Skip to content

Ubuntu vulnerable package marked as fixed but new version hadn't been released #4244

@beaturmis

Description

@beaturmis

Describe the bug
Bumped into a problem with UBUNTU-CVE-2024-38541 on July, 15 2025
Package linux was marked as fixed with version 5.15.0-144.157 in OSV.
But the fixed package version hadn't been released by Ubuntu at that moment. So there was a temporary inconsistency in OSV DB which led to providing false information about available fixes.

Expected behaviour
Information about fixed versions is provided only in case packages have been published to Ubuntu repositories.

Screenshots

OSV DB info with fixed version

Image

Screenshot from Ubuntu CVE info page showing "Work in progress"
Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions