open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UAENABLEGDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
{ "binaries": [ { "binary_name": "libopen62541-1.4", "binary_version": "1.4.11.1-1build1" }, { "binary_version": "1.4.11.1-1build1", "binary_name": "libopen62541-1.4-tools" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67855.json"