Aggregator

USN-8739-1: ImageMagick vulnerabilities

5 hours 56 minutes ago
It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, CVE-2026-56373) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-56370) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56378) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379) It was discovered that ImageMagick incorrectly handled memory allocation in certain operations. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61465) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-61857) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866) It was discovered that ImageMagick incorrectly handled certain images on 32-bit systems. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-62946)

USN-8670-3: curl vulnerability

7 hours 5 minutes ago
USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

USN-8679-2: Vim vulnerability

7 hours 14 minutes ago
USN-8679-1 fixed a vulnerability in Vim. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: It was discovered that Vim incorrectly handled certain tags files. An attacker could possibly use this issue to execute arbitrary code.

USN-8738-1: FFmpeg vulnerabilities

7 hours 25 minutes ago
It was discovered that FFmpeg incorrectly handled certain video frames when using the hqdn3d filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036) Adrian Junge discovered that FFmpeg incorrectly handled certain compressed video files. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-66038) Adrian Junge discovered that FFmpeg incorrectly handled certain audio files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66039) Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectly handled certain video files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70632)

USN-8737-1: GNU C Library vulnerabilities

9 hours 8 minutes ago
It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499) It was discovered that GNU C Library had an out-of-bounds stack array access in the tdelete function. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-19542) It was discovered that GNU C Library incorrectly handled memory when calling wordexp with the WRDE_APPEND flag. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-6368) It was discovered that GNU C Library had a stack overflow in the wordexp function when expanding paths beginning with a tilde followed by a long username. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-6791) It was discovered that GNU C Library had a hang in the SHIFT_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-77117) It was discovered that GNU C Library had a hang in the EUC_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-80489)

USN-8736-1: Perl vulnerabilities

10 hours 1 minute ago
It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (CVE-2026-15534) It was discovered that Perl incorrectly handled certain regular expression containing alternative matching branches. An attacker could possibly use this issue to cause incorrect regular expression matches, resulting in security restrictions being bypassed. (CVE-2026-19487)

php-pecl-mongodb-1.20.1-3.el9

18 hours 48 minutes ago
FEDORA-EPEL-2026-d6aefc999f Packages in this update:
  • php-pecl-mongodb-1.20.1-3.el9
Update description: Backported from 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Backported from 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb-1.21.9-1.el10_2

19 hours 11 minutes ago
FEDORA-EPEL-2026-99ac8d2816 Packages in this update:
  • php-pecl-mongodb-1.21.9-1.el10_2
Update description: Version 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb2-2.1.9-1.fc44

19 hours 31 minutes ago
FEDORA-2026-358d3ccdfe Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc44
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-2.el10_2

19 hours 32 minutes ago
FEDORA-EPEL-2026-7d7ac5f0f9 Packages in this update:
  • php-pecl-mongodb2-2.1.9-2.el10_2
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968