{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* Bump epoch to supersede the vendor package in the ELS channel\n     (matches the ubuntu16/ubuntu18 ELS branches).\n   * Add gpg to Build-Depends: the build-time test suite\n     (uaclient/tests/test_gpg.py) invokes the gpg binary, which is not\n     present in the minimal ELS build chroot.\n   * Add debian/mark_skip_pytests.sh and invoke it from debian/rules:\n     on FIPS-capable build hosts running in a disabled state, some\n     status/FIPS pytests fail at build time; skip only those, only in\n     that environment (matches the ubuntu16/ubuntu18 ELS branches).\n   * Skip tools/check-versions-are-consistent.py in override_dh_auto_build:\n     its regex does not handle a package epoch and misparses our\n     1:34~20.04+tuxcare.elsN version, aborting the build; version.py\n     already matches the shipped upstream version (34).\n   * SECURITY UPDATE: Pro bearer token exposed via apt-helper command line\n     - Write APT credentials to a temporary 0600 auth file and pass a\n       credential-free URL to apt-helper, instead of embedding the token in\n       the download-file URL argument where it leaked to local users via\n       /proc/<pid>/cmdline. Source tarball re-packed with the fix (3.0 native).\n     - cve-2026-9494\n   * SECURITY UPDATE: APT source injection via crafted contract-server response\n     - validate contract directives (aptURL, suites, additionalPackages) to\n       reject newline/CR/NUL/space characters, preventing injection of\n       attacker-controlled lines into root-owned apt sources and the apt-get\n       install invocation. Source tarball re-packed with the fix (3.0 native).\n     - cve-2026-11386\n   * SECURITY UPDATE: symlink file disclosure in \"pro collect-logs\"\n     - Skip symlinked user log files and create the diagnostic archive\n       exclusively (x:gz) with a root-only umask so an existing output file or\n       symlink is not followed or overwritten. Source tarball re-packed with\n       the fix (3.0 native).\n     - cve-2026-12391",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu20.04els/advisories/2026/clsa-2026_1785340982.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-29T16:03:49Z",
      "generator": {
        "date": "2026-07-29T16:03:49Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1785340982",
      "initial_release_date": "2026-07-29T16:03:49Z",
      "revision_history": [
        {
          "date": "2026-07-29T16:03:49Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2026-11386, CVE-2026-12391, CVE-2026-9494"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 20.04",
                "product": {
                  "name": "Ubuntu 20.04",
                  "product_id": "Ubuntu-20",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64",
                "product": {
                  "name": "ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64",
                  "product_id": "ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ubuntu-pro-client-l10n@1:34~20.04%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
                "product": {
                  "name": "ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
                  "product_id": "ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ubuntu-pro-client@1:34~20.04%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
                "product": {
                  "name": "ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
                  "product_id": "ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ubuntu-advantage-pro@1:34~20.04%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
                "product": {
                  "name": "ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
                  "product_id": "ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ubuntu-advantage-tools@1:34~20.04%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
                "product": {
                  "name": "ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
                  "product_id": "ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ubuntu-pro-auto-attach@1:34~20.04%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
        },
        "product_reference": "ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all"
        },
        "product_reference": "ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all"
        },
        "product_reference": "ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all"
        },
        "product_reference": "ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64"
        },
        "product_reference": "ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-12391",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
          "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-12391"
        },
        {
          "category": "external",
          "summary": "https://ubuntu.com/security/CVE-2026-12391",
          "url": "https://ubuntu.com/security/CVE-2026-12391"
        }
      ],
      "release_date": "2026-07-16T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-29T16:03:03.767956Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982",
          "product_ids": [
            "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
            "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-11386",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
          "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-11386"
        },
        {
          "category": "external",
          "summary": "https://ubuntu.com/security/CVE-2026-11386",
          "url": "https://ubuntu.com/security/CVE-2026-11386"
        }
      ],
      "release_date": "2026-07-16T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-29T16:03:03.767956Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982",
          "product_ids": [
            "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
            "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9494",
      "cwe": {
        "id": "CWE-214",
        "name": "Invocation of Process Using Visible Sensitive Information"
      },
      "notes": [
        {
          "category": "description",
          "text": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in\nthe cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can\nmonitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
          "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
          "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-9494"
        },
        {
          "category": "external",
          "summary": "https://ubuntu.com/security/CVE-2026-9494",
          "url": "https://ubuntu.com/security/CVE-2026-9494"
        }
      ],
      "release_date": "2026-07-16T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-29T16:03:03.767956Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982",
          "product_ids": [
            "Ubuntu-20:ubuntu-advantage-pro-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-advantage-tools-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-pro-auto-attach-1:34~20.04+tuxcare.els1.all",
            "Ubuntu-20:ubuntu-pro-client-1:34~20.04+tuxcare.els1.amd64",
            "Ubuntu-20:ubuntu-pro-client-l10n-1:34~20.04+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785340982"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}