UBUNTU-CVE-2026-47191

Source
https://ubuntu.com/security/CVE-2026-47191
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47191.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-47191
Upstream
Published
2026-08-14T17:18:00Z
Modified
2026-08-19T13:31:54Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository. This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5.3 fixes the issue. As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party. If available, additional validate cryptographically signed commits or tags. Alternatively, mirror the repository to a save place, validate its integrity, and use this instead of the original one.

References

Affected packages

Ubuntu:22.04:LTS / kas

Package

Name
kas
Purl
pkg:deb/ubuntu/kas?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.3.3-2
2.5-1
2.6.3-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "kas",
            "binary_version": "2.6.3-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47191.json"

Ubuntu:24.04:LTS / kas

Package

Name
kas
Purl
pkg:deb/ubuntu/kas?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "kas",
            "binary_version": "4.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47191.json"

Ubuntu:25.10 / kas

Package

Name
kas
Purl
pkg:deb/ubuntu/kas?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.7-1
4.8.1-1
4.8.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "kas",
            "binary_version": "4.8.1-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47191.json"

Ubuntu:26.04:LTS / kas

Package

Name
kas
Purl
pkg:deb/ubuntu/kas?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.1-2
5.*
5.0-1
5.1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "kas",
            "binary_version": "5.1-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47191.json"