It was discovered that Apache MINA lacked an acceptMatchers allowlist mechanism to restrict which classes could be deserialized. An attacker could use this to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-52046)
It was discovered that Apache MINA's deserialization filter could be bypassed via multiple code paths. An attacker could use this to execute arbitrary code by sending a specially crafted serialized object over the network. (CVE-2026-42778, CVE-2026-42779, CVE-2026-47065)
2.1.5-1ubuntu0.1~esm12.2.1-3ubuntu0.1~esm12.2.1-4ubuntu0.1~esm1