jq-debugsource-1.8.0-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:jq-devel-1.8.0-4.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:jq-1.8.0-4.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:jq-1.8.0-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:jq-debuginfo-1.8.0-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:jq-debugsource-1.8.0-4.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:jq-devel-1.8.0-4.oe2403sp3.x86_64']}}, {'cve': 'CVE-2026-41256', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41256', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-41257', 'notes': [{'text': "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-41257', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43894', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43894', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43895', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43895', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-43896', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-43896', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}, {'cve': 'CVE-2026-44777', 'notes': [{'text': 'jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-44777', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'Medium', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2427', 'details': 'jq security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}}]}
36d35e7d701c1a3703ea4f9e4ac1adf274f05ffc666e1e9a7ddd6bb3eb925d42
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2428
An update for python-pillow is now available for openEuler-24.03-LTS
High
2026-05-22 16:22:08+03:00
2026-05-22 16:22:08+03:00
['CVE-2026-42311']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python3-pillow-help-10.3.0-5.oe2403.noarch.rpm', 'product_id': 'python3-pillow-help-10.3.0-5.oe2403.noarch.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS', 'name': 'python-pillow-10.3.0-5.oe2403.src.rpm', 'product_id': 'python-pillow-10.3.0-5.oe2403.src.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2428', 'summary': 'openEuler-SA-2026-2428', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42311&packageName=python-pillow', 'summary': 'CVE-2026-42311', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42311', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2428.json', 'summary': 'openEuler-SA-2026-2428 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-pillow security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-pillow is now available for openEuler-24.03-LTS', 'title': 'Summary', 'category': 'general'}, {'text': 'Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \\ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift. of CVE-2022-22815,CVE-2022-22816)\n\nSecurity Fix(es):\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.(CVE-2026-42311)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-pillow is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'python-pillow', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-pillow is now available for openEuler-24.03-LTS', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2428', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:08+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:08+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:08+08:00', 'initial_release_date': '2026-05-22T21:22:08+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2428', 'summary': 'openEuler-SA-2026-2428', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42311&packageName=python-pillow', 'summary': 'CVE-2026-42311', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42311', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2428.json', 'summary': 'openEuler-SA-2026-2428 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS', 'product': {'name': 'openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'aarch64', 'branches': [{'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-10.3.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python3-pillow-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64.rpm', 'product': {'name': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-10.3.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python3-pillow-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}, {'name': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64.rpm', 'product': {'name': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python3-pillow-help-10.3.0-5.oe2403.noarch.rpm', 'product': {'name': 'python3-pillow-help-10.3.0-5.oe2403.noarch.rpm', 'product_id': 'python3-pillow-help-10.3.0-5.oe2403.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'src', 'branches': [{'name': 'python-pillow-10.3.0-5.oe2403.src.rpm', 'product': {'name': 'python-pillow-10.3.0-5.oe2403.src.rpm', 'product_id': 'python-pillow-10.3.0-5.oe2403.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pillow-debuginfo-10.3.0-5.oe2403.aarch64'}, 'product_reference': 'python-pillow-debuginfo-10.3.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pillow-debugsource-10.3.0-5.oe2403.aarch64'}, 'product_reference': 'python-pillow-debugsource-10.3.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-10.3.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-10.3.0-5.oe2403.aarch64'}, 'product_reference': 'python3-pillow-10.3.