USN-8642-1

Source
https://ubuntu.com/security/notices/USN-8642-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8642-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-8642-1
Upstream
Related
Published
2026-08-18T13:02:22Z
Modified
2026-08-18T22:14:59.705602179Z
Summary
c3p0 vulnerabilities
Details

It was discovered that c3p0 was vulnerable to remote code execution via maliciously crafted serialized objects and JNDI references. An attacker could use this to execute arbitrary code, bypass security restrictions, or cause a denial of service.

References

Affected packages

Ubuntu:Pro:18.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-9+deb8u1ubuntu0.18.04.1+esm1

Affected versions

0.*
0.9.1.2-9
0.9.1.2-9+deb8u1build0.18.04.1
0.9.1.2-9+deb8u1ubuntu0.18.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.9.1.2-9+deb8u1ubuntu0.18.04.1+esm1",
            "binary_name": "libc3p0-java"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:18.04:LTS",
    "cves": []
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8642-1.json"

Ubuntu:Pro:20.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-10ubuntu0.20.04.1+esm1

Affected versions

0.*
0.9.1.2-10
0.9.1.2-10ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.9.1.2-10ubuntu0.20.04.1+esm1",
            "binary_name": "libc3p0-java"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:20.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type": "CVSS_V4"
                },
                {
                    "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2026-27727"
        },
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type": "CVSS_V4"
                },
                {
                    "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2026-27830"
        },
        {
            "severity": [
                {
                    "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2026-55153"
        },
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2026-55223"
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8642-1.json"

Ubuntu:Pro:22.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-10ubuntu1+esm1

Affected versions

0.*
0.9.1.2-10
0.9.1.2-10ubuntu1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libc3p0-java",
            "binary_version": "0.9.1.2-10ubuntu1+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:Pro:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8642-1.json"

Ubuntu:Pro:24.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-10ubuntu2+esm1

Affected versions

0.*
0.9.1.2-10ubuntu1
0.9.1.2-10ubuntu2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.9.1.2-10ubuntu2+esm1",
            "binary_name": "libc3p0-java"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:24.04:LTS",
    "cves": []
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8642-1.json"

Ubuntu:Pro:26.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps%2Fresolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-11ubuntu0.1~esm1

Affected versions

0.*
0.9.1.2-10ubuntu2
0.9.1.2-11

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libc3p0-java",
            "binary_version": "0.9.1.2-11ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:26.04:LTS",
    "cves": []
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8642-1.json"