Aggregator

USN-8810-1: ImageMagick vulnerabilities

12 hours 3 minutes ago
It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33535) Kamil Frankowicz discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33536) It was discovered that ImageMagick did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-34238) Jake Lamberson discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40310) Junmin Zhu discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40311) It was discovered that ImageMagick did not correctly handle opening certain MSL files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly cause a denial of service. This issue affected Ubuntu 26.04 LTS. (CVE-2026-40312) It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56361)

USN-8287-2: XDG Desktop Portal regression

17 hours 44 minutes ago
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

USN-8809-1: libgit2 vulnerability

17 hours 54 minutes ago
Kazuma Matsumoto and Isabel Mill discovered that libgit2 incorrectly handled certain repository URLs when using the SSH transport. A remote attacker could possibly use this issue to execute arbitrary commands.

USN-8808-1: SQL parse vulnerabilities

18 hours 5 minutes ago
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.