U

Ubuntu Security Notices

U
Ubuntu Security Notices Security

USN-8776-1: python-cryptography vulnerabilities

It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with obs…

U
Ubuntu Security Notices Security

USN-8774-1: libheif vulnerabilities

Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna discovered that libheif incorrectly handled certain image sequences. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-62377)

U
Ubuntu Security Notices Security

USN-8736-2: Perl vulnerabilities

USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (C…

U
Ubuntu Security Notices Security

USN-8773-1: GNU Guix vulnerability

It was discovered that GNU Guix incorrectly made build outputs accessible to local users before their file metadata was finalized. A local attacker could possibly use this issue to gain elevated privileges.

U
Ubuntu Security Notices Security

USN-8772-1: AOM vulnerabilities

It was discovered that AOM incorrectly handled the first-pass statistics buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use this issue to cause a heap buffer overflow, leading to a denial of service or possibly execute arbitrary code. (CVE-2026-56208) It was discovered that AOM incorrectly validated spatial and temporal layer IDs in the SVC (Scalable Video Coding) encoder c…

U
Ubuntu Security Notices Security

USN-8514-2: OpenSSH vulnerability

USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files…

U
Ubuntu Security Notices Security

USN-8770-1: SimpleSAMLphp vulnerabilities

It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents.…

U
Ubuntu Security Notices Security

USN-8769-1: phpseclib vulnerability

It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.

U
Ubuntu Security Notices Security

USN-8768-1: Shibboleth vulnerability

Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information.

U
Ubuntu Security Notices Security

USN-8766-1: Suricata-Update vulnerability

Guillem Lefait discovered that Suricata-Update did not properly validate destination paths when extracting files referenced by downloaded rule archives. An attacker could possibly use this issue to write arbitrary files outside the configured rules directory.

U
Ubuntu Security Notices Security

USN-8764-1: SRT vulnerabilities

It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an encrypted connection and inject arbitrary content or interrupt a media stream. (CVE-2026-55868) It was discovered that SRT did not properly validate certain control packets during connection setup and key refresh operations. A remote attacker could po…

U
Ubuntu Security Notices Security

USN-8763-1: kitty vulnerabilities

It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-42850) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privile…

U
Ubuntu Security Notices Security

USN-8761-1: Linux kernel (Azure) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPU drivers; - Hardware…

U
Ubuntu Security Notices Security

USN-8760-1: Linux kernel (NVIDIA) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - ARM64 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Accelera…

U
Ubuntu Security Notices Security

USN-8758-1: dracut vulnerability

It was discovered that dracut did not properly shell-quote messages written by the die() function to the emergency hook directory. An attacker on the adjacent network controlling a rogue DHCP server could use this issue to inject commands that execute as root during boot-failure handling. (CVE-2026-15816)

U
Ubuntu Security Notices Security

USN-8739-2: ImageMagick vulnerabilities

USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04…

U
Ubuntu Security Notices Security

USN-8757-1: cgit vulnerability

It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensitive information.

U
Ubuntu Security Notices Security

USN-8756-1: Yelp vulnerability

It was discovered that Yelp allowed help documents to execute arbitrary scripts. An attacker could possibly use this issue to trick a user into opening a specially crafted help document and obtain sensitive information.

U
Ubuntu Security Notices Security

USN-8755-1: libvips vulnerability

It was discovered that libvips incorrectly handled specially crafted TIFF images when saving them as HEIF images. An attacker could possibly use this issue to cause libvips to crash, resulting in a denial of service.

U
Ubuntu Security Notices Security

USN-8754-1: Freeciv vulnerability

It was discovered that Freeciv incorrectly handled certain network packets, resulting in a stack overflow. A remote attacker could possibly use this issue to cause Freeciv clients or servers to crash, resulting in a denial of service.

U
Ubuntu Security Notices Security

USN-8563-5: nginx vulnerability

USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was backed out in USN-8563-2 because it could cause a regression. This update includes a better fix for CVE-2026-42533. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use thi…

U
Ubuntu Security Notices Security

USN-8750-1: FFmpeg vulnerabilities

Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-12706) Xinghang Lv discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted fil…

U
Ubuntu Security Notices Security

USN-8749-1: CivetWeb vulnerabilities

It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-55763) It was discovered that CivetWeb did not correctly handle parsing certain HTTP requests. A remote attacker could possibly use this issue…