Skip to content

Cyberus Linux Security Tracker

This is the security tracker for Cyberus Linux. It allows monitoring the status of vulnerabilities that affect Cyberus Linux releases. Vulnerabilities are ingested from official sources, such as NVD and others.

For general information about installing or upgrading Cyberus Linux, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.

Releases

These are the currently supported releases.

Latest Events

GHSA-5qpq-xqfv-j9pg
Cyberus Linux 26.05
xz
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure
2026-09-10 21:51 CEST
New → Plausible

GHSA-r8jp-q6fh-g5r2
Cyberus Linux 26.05
cups
CVE-2026-27447 follow-up: remaining case-insensitive username matching in scheduler side paths
2026-09-10 21:49 CEST
New → Plausible

GHSA-559w-7676-3xrq
Cyberus Linux 26.05
cups
Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound — reachable from SNMP supply-description parsing (backend/snmp-supplies.c)
2026-09-10 21:48 CEST
New → Plausible

GHSA-559w-7676-3xrq
Cyberus Linux 26.05
cups
Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound — reachable from SNMP supply-description parsing (backend/snmp-supplies.c)
2026-09-10 21:47 CEST
New

GHSA-r8jp-q6fh-g5r2
Cyberus Linux 26.05
cups
CVE-2026-27447 follow-up: remaining case-insensitive username matching in scheduler side paths
2026-09-10 21:47 CEST
New

GHSA-5qpq-xqfv-j9pg
Cyberus Linux 26.05
xz
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure
2026-09-10 21:46 CEST
New

GHSA-fqmh-x7gg-pfgw
Cyberus Linux 26.05
mongoc
Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output
2026-09-10 18:45 CEST
New → Resolved

GHSA-8vwp-6h6c-hx6h
Cyberus Linux 26.05
mongoc
Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
2026-09-10 18:45 CEST
New → Resolved

GHSA-fw3j-wh78-34mj
Cyberus Linux 26.05
mongoc
Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
2026-09-10 18:45 CEST
New → Resolved

GHSA-h2g7-2gxh-c5v2
Cyberus Linux 26.05
mongoc
Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
2026-09-10 18:45 CEST
New → Resolved

GHSA-fqmh-x7gg-pfgw
Cyberus Linux 26.05
mongoc
Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output
2026-09-10 18:44 CEST
New

GHSA-8vwp-6h6c-hx6h
Cyberus Linux 26.05
mongoc
Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
2026-09-10 18:44 CEST
New

GHSA-fw3j-wh78-34mj
Cyberus Linux 26.05
mongoc
Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
2026-09-10 18:44 CEST
New

GHSA-h2g7-2gxh-c5v2
Cyberus Linux 26.05
mongoc
Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
2026-09-10 18:44 CEST
New

GHSA-c9qr-rh56-vvrc
Cyberus Linux 26.05
mongoc
Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
2026-09-10 18:40 CEST
New → Acknowledged
Status for the r1.30 branch is unclear. The CVE information and the GHSA information both point at any version prior to 2.5.1 being affected, which would include the r1 series. A cursory look at the codebase seems to indicate the locations where the fix was applied look similar.

GHSA-c9qr-rh56-vvrc
Cyberus Linux 26.05
mongoc
Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
2026-09-10 18:40 CEST
New

CVE-2026-86219
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
2026-09-09 21:31 CEST
New → Plausible

CVE-2025-40918
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely
2026-09-09 21:31 CEST
New → Resolved

CVE-2025-40918
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely
2026-09-09 21:31 CEST
New

CVE-2026-86219
Cyberus Linux 26.05
perlPackages.AuthenSASL
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
2026-09-09 21:31 CEST
New

CVE-2026-18238
Cyberus Linux 26.05
libpcap
OOBR in rpcap client in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-18313
Cyberus Linux 26.05
libpcap
rpcapd memory leak in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-0799
Cyberus Linux 26.05
libpcap
OOBR and OOBW in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-31911
Cyberus Linux 26.05
libpcap
abort() in libpcap before 1.10.7 on an invalid BPF opcode
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-31912
Cyberus Linux 26.05
libpcap
OOBR in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-6244
Cyberus Linux 26.05
libpcap
division by zero in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-6554
Cyberus Linux 26.05
libpcap
infinte loop in libpcap before 1.10.7
2026-09-09 21:29 CEST
New → Plausible

CVE-2026-18238
Cyberus Linux 26.05
libpcap
OOBR in rpcap client in libpcap before 1.10.7
2026-09-09 21:29 CEST
New

CVE-2026-18313
Cyberus Linux 26.05
libpcap
rpcapd memory leak in libpcap before 1.10.7
2026-09-09 21:29 CEST
New

CVE-2026-0799
Cyberus Linux 26.05
libpcap
OOBR and OOBW in libpcap before 1.10.7
2026-09-09 21:29 CEST
New