Aggregator

USN-8810-1: ImageMagick vulnerabilities

5 hours 33 minutes ago
It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33535) Kamil Frankowicz discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33536) It was discovered that ImageMagick did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-34238) Jake Lamberson discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40310) Junmin Zhu discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40311) It was discovered that ImageMagick did not correctly handle opening certain MSL files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly cause a denial of service. This issue affected Ubuntu 26.04 LTS. (CVE-2026-40312) It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56361)

USN-8287-2: XDG Desktop Portal regression

11 hours 14 minutes ago
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

USN-8809-1: libgit2 vulnerability

11 hours 24 minutes ago
Kazuma Matsumoto and Isabel Mill discovered that libgit2 incorrectly handled certain repository URLs when using the SSH transport. A remote attacker could possibly use this issue to execute arbitrary commands.

USN-8808-1: SQL parse vulnerabilities

11 hours 34 minutes ago
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.

emacs-31.1-4.fc46

15 hours 18 minutes ago
FEDORA-2026-b3367f2111 Packages in this update:
  • emacs-31.1-4.fc46
Update description:

Automatic update for emacs-31.1-4.fc46.

Changelog * Wed Sep 23 2026 Peter Oliver <git@mavit.org.uk> - 1:31.1-4 - Prevent arbitrary code execution in flymake (rhbz#2537390).