Aggregator

USN-8514-2: OpenSSH vulnerability

5 days 22 hours ago
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation.

USN-8771-1: Valkey vulnerabilities

6 days 3 hours ago
Madelyn Olson discovered that Valkey incorrectly handled TLS connections under certain conditions. A remote attacker could possibly use this issue to cause Valkey to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-56684) It was discovered that Valkey incorrectly handled certain stream RDB payloads when executing the RESTORE command. An authenticated remote attacker could possibly use this issue to cause Valkey to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63639) It was discovered that Valkey incorrectly handled cluster slot migration operations. A remote attacker could possibly use this issue to cause Valkey to crash, resulting in a denial of service. This issue was only addressed in Ubuntu 26.04 LTS. (CVE-2026-85522)

USN-8770-1: SimpleSAMLphp vulnerabilities

6 days 15 hours ago
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents. A remote attacker could possibly use this issue to obtain sensitive information. This issue did not affect Ubuntu 24.04 LTS. (CVE-2024-52596) It was discovered that SimpleSAMLphp incorrectly verified signatures in SAML messages using the HTTP-Redirect binding. A remote attacker could possibly use this issue to bypass authentication and impersonate users. (CVE-2025-27773)

USN-8769-1: phpseclib vulnerability

6 days 15 hours ago
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.

USN-8766-1: Suricata-Update vulnerability

6 days 16 hours ago
Guillem Lefait discovered that Suricata-Update did not properly validate destination paths when extracting files referenced by downloaded rule archives. An attacker could possibly use this issue to write arbitrary files outside the configured rules directory.