UBUNTU-CVE-2026-23992

Source
https://ubuntu.com/security/CVE-2026-23992
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-23992.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-23992
Upstream
Published
2026-01-22T03:15:00Z
Modified
2026-01-30T20:32:25.902858Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

References

Affected packages

Ubuntu:24.04:LTS / golang-github-theupdateframework-go-tuf

Package

Name
golang-github-theupdateframework-go-tuf
Purl
pkg:deb/ubuntu/golang-github-theupdateframework-go-tuf@0.6.1-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.5.2-5
0.6.1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-theupdateframework-go-tuf-dev",
            "binary_version": "0.6.1-1"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-23992.json"

Ubuntu:25.10 / golang-github-theupdateframework-go-tuf

Package

Name
golang-github-theupdateframework-go-tuf
Purl
pkg:deb/ubuntu/golang-github-theupdateframework-go-tuf@2.0.2+0.7.0-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.0.2+0.7.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-theupdateframework-go-tuf-dev",
            "binary_version": "2.0.2+0.7.0-1"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-23992.json"