Cyberus Linux Security Tracker
This is the security tracker for Cyberus Linux. It allows monitoring the status of vulnerabilities that affect Cyberus Linux releases. Vulnerabilities are ingested from official sources, such as NVD and others.
For general information about installing or upgrading Cyberus Linux, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.
Releases
These are the currently supported releases.
Latest Events
GHSA-5qpq-xqfv-j9pg
Cyberus Linux 26.05
xz
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure
2026-09-10 21:51 CEST
New → Plausible
GHSA-r8jp-q6fh-g5r2
Cyberus Linux 26.05
cups
CVE-2026-27447 follow-up: remaining case-insensitive username matching in scheduler side paths
2026-09-10 21:49 CEST
New → Plausible
GHSA-559w-7676-3xrq
Cyberus Linux 26.05
cups
Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound — reachable from SNMP supply-description parsing (backend/snmp-supplies.c)
2026-09-10 21:48 CEST
New → Plausible
GHSA-559w-7676-3xrq
Cyberus Linux 26.05
cups
Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound — reachable from SNMP supply-description parsing (backend/snmp-supplies.c)
2026-09-10 21:47 CEST
New
GHSA-r8jp-q6fh-g5r2
Cyberus Linux 26.05
cups
CVE-2026-27447 follow-up: remaining case-insensitive username matching in scheduler side paths
2026-09-10 21:47 CEST
New
GHSA-5qpq-xqfv-j9pg
Cyberus Linux 26.05
xz
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure
2026-09-10 21:46 CEST
New
GHSA-fqmh-x7gg-pfgw
Cyberus Linux 26.05
mongoc
Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output
2026-09-10 18:45 CEST
New → Resolved
GHSA-8vwp-6h6c-hx6h
Cyberus Linux 26.05
mongoc
Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
2026-09-10 18:45 CEST
New → Resolved
GHSA-fw3j-wh78-34mj
Cyberus Linux 26.05
mongoc
Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
2026-09-10 18:45 CEST
New → Resolved
GHSA-h2g7-2gxh-c5v2
Cyberus Linux 26.05
mongoc
Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
2026-09-10 18:45 CEST
New → Resolved
GHSA-fqmh-x7gg-pfgw
Cyberus Linux 26.05
mongoc
Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output
2026-09-10 18:44 CEST
New
GHSA-8vwp-6h6c-hx6h
Cyberus Linux 26.05
mongoc
Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
2026-09-10 18:44 CEST
New
GHSA-fw3j-wh78-34mj
Cyberus Linux 26.05
mongoc
Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
2026-09-10 18:44 CEST
New
GHSA-h2g7-2gxh-c5v2
Cyberus Linux 26.05
mongoc
Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
2026-09-10 18:44 CEST
New
GHSA-c9qr-rh56-vvrc
Cyberus Linux 26.05
mongoc
Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
2026-09-10 18:40 CEST
New → Acknowledged
Status for the r1.30 branch is unclear.
The CVE information and the GHSA information both point at any version prior to 2.5.1 being affected, which would include the r1 series.
A cursory look at the codebase seems to indicate the locations where the fix was applied look similar.
GHSA-c9qr-rh56-vvrc
Cyberus Linux 26.05
mongoc
Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
2026-09-10 18:40 CEST
New
CVE-2026-86219
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
2026-09-09 21:31 CEST
New → Plausible
CVE-2025-40918
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely
2026-09-09 21:31 CEST
New → Resolved
CVE-2025-40918
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely
2026-09-09 21:31 CEST
New
CVE-2026-86219
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
2026-09-09 21:31 CEST
New
CVE-2026-18238
Cyberus Linux 26.05
libpcap
OOBR in rpcap client in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-18313
Cyberus Linux 26.05
libpcap
rpcapd memory leak in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-0799
Cyberus Linux 26.05
libpcap
OOBR and OOBW in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-31911
Cyberus Linux 26.05
libpcap
abort() in libpcap before 1.10.7 on an invalid BPF opcode
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-31912
Cyberus Linux 26.05
libpcap
OOBR in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-6244
Cyberus Linux 26.05
libpcap
division by zero in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-6554
Cyberus Linux 26.05
libpcap
infinte loop in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible
CVE-2026-18238
Cyberus Linux 26.05
libpcap
OOBR in rpcap client in libpcap before 1.10.7
2026-09-09 21:29 CEST
New
CVE-2026-18313
Cyberus Linux 26.05
libpcap
rpcapd memory leak in libpcap before 1.10.7
2026-09-09 21:29 CEST
New
CVE-2026-0799
Cyberus Linux 26.05
libpcap
OOBR and OOBW in libpcap before 1.10.7
2026-09-09 21:29 CEST
New