UBUNTU-CVE-2026-82623

Source
https://ubuntu.com/security/CVE-2026-82623
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-82623.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-82623
Upstream
Published
2026-08-31T00:00:00Z
Modified
2026-08-31T22:16:02.855332152Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UADataValuebackendcopyRange of the file plugins/historydata/uahistorydatabackend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.

References

Affected packages

Ubuntu:26.04:LTS / open62541

Package

Name
open62541
Purl
pkg:deb/ubuntu/open62541?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.11.1-1
1.4.11.1-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.4.11.1-1build1",
            "binary_name": "libopen62541-1.4"
        },
        {
            "binary_version": "1.4.11.1-1build1",
            "binary_name": "libopen62541-1.4-tools"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-82623.json"