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-devel-10.3.0-5.oe2403.aarch64'}, 'product_reference': 'python3-pillow-devel-10.3.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-qt-10.3.0-5.oe2403.aarch64'}, 'product_reference': 'python3-pillow-qt-10.3.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-tk-10.3.0-5.oe2403.aarch64'}, 'product_reference': 'python3-pillow-tk-10.3.0-5.oe2403.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pillow-debuginfo-10.3.0-5.oe2403.x86_64'}, 'product_reference': 'python-pillow-debuginfo-10.3.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pillow-debugsource-10.3.0-5.oe2403.x86_64'}, 'product_reference': 'python-pillow-debugsource-10.3.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-10.3.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-10.3.0-5.oe2403.x86_64'}, 'product_reference': 'python3-pillow-10.3.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-devel-10.3.0-5.oe2403.x86_64'}, 'product_reference': 'python3-pillow-devel-10.3.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-qt-10.3.0-5.oe2403.x86_64'}, 'product_reference': 'python3-pillow-qt-10.3.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64 as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-tk-10.3.0-5.oe2403.x86_64'}, 'product_reference': 'python3-pillow-tk-10.3.0-5.oe2403.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-help-10.3.0-5.oe2403.noarch as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python3-pillow-help-10.3.0-5.oe2403.noarch'}, 'product_reference': 'python3-pillow-help-10.3.0-5.oe2403.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-10.3.0-5.oe2403.src as a component of openEuler-24.03-LTS', 'product_id': 'openEuler-24.03-LTS:python-pillow-10.3.0-5.oe2403.src'}, 'product_reference': 'python-pillow-10.3.0-5.oe2403.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42311', 'notes': [{'text': 'Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42311', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2428', 'details': 'python-pillow security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS:python-pillow-debuginfo-10.3.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python-pillow-debugsource-10.3.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python3-pillow-10.3.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python3-pillow-devel-10.3.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python3-pillow-qt-10.3.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python3-pillow-tk-10.3.0-5.oe2403.aarch64', 'openEuler-24.03-LTS:python-pillow-debuginfo-10.3.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python-pillow-debugsource-10.3.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python3-pillow-10.3.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python3-pillow-devel-10.3.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python3-pillow-qt-10.3.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python3-pillow-tk-10.3.0-5.oe2403.x86_64', 'openEuler-24.03-LTS:python3-pillow-help-10.3.0-5.oe2403.noarch', 'openEuler-24.03-LTS:python-pillow-10.3.0-5.oe2403.src']}}]}
205ba47d85422ec5e13889593129a333966314187f04a34c6423315d88852bdb
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00
openEuler-SA-2026-2429
An update for python-pillow is now available for openEuler-24.03-LTS-SP3
High
2026-05-22 16:22:09+03:00
2026-05-22 16:22:09+03:00
['CVE-2026-42311']
[{'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pillow-10.3.0-5.oe2403sp3.src.rpm', 'product_id': 'python-pillow-10.3.0-5.oe2403sp3.src.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64.rpm'}, {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3', 'name': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch.rpm', 'product_id': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch.rpm'}]
[{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2429', 'summary': 'openEuler-SA-2026-2429', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42311&packageName=python-pillow', 'summary': 'CVE-2026-42311', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42311', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2429.json', 'summary': 'openEuler-SA-2026-2429 vex file', 'category': 'self'}]
{'document': {'lang': 'en', 'notes': [{'text': 'python-pillow security update', 'title': 'Synopsis', 'category': 'general'}, {'text': 'An update for python-pillow is now available for openEuler-24.03-LTS-SP3', 'title': 'Summary', 'category': 'general'}, {'text': 'Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \\ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift. of CVE-2022-22815,CVE-2022-22816)\n\nSecurity Fix(es):\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.