Signal

Critical vulnerabilities fixed in CryptX affecting Ubuntu 18.04 LTS

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-03-26 15:54 UTCUpdated 2026-03-26 23:33 UTC
rss
cvesecurity_advisoryubuntucryptographyvulnerabilitypatch
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
CryptX: CVSS (Max): 9.8
AusCERT - Bulletins · News · portal.auscert.org.au · 2026-03-26 23:33 UTC
USN-8128-1: CryptX vulnerabilities
Ubuntu Security Notices · News · ubuntu.com · 2026-03-26 15:54 UTC
limited source diversity in top sources
Overview

Multiple severe security flaws were addressed in CryptX, a cryptographic library used in Ubuntu 18.04 LTS.

Entities
UbuntuCryptX
Score total
0.87
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Patches were released on 26 March 2026 to address these critical issues.
  • The vulnerabilities affect a widely used cryptographic library in a long-term supported OS version.
  • Prompt updates are essential to mitigate potential attacks exploiting these flaws.
Why it matters
  • CryptX vulnerabilities can lead to data integrity violations and authentication bypass.
  • High severity CVEs with CVSS up to 9.8 indicate critical risk to affected systems.
  • Ubuntu 18.04 LTS users must patch to prevent exploitation of these flaws.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • CryptX did not verify authentication tags during GCM and ChaCha20-Poly1305 decryption, allowing possible authentication bypass.
  • CryptX included a vulnerable version of the tomcrypt library susceptible to malformed Unicode handling.
  • CryptX included a vulnerable version of the libtommath library with an integer overflow leading to memory corruption or denial of service.
How sources frame it
  • Ubuntu Security Notices: neutral
This briefing consolidates critical CryptX vulnerabilities affecting Ubuntu 18.04 LTS with high severity CVEs, emphasizing the importance of timely patching to maintain system security.
All evidence
All evidence
CryptX: CVSS (Max): 9.8
AusCERT - Bulletins · portal.auscert.org.au · 2026-03-26 23:33 UTC
USN-8128-1: CryptX vulnerabilities
Ubuntu Security Notices · ubuntu.com · 2026-03-26 15:54 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • AusCERT - Bulletins (1)
  • Ubuntu Security Notices (1)
Top origin domains (this list)
  • portal.auscert.org.au (1)
  • ubuntu.com (1)