{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "gpgv"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "gpgv",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.4-2ubuntu17.4",
                    "version": "2.4.4-2ubuntu17.4"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.4-2ubuntu17.6",
                    "version": "2.4.4-2ubuntu17.6"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.4-2ubuntu17.6",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:38:56 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 24.04 noble image from daily image serial 20260902 to 20260903",
    "from_series": "noble",
    "to_series": "noble",
    "from_serial": "20260902",
    "to_serial": "20260903",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}