Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-12249: Ubuntu ADSys uses less trusted source code
CVE-2026-12249 · published 4 days ago
Summary
The ADSys component provided by Ubuntu includes code from a source that is not fully trusted. This could allow a malicious change to be introduced into the software, potentially affecting systems that rely on it. Update to a version newer than v0.16.3-0.20250318112551-8b1939f96d38 or apply patches from the official Ubuntu repository to resolve the issue.
What to do
- Update ubuntu github.com/ubuntu/adsys to version 0.16.3-0.20250318112551-8b1939f96d38.
- Update github.com ubuntu to version 0.16.3-0.20250318112551-8b1939f96d38.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Go | ubuntu | github.com/ubuntu/adsys |
< 0.16.3-0.20250318112551-8b1939f96d38 Fix: upgrade to 0.16.3-0.20250318112551-8b1939f96d38
|
| go | github.com | ubuntu |
< 0.16.3-0.20250318112551-8b1939f96d38 Fix: upgrade to 0.16.3-0.20250318112551-8b1939f96d38
|
Original advisory text
Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys
Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/ubuntu/adsys before v0.16.3-0.20250318112551-8b1939f96d38.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/ubuntu/adsys before v0.16.3-0.20250318112551-8b1939f96d38.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-12249 Vendor Advisory
- https://github.com/ubuntu/adsys/commit/8b1939f96d3827b4426eb06c1ced5bf317b0a99d Patch
- https://github.com/ubuntu/adsys/releases/tag/v0.16.3 URL
- https://github.com/advisories/GHSA-crm4-q7v4-c2r2 Vendor Advisory
- https://github.com/ubuntu URL
- https://launchpad.net/ubuntu/+source/adsys URL
- https://launchpad.net/ubuntu/focal URL
- https://launchpad.net/ubuntu/jammy URL
- https://launchpad.net/ubuntu/noble URL
- https://launchpad.net/ubuntu/questing URL
- https://launchpad.net/ubuntu/resolute URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12249... Vendor Advisory
- https://github.com/ubuntu/adsys Product
- https://ubuntu.com/security/CVE-2026-12249 URL
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-348Use of Less Trusted Source
Timeline
Published28 Sep 2026
Updated30 Sep 2026
First seen22 Jun 2026
Sources
CVE-2026-12249 · NVD
GHSA-crm4-q7v4-c2r2 · GHSA
CVE-2026-12249 · OSV
GHSA-crm4-q7v4-c2r2 · OSV
GO-2026-6543 · OSV
Track software like this
Free during beta