UBUNTU-CVE-2026-62943

Source
https://ubuntu.com/security/CVE-2026-62943
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-62943
Upstream
Published
2026-09-18T17:16:00Z
Modified
2026-09-23T23:31:26Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete command. A user restricted through an authorized_keys forced command can append a trailing pipe command after a valid btrbk command prefix, bypassing the allowlist and executing arbitrary commands with the privileges of the backup-target SSH account. Deployments that do not use ssh_filter_btrbk.sh in authorized_keys are not affected. This issue is fixed in version 0.32.7.

References

Affected packages

Ubuntu:16.04:LTS
btrbk

Package

Name
btrbk
Purl
pkg:deb/ubuntu/btrbk?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.19.3-1
0.20.0-1
0.21.0-1
0.22.0-1
0.22.1-1
0.22.2-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "btrbk",
            "binary_version":  "0.22.2-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json"
Ubuntu:18.04:LTS
btrbk

Package

Name
btrbk
Purl
pkg:deb/ubuntu/btrbk?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.25.1-1
0.26.0-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "btrbk",
            "binary_version":  "0.26.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json"
Ubuntu:20.04:LTS
btrbk

Package

Name
btrbk
Purl
pkg:deb/ubuntu/btrbk?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.27.1-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "btrbk",
            "binary_version":  "0.27.1-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json"
Ubuntu:22.04:LTS
btrbk

Package

Name
btrbk
Purl
pkg:deb/ubuntu/btrbk?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.27.1-2
0.31.3-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "btrbk",
            "binary_version":  "0.31.3-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json"
Ubuntu:24.04:LTS
btrbk

Package

Name
btrbk
Purl
pkg:deb/ubuntu/btrbk?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.32.5-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "btrbk",
            "binary_version":  "0.32.5-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json"
Ubuntu:26.04:LTS
btrbk

Package

Name
btrbk
Purl
pkg:deb/ubuntu/btrbk?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.32.6-2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "btrbk",
            "binary_version":  "0.32.6-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-62943.json"