azurelustre-csi (0.5.0-ubuntu22.04u7) jammy; urgency=low

  * [HIGH] CVE-2026-33818 in stdlib (v1.25.11) - encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recu...
  * [HIGH] CVE-2026-39821 in stdlib (v1.25.11) - golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege esc...
  * [HIGH] CVE-2026-39822 in stdlib (v1.25.11) - golang: Go os.Root: Symlink following vulnerability allows directory traversa...
  * [HIGH] CVE-2026-56853 in stdlib (v1.25.11) - net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to D...
  * [HIGH] CVE-2026-56858 in stdlib (v1.25.11) - html/template: golang: Go html/template: Cross-Site Scripting via pathologica...
  * [HIGH] CVE-2026-56859 in stdlib (v1.25.11) - encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth...
  * [HIGH] CVE-2026-56860 in stdlib (v1.25.11) - net/url: golang: golang net/url: Denial of Service from quadratic complexity...
  * [HIGH] CVE-2026-56862 in stdlib (v1.25.11) - crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUp...
  * [LOW] CVE-2026-54874 in libssl3 (3.0.2-0ubuntu1.26), openssl (3.0.2-0ubuntu1.26) - openssl: excessive memory use buffering DTLS records for a future epoch
  * [LOW] CVE-2026-63074 in libssl3 (3.0.2-0ubuntu1.26), openssl (3.0.2-0ubuntu1.26) - openssl: CMP indefinite cache growth of ExtraCerts
  * [LOW] CVE-2026-75803 in libssl3 (3.0.2-0ubuntu1.26), openssl (3.0.2-0ubuntu1.26) - Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty...
  * [LOW] CVE-2026-8932 in curl (7.81.0-1ubuntu1.26), libcurl4 (7.81.0-1ubuntu1.26) - libcurl: libcurl: Security feature bypass due to improper mTLS connection reu...
  * [MEDIUM] CVE-2026-12087 in perl-base (5.34.0-3ubuntu1.7) - perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read
  * [MEDIUM] CVE-2026-13221 in perl-base (5.34.0-3ubuntu1.7) - perl: Perl: Incorrect regular expression processing via large regular express...
  * [MEDIUM] CVE-2026-42505 in stdlib (v1.25.11) - crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client...
  * [MEDIUM] CVE-2026-57432 in perl-base (5.34.0-3ubuntu1.7) - perl: Perl: Information disclosure via integer overflow in pack/unpack operat...
  * [MEDIUM] CVE-2026-57433 in perl-base (5.34.0-3ubuntu1.7) - Storable: Storable: Denial of Service via signed integer overflow in deserial...
  * [MEDIUM] CVE-2026-63072 in libssl3 (3.0.2-0ubuntu1.26), openssl (3.0.2-0ubuntu1.26) - openssl: heap buffer overflow in CMS key unwrapping
  * [MEDIUM] CVE-2026-63076 in libssl3 (3.0.2-0ubuntu1.26), openssl (3.0.2-0ubuntu1.26) - openssl: invalid pointer dereference in CMP server via crafted protectionAlg
 -- azcu-bot <azcu-publishing@microsoft.com>  Wed, 26 Aug 2026 00:00:00 +0000

