UBUNTU-CVE-2026-4541

Source
https://ubuntu.com/security/CVE-2026-4541
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-4541
Upstream
Published
2026-03-22T09:15:00Z
Modified
2026-05-26T19:29:26.033218683Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/cryptosigned25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this issue. Patch name: 9c87269607e0d7d20174df742accc49c042cff17. Upgrading the affected component is recommended.

References

Affected packages

Ubuntu:18.04:LTS
tinyssh

Package

Name
tinyssh
Purl
pkg:deb/ubuntu/tinyssh?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20180101-1
20180201-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20180201-1",
            "binary_name": "tinysshd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json"
Ubuntu:20.04:LTS
tinyssh

Package

Name
tinyssh
Purl
pkg:deb/ubuntu/tinyssh?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20190101-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20190101-1build1",
            "binary_name": "tinysshd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json"
Ubuntu:22.04:LTS
tinyssh

Package

Name
tinyssh
Purl
pkg:deb/ubuntu/tinyssh?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20190101-1build1
20190101-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20190101-1ubuntu1",
            "binary_name": "tinysshd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json"
Ubuntu:24.04:LTS
tinyssh

Package

Name
tinyssh
Purl
pkg:deb/ubuntu/tinyssh?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20230101-2
20230101-3
20230101-4
20240101-1
20240101-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20240101-2",
            "binary_name": "tinysshd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json"
Ubuntu:25.10
tinyssh

Package

Name
tinyssh
Purl
pkg:deb/ubuntu/tinyssh?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20250201-1
20250501-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20250501-1",
            "binary_name": "tinysshd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json"
Ubuntu:26.04:LTS
tinyssh

Package

Name
tinyssh
Purl
pkg:deb/ubuntu/tinyssh?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20250501-1
20250501-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20250501-2",
            "binary_name": "tinysshd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4541.json"