6 hours 23 minutes ago
It was discovered that Rclone incorrectly handled unauthenticated requests
to the remote control API. An attacker could possibly use this issue to
execute arbitrary commands as the user invoking rclone. (CVE-2026-49980)
8 hours 10 minutes ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- User-space API (UAPI);
- Kernel build system;
- ARM32 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Cryptographic API;
- Intel NPU Driver;
- Compute Acceleration Framework;
- ACPI drivers;
- Drivers core;
- DRBD Distributed Replicated Block Device drivers;
- Rados block device (RBD) driver;
- Ublk userspace block driver;
- Compressed RAM block device driver;
- Bluetooth drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- FPGA Framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- I2C subsystem;
- I3C subsystem;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Mouse) drivers;
- IOMMU subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Mellanox network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- MediaTek network drivers;
- NVME drivers;
- Operating Performance Points (OPP) driver;
- PCI subsystem;
- PTP clock framework;
- RPMSG subsystem;
- SCSI subsystem;
- SoundWire subsystem;
- SPI subsystem;
- Greybus lights staging drivers;
- Media staging drivers;
- NVIDIA Tegra embedded controller (NVEC) staging driver;
- Realtek RTL8723BS SDIO drivers;
- TCM subsystem;
- Trusted Execution Environment drivers;
- Thunderbolt and USB4 drivers;
- TTY drivers;
- USB Gadget drivers;
- USB Dual Role (OTG-ready) Controller drivers;
- USB Serial drivers;
- vDPA drivers;
- VFIO drivers;
- Virtio Host (VHOST) subsystem;
- Virtio drivers;
- Xen hypervisor drivers;
- 9P distributed file system;
- AFS file system;
- File systems infrastructure;
- BTRFS file system;
- Ceph distributed file system;
- exFAT file system;
- F2FS file system;
- GFS2 file system;
- HFS file system;
- HFS+ file system;
- JFS file system;
- Network file systems library;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- NTFS3 file system;
- OCFS2 file system;
- OrangeFS file system;
- SMB network file system;
- BPF subsystem;
- File system encryption (fscrypt);
- Software nodes and device properties;
- IPv4 networking;
- KVM subsystem;
- Mellanox drivers;
- Memory management;
- Networking core;
- Netfilter;
- Socket messages infrastructure;
- MediaTek SoC drivers;
- Sun RPC protocol;
- Network traffic control;
- IPv6 networking;
- Amateur Radio drivers;
- Bluetooth subsystem;
- IP tunnels definitions;
- KCM (Kernel Connection Multiplexor) sockets driver;
- MultiProtocol Label Switching driver;
- TCP network protocol;
- XFRM subsystem;
- Tracing infrastructure;
- io_uring subsystem;
- Control group (cgroup);
- Perf events;
- IRQ subsystem;
- Locking primitives;
- KProbes tracing;
- 9P file system network protocol;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- CAN network layer;
- Ceph Core library;
- Handshake API;
- HSR network protocol;
- IFE protocol;
- L2TP protocol;
- MAC80211 subsystem;
- IEEE 802.15.4 subsystem;
- Multipath TCP;
- NFC subsystem;
- Open vSwitch;
- Phonet protocol;
- RDS protocol;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- X.25 network layer;
- eXpress Data Path;
- Rust bindings mechanism;
- AppArmor security module;
- Key management;
- Linux Security Modules (LSM) Framework;
- SELinux security module;
- ALSA framework;
- AudioScience HPI driver;
- Intel ASoC drivers;
- USB sound devices;
(CVE-2024-14040, CVE-2024-35948, CVE-2024-41008, CVE-2024-43872,
CVE-2024-44932, CVE-2024-44964, CVE-2024-49932, CVE-2024-49940,
CVE-2024-50106, CVE-2024-50217, CVE-2024-52560, CVE-2024-53098,
CVE-2024-56552, CVE-2024-56591, CVE-2024-57857, CVE-2024-58089,
CVE-2024-58094, CVE-2024-58098, CVE-2024-58100, CVE-2024-58241,
CVE-2025-21687, CVE-2025-21693, CVE-2025-21984, CVE-2025-21985,
CVE-2025-22104, CVE-2025-22108, CVE-2025-22109, CVE-2025-23132,
CVE-2025-37776, CVE-2025-37876, CVE-2025-37906, CVE-2025-38064,
CVE-2025-38069, CVE-2025-38187, CVE-2025-38204, CVE-2025-38206,
CVE-2025-38242, CVE-2025-38498, CVE-2025-38563, CVE-2025-38565,
CVE-2025-38636, CVE-2025-38717, CVE-2025-39677, CVE-2025-39789,
CVE-2025-39859, CVE-2025-39862, CVE-2025-39896, CVE-2025-39933,