(CVE-2026-42311)', 'title': 'Description', 'category': 'general'}, {'text': 'An update for python-pillow is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.', 'title': 'Topic', 'category': 'general'}, {'text': 'High', 'title': 'Severity', 'category': 'general'}, {'text': 'python-pillow', 'title': 'Affected Component', 'category': 'general'}], 'title': 'An update for python-pillow is now available for openEuler-24.03-LTS-SP3', 'category': 'csaf_vex', 'tracking': {'id': 'openEuler-SA-2026-2429', 'status': 'final', 'version': '1.0.0', 'generator': {'date': '2026-05-22T21:22:09+08:00', 'engine': {'name': 'openEuler CSAF Tool V1.0'}}, 'revision_history': [{'date': '2026-05-22T21:22:09+08:00', 'number': '1.0.0', 'summary': 'Initial'}], 'current_release_date': '2026-05-22T21:22:09+08:00', 'initial_release_date': '2026-05-22T21:22:09+08:00'}, 'publisher': {'name': 'openEuler', 'category': 'vendor', 'namespace': 'https://www.openeuler.org', 'contact_details': 'openeuler-security@openeuler.org', 'issuing_authority': 'openEuler security committee'}, 'references': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2429', 'summary': 'openEuler-SA-2026-2429', 'category': 'self'}, {'url': 'https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42311&packageName=python-pillow', 'summary': 'CVE-2026-42311', 'category': 'self'}, {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-42311', 'summary': 'nvd cve', 'category': 'external'}, {'url': 'https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2429.json', 'summary': 'openEuler-SA-2026-2429 vex file', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https:/www.first.org/tlp/', 'label': 'WHITE'}}, 'aggregate_severity': {'text': 'High', 'namespace': 'https://nvd.nist.gov/vuln-metrics/cvss'}}, 'product_tree': {'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler', 'branches': [{'name': 'openEuler-24.03-LTS-SP3', 'product': {'name': 'openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'src', 'branches': [{'name': 'python-pillow-10.3.0-5.oe2403sp3.src.rpm', 'product': {'name': 'python-pillow-10.3.0-5.oe2403sp3.src.rpm', 'product_id': 'python-pillow-10.3.0-5.oe2403sp3.src.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'aarch64', 'branches': [{'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64.rpm', 'product': {'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'x86_64', 'branches': [{'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}, {'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64.rpm', 'product': {'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_id': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'noarch', 'branches': [{'name': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch.rpm', 'product': {'name': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch.rpm', 'product_id': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch.rpm', 'product_identification_helper': {'cpe': 'cpe:/a:openEuler:openEuler:24.03-LTS-SP3'}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'vendor'}], 'relationships': [{'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-10.3.0-5.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pillow-10.3.0-5.oe2403sp3.src'}, 'product_reference': 'python-pillow-10.3.0-5.oe2403sp3.src.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-10.3.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python3-pillow-10.3.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64'}, 'product_reference': 'python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-10.3.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python3-pillow-10.3.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64'}, 'product_reference': 'python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}, {'category': 'default_component_of', 'full_product_name': {'name': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3', 'product_id': 'openEuler-24.03-LTS-SP3:python3-pillow-help-10.3.0-5.oe2403sp3.noarch'}, 'product_reference': 'python3-pillow-help-10.3.0-5.oe2403sp3.noarch.rpm', 'relates_to_product_reference': 'openEuler-24.03-LTS-SP3'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42311', 'notes': [{'text': 'Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2026-42311', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'threats': [{'details': 'High', 'category': 'impact'}], 'remediations': [{'url': 'https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2429', 'details': 'python-pillow security update', 'category': 'vendor_fix', 'product_ids': {'$ref': '$.vulnerabilities[0].product_status.fixed'}}], 'product_status': {'fixed': ['openEuler-24.03-LTS-SP3:python-pillow-10.3.0-5.oe2403sp3.src', 'openEuler-24.03-LTS-SP3:python-pillow-debuginfo-10.3.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python-pillow-debugsource-10.3.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-pillow-10.3.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-pillow-devel-10.3.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-pillow-qt-10.3.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python3-pillow-tk-10.3.0-5.oe2403sp3.aarch64', 'openEuler-24.03-LTS-SP3:python-pillow-debuginfo-10.3.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python-pillow-debugsource-10.3.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-pillow-10.3.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-pillow-devel-10.3.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-pillow-qt-10.3.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-pillow-tk-10.3.0-5.oe2403sp3.x86_64', 'openEuler-24.03-LTS-SP3:python3-pillow-help-10.3.0-5.oe2403sp3.noarch']}}]}
44a651c802593affb65e1373eb25592003747d8f855f4bc9e26fbaf22aa64212
2026-06-01 21:28:07.118716+03:00
2026-06-23 02:41:30.408833+03:00