CVE-2026-50593

Publication date 5 June 2026

Last updated 18 June 2026


Ubuntu priority

Cvss 3 Severity Score

7.3 · High

Score breakdown

Description

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

Status

Package Ubuntu Release Status
graphite2 26.04 LTS resolute
Fixed 1.3.14-11ubuntu1.1
25.10 questing
Fixed 1.3.14-2ubuntu1.3
24.04 LTS noble
Fixed 1.3.14-2ubuntu0.24.04.1
22.04 LTS jammy
Fixed 1.3.14-1ubuntu0.1
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
graphite2

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.3 · High

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H


Access our resources on patching vulnerabilities