Aggregator

USN-8839-1: Atril vulnerabilities

6 days 10 hours ago
It was discovered that Atril did not properly sanitize command-line arguments in PDF /GoToR actions. If a user opened a specially crafted PDF file, an attacker could possibly use this issue to execute arbitrary code. (CVE-2026-46529) It was discovered that Atril incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-1010006) Andy Nguyen discovered that Atril incorrectly handled certain images. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)

USN-8838-1: catdoc vulnerabilities

6 days 10 hours ago
It was discovered that catdoc had an integer overflow when processing shared string tables in malformed spreadsheet files. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. (CVE-2024-48877) It was discovered that catdoc had an integer overflow when processing file allocation tables in malformed document files. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. (CVE-2024-52035) It was discovered that catdoc incorrectly validated sector sizes when processing malformed document files, leading to an integer underflow. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. (CVE-2024-54028)

USN-8835-1: Emacs vulnerability

6 days 11 hours ago
It was discovered that Emacs improperly handled specially crafted SVG images, resulting in memory corruption. An attacker could possibly use this issue to cause Emacs to crash, resulting in a denial of service, or obtain sensitive information.

USN-8830-1: phpseclib vulnerabilities

6 days 11 hours ago
It was discovered that phpseclib did not perform constant-time padding validation when using AES in CBC mode. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-32935) It was discovered that phpseclib did not use a constant-time comparison when validating SSH packet authentication codes. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-40194) It was discovered that phpseclib did not properly limit object identifier lengths when parsing ASN.1 data. An attacker could possibly use this issue to cause phpseclib to use excessive resources, leading to a denial of service. (CVE-2026-44167)

USN-8828-1: dracut vulnerabilities

6 days 12 hours ago
It was discovered that dracut created initramfs images with overly permissive permissions under certain circumstances. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-8637) It was discovered that dracut did not properly sanitize DHCP options before writing them to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893) It was discovered that dracut did not properly quote error messages written to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-15816) It was discovered that dracut did not properly sanitize network configuration data before writing it to a temporary shell script under certain circumstances. A remote attacker controlling DHCP on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 22.04 LTS. (CVE-2026-16445)

USN-8827-1: Erlang vulnerabilities

6 days 12 hours ago
It was discovered that the Erlang Port Mapper Daemon did not properly handle slow connections. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-42792) It was discovered that Erlang incorrectly handled certain external term format data, leading to heap corruption. An attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-55737) It was discovered that Erlang incorrectly handled invalid external term format data. An attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54890) It was discovered that Erlang incorrectly handled certain packet lengths, leading to a buffer overflow. A remote attacker could possibly use this issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538) It was discovered that the Erlang Megaco flex scanner incorrectly handled certain input, leading to a buffer overflow. A remote attacker could possibly use this issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-59250) It was discovered that Erlang TLS clients incorrectly accepted cipher suites that they had not offered. A remote attacker could possibly use this issue to intercept and modify TLS communications. (CVE-2026-55953) It was discovered that Erlang incorrectly handled certain certificate chains. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58227) It was discovered that Erlang incorrectly handled certain certificate policies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59251) It was discovered that the Erlang HTTP server incorrectly handled certain conflicting HTTP framing headers. A remote attacker could possibly use this issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812) It was discovered that the Erlang HTTP server incorrectly handled certain malformed chunk sizes. A remote attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664) It was discovered that the Erlang HTTP server did not properly limit the size of chunked request bodies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-74835) It was discovered that the Erlang HTTP server incorrectly handled certain equivalent request paths and differences in character case. A remote attacker could possibly use this issue to bypass authentication and gain unauthorized access. (CVE-2026-66835, CVE-2026-73270) It was discovered that the Erlang HTTP server did not properly limit simultaneous connections. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-70399) It was discovered that the Erlang HTTP server incorrectly handled header continuation lines. A remote attacker could possibly use this issue to smuggle HTTP requests. (CVE-2026-66357) It was discovered that the Erlang HTTP server incorrectly handled certain malformed header names. A remote attacker could possibly use this issue to smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-73276) It was discovered that the Erlang HTTP server incorrectly handled incomplete request bodies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-71380) It was discovered that the Erlang HTTP client did not properly limit the size of HTTP response headers. A malicious HTTP server could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-55951) It was discovered that Erlang did not properly limit the length of port numbers when parsing URIs. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696) It was discovered that the Erlang SNMP application did not properly limit the size of certain integer values. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-70405) It was discovered that the Erlang LDAP client did not properly limit the length of port numbers in referral URLs. A malicious LDAP server could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-70409)

USN-8836-1: FreeRDP vulnerabilities

6 days 13 hours ago
It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.

USN-8834-1: Exim vulnerabilities

6 days 13 hours ago
It was discovered that Exim had an out-of-bounds write when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-94054) It was discovered that Exim had a use-after-free when certain non-default TLS settings were used with GnuTLS. A remote attacker could possibly use this issue to cause Exim to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-94055) It was discovered that Exim allowed attackers to read uninitialized data from stack memory when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-94056) It was discovered that Exim allowed SMTP smuggling via crafted data sent after a rejection during DATA processing. A remote attacker could possibly use this issue to inject arbitrary email messages. (CVE-2026-94057)

USN-8833-1: libvirt vulnerabilities

6 days 13 hours ago
It was discovered that libvirt did not properly validate newline characters in DNS TXT record values and SRV record attributes in its virtual network driver. A local attacker with permission to define virtual networks could possibly use this issue to inject arbitrary dnsmasq configuration directives, leading to arbitrary command execution as root. (CVE-2026-61477) It was discovered that libvirt did not properly handle errors during XML context parsing. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2026-61478) He Wei discovered that libvirt had a symlink-following vulnerability in the file ownership change function used for virtual TPM state directories. A local attacker running as the swtpm user could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading to privilege escalation. (CVE-2026-63622) It was discovered that libvirt created storage volume images with overly permissive permissions during clone or convert operations. A local attacker could possibly use this issue to read guest disk contents, resulting in information disclosure. (CVE-2026-63623) It was discovered that libvirt had an integer overflow in the NodeGetFreePages RPC handler. A local attacker could possibly use this issue to cause libvirt to crash or execute arbitrary code. (CVE-2026-18917) It was discovered that libvirt had a symlink-following flaw in the virtual TPM emulator setup function. A local attacker with access to the swtpm account could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading to privilege escalation. (CVE-2026-77159)

USN-8831-1: libvirt vulnerabilities

6 days 14 hours ago
It was discovered that libvirt had an integer overflow vulnerability in the NodeGetFreePages RPC handler. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-18917) It was discovered that libvirt did not correctly handle symbolic links when changing ownership of the TPM emulator log file. A local attacker with access to the swtpm account could possibly use this issue to cause libvirt to change the ownership of an arbitrary file. (CVE-2026-77159)