CVE-2025-39958, CVE-2025-39990, CVE-2025-40025, CVE-2025-40040,
CVE-2025-40054, CVE-2025-40064, CVE-2025-40074, CVE-2025-40075,
CVE-2025-40139, CVE-2025-40158, CVE-2025-40168, CVE-2025-40170,
CVE-2025-40203, CVE-2025-40274, CVE-2025-40344, CVE-2025-40354,
CVE-2025-68174, CVE-2025-68304, CVE-2025-68360, CVE-2025-68745,
CVE-2025-68822, CVE-2025-71073, CVE-2025-71074, CVE-2025-71202,
CVE-2025-71289, CVE-2026-23208, CVE-2026-23239, CVE-2026-23240,
CVE-2026-23327, CVE-2026-23393, CVE-2026-23469, CVE-2026-31420,
CVE-2026-31479, CVE-2026-31486, CVE-2026-31493, CVE-2026-31560,
CVE-2026-31568, CVE-2026-31630, CVE-2026-31663, CVE-2026-31771,
CVE-2026-43009, CVE-2026-43029, CVE-2026-43042, CVE-2026-43048,
CVE-2026-43101, CVE-2026-43116, CVE-2026-43126, CVE-2026-43172,
CVE-2026-43213, CVE-2026-43263, CVE-2026-43303, CVE-2026-43352,
CVE-2026-43353, CVE-2026-43464, CVE-2026-45850, CVE-2026-45894,
CVE-2026-45932, CVE-2026-45944, CVE-2026-46054, CVE-2026-46130,
CVE-2026-46158, CVE-2026-46170, CVE-2026-46175, CVE-2026-46181,
CVE-2026-46203, CVE-2026-46275, CVE-2026-46315, CVE-2026-46320,
CVE-2026-46324, CVE-2026-46330, CVE-2026-52908, CVE-2026-52909,
CVE-2026-52910, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52934, CVE-2026-52941, CVE-2026-52956,
CVE-2026-52988, CVE-2026-52991, CVE-2026-53000, CVE-2026-53005,
CVE-2026-53009, CVE-2026-53024, CVE-2026-53025, CVE-2026-53053,
CVE-2026-53070, CVE-2026-53078, CVE-2026-53089, CVE-2026-53090,
CVE-2026-53091, CVE-2026-53109, CVE-2026-53118, CVE-2026-53120,
CVE-2026-53129, CVE-2026-53131, CVE-2026-53132, CVE-2026-53133,
CVE-2026-53148, CVE-2026-53159, CVE-2026-53182, CVE-2026-53183,
CVE-2026-53185, CVE-2026-53186, CVE-2026-53196, CVE-2026-53198,
CVE-2026-53216, CVE-2026-53217, CVE-2026-53221, CVE-2026-53230,
CVE-2026-53232, CVE-2026-53239, CVE-2026-53250, CVE-2026-53254,
CVE-2026-53256, CVE-2026-53262, CVE-2026-53264, CVE-2026-53266,
CVE-2026-53269, CVE-2026-53270, CVE-2026-53273, CVE-2026-53275,
CVE-2026-53281, CVE-2026-53284, CVE-2026-53354, CVE-2026-53355,
CVE-2026-53357, CVE-2026-53358, CVE-2026-53361, CVE-2026-53368,
CVE-2026-53384, CVE-2026-53398, CVE-2026-53399, CVE-2026-63795,
CVE-2026-63796, CVE-2026-63797, CVE-2026-63800, CVE-2026-63801,
CVE-2026-63804, CVE-2026-63807, CVE-2026-63808, CVE-2026-63815,
CVE-2026-63818, CVE-2026-63825, CVE-2026-63828, CVE-2026-63829,
CVE-2026-63830, CVE-2026-63831, CVE-2026-63853, CVE-2026-63858,
CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63893,
CVE-2026-63906, CVE-2026-63912, CVE-2026-63914, CVE-2026-63915,
CVE-2026-63916, CVE-2026-63917, CVE-2026-63919, CVE-2026-63921,
CVE-2026-63922, CVE-2026-63924, CVE-2026-63926, CVE-2026-63940,
CVE-2026-63944, CVE-2026-63945, CVE-2026-63946, CVE-2026-63947,
CVE-2026-63948, CVE-2026-63952, CVE-2026-63974, CVE-2026-63975,
CVE-2026-63976, CVE-2026-63978, CVE-2026-63979, CVE-2026-63980,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64010, CVE-2026-64011,
CVE-2026-64015, CVE-2026-64018, CVE-2026-64025, CVE-2026-64029,
CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039,
CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051,
CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073,
CVE-2026-64076, CVE-2026-64077, CVE-2026-64082, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64091, CVE-2026-64092,
CVE-2026-64093, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098,
CVE-2026-64099, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106,
CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64112,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64117, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125,
CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133,
CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137,
CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148,
CVE-2026-64153, CVE-2026-64155, CVE-2026-64160, CVE-2026-64163,
CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170,
CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178,
CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183,
CVE-2026-64184, CVE-2026-64185, CVE-2026-64191, CVE-2026-64206,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64237, CVE-2026-64247, CVE-2026-64249, CVE-2026-64268,
CVE-2026-64269, CVE-2026-64280, CVE-2026-64303, CVE-2026-64313,
CVE-2026-64315, CVE-2026-64319, CVE-2026-64320, CVE-2026-64355,
CVE-2026-64361, CVE-2026-64364, CVE-2026-64382, CVE-2026-64383,
CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387,
CVE-2026-64390, CVE-2026-64391, CVE-2026-64392, CVE-2026-64393,
CVE-2026-64394, CVE-2026-64396, CVE-2026-64397, CVE-2026-64399,
CVE-2026-64400, CVE-2026-64408, CVE-2026-64438, CVE-2026-64441,
CVE-2026-64445, CVE-2026-64450, CVE-2026-64475, CVE-2026-64510,
CVE-2026-64518, CVE-2026-64523, CVE-2026-64529, CVE-2026-64530,
CVE-2026-64534, CVE-2026-64535, CVE-2026-64541, CVE-2026-64548,
CVE-2026-64551, CVE-2026-64552, CVE-2026-64554, CVE-2026-64555,
CVE-2026-64557, CVE-2026-64561, CVE-2026-64562, CVE-2026-64564,
CVE-2026-64586, CVE-2026-64597, CVE-2026-64598, CVE-2026-68082,
CVE-2026-68083, CVE-2026-68117, CVE-2026-68123, CVE-2026-68124,
CVE-2026-68127, CVE-2026-68136, CVE-2026-68137, CVE-2026-68138,
CVE-2026-68144, CVE-2026-68147, CVE-2026-68152, CVE-2026-68154,
CVE-2026-68156, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160,
CVE-2026-68161, CVE-2026-68162, CVE-2026-68198, CVE-2026-68206,
CVE-2026-68209, CVE-2026-68210, CVE-2026-68213, CVE-2026-68228,
CVE-2026-68229, CVE-2026-68300, CVE-2026-68302, CVE-2026-68343,
CVE-2026-68381, CVE-2026-68388, CVE-2026-68426, CVE-2026-68431,
CVE-2026-68457, CVE-2026-68461, CVE-2026-68470, CVE-2026-68476,
CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033,
CVE-2026-72041, CVE-2026-72065, CVE-2026-72069, CVE-2026-72071,
CVE-2026-72083, CVE-2026-72084, CVE-2026-72085, CVE-2026-72098,
CVE-2026-72111, CVE-2026-72124, CVE-2026-72125, CVE-2026-72126,
CVE-2026-72129, CVE-2026-72130, CVE-2026-72191, CVE-2026-72192,
CVE-2026-72194, CVE-2026-72200, CVE-2026-72217, CVE-2026-72221,
CVE-2026-72222, CVE-2026-72226, CVE-2026-72234, CVE-2026-72251,
CVE-2026-72255, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296,
CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319,
CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329,
CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72380,
CVE-2026-72383, CVE-2026-72398, CVE-2026-72399, CVE-2026-72421,
CVE-2026-72422, CVE-2026-72434, CVE-2026-72436, CVE-2026-72451,
CVE-2026-72454, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473,
CVE-2026-72487, CVE-2026-72488, CVE-2026-72489, CVE-2026-72491,
CVE-2026-72494, CVE-2026-72495, CVE-2026-72496, CVE-2026-72499,
CVE-2026-74255, CVE-2026-74264, CVE-2026-74267, CVE-2026-74268,
CVE-2026-74269, CVE-2026-74279, CVE-2026-74280, CVE-2026-74287,
CVE-2026-74302, CVE-2026-74305, CVE-2026-74310, CVE-2026-74345,
CVE-2026-74350, CVE-2026-74376, CVE-2026-74384, CVE-2026-74394,
CVE-2026-74398, CVE-2026-74401, CVE-2026-74405, CVE-2026-74406,
CVE-2026-74407, CVE-2026-74408, CVE-2026-74410, CVE-2026-74411,
CVE-2026-74417, CVE-2026-74427, CVE-2026-74436, CVE-2026-74439,
CVE-2026-74440, CVE-2026-74473, CVE-2026-74474, CVE-2026-74475,
CVE-2026-74476, CVE-2026-74478, CVE-2026-74480, CVE-2026-74493,
CVE-2026-74495, CVE-2026-74521, CVE-2026-74538, CVE-2026-74541,
CVE-2026-74556, CVE-2026-74569)
8 hours 11 minutes ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
8 hours 13 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033,
CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048,
CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064,
CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085,
CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089,
CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098,
CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108,
CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114,
CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121,
CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128,
CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136,
CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147,
CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163,
CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170,
CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178,
CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183,
CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217,
CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221,
CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)
8 hours 15 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055,
CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096,
CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103,
CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126,
CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134,
CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138,
CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180,
CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64518)
8 hours 16 minutes ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- User-space API (UAPI);
- Kernel build system;
- ARM32 architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Compute Acceleration Framework;
- Intel NPU Driver;
- ACPI drivers;
- Android drivers;
- Drivers core;
- Compressed RAM block device driver;
- Bluetooth drivers;
- Character device driver;
- Hardware random number generator core;
- CPU frequency scaling framework;
- Hardware crypto device drivers;
- Buffer Sharing and Synchronization framework;
- Intel Stratix 10 firmware drivers;
- FPGA Framework;
- GPIO subsystem;
- GPU drivers;
- HID subsystem;
- CoreSight HW tracing drivers;
- I2C subsystem;
- IIO subsystem;
- IIO ADC drivers;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Mouse) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- Multiple devices driver;
- Media drivers;
- Multifunction device drivers;
- Fastrpc Driver;
- MMC subsystem;
- Ethernet bonding driver;
- Network drivers;
- Mellanox network drivers;
- MediaTek network drivers;
- NTB driver;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- System reset/shutdown drivers;
- Power sequencing drivers;
- PTP clock framework;
- Voltage and Current Regulator drivers;
- RPMSG subsystem;
- SLIMbus drivers;
- SPI subsystem;
- Media staging drivers;
- Realtek RTL8723BS SDIO drivers;
- VME bus staging drivers;
- Trusted Execution Environment drivers;
- Thunderbolt and USB4 drivers;
- TTY drivers;
- Cadence USB3 driver;
- ULPI bus;
- DesignWare USB3 driver;
- Faraday FOTG210 USB2 dual-role controller driver;
- USB Gadget drivers;
- USB Host Controller drivers;
- USB ChaosKey driver;
- Siemens ID Mouse USB driver;
- IOWarrior USB driver;
- LD Didactic USB driver;
- LEGO USB Tower driver;
- Intel USBIO USB I/O expander driver;
- USS720 USB parallel port adapter driver;
- MediaTek USB3 DRD driver;
- USB Serial drivers;
- USB Type-C Port Controller Manager driver;
- USB Type-C Connector System Software Interface driver;
- USB over IP driver;
- VFIO drivers;
- Framebuffer layer;
- Virtio drivers;
- BTRFS file system;
- EROFS file system;
- exFAT file system;
- F2FS file system;
- File systems infrastructure;
- FUSE (File system in Userspace);
- GFS2 file system;
- HFS file system;
- HFS+ file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- NILFS2 file system;
- NTFS3 file system;
- OCFS2 file system;
- Proc file system;
- SMB network file system;
- UDF file system;
- XFS file system;
- Key management;
- BPF subsystem;
- Memory management;
- Software nodes and device properties;
- Glob pattern matching library;
- Memory Management;
- KVM subsystem;
- Mellanox drivers;
- Restartable sequences system call mechanism;
- Socket messages infrastructure;
- Network traffic control;
- Bluetooth subsystem;
- Netfilter;
- Networking core;
- Network sockets;
- TCP network protocol;
- io_uring subsystem;
- IPC subsystem;
- Audit subsystem;
- Perf events;
- Kernel fork() syscall;
- Locking primitives;
- Kernel module support;
- Scheduler infrastructure;
- Signal handling mechanism;
- Timer subsystem;
- Tracing infrastructure;
- Debug objects infrastructure;
- 6LoWPAN network protocol;
- IEEE 802 network protocols;
- 9P file system network protocol;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Devlink API;
- HSR network protocol;
- IEEE802154.4 network protocol;
- IPv4 networking;
- IPv6 networking;
- XFRM subsystem;
- L2TP protocol;
- MAC80211 subsystem;
- IEEE 802.15.4 subsystem;
- Multipath TCP;
- NetLabel subsystem;
- Open vSwitch;
- Phonet protocol;
- Qualcomm IPC Router (QRTR);
- RDS protocol;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- eXpress Data Path;
- AppArmor security module;
- Linux Security Modules (LSM) Framework;
- Apple Onboard Audio ALSA driver;
- ALSA framework;
- FireWire sound drivers;
- HD-audio driver;
- Gravis UltraSound ALSA driver;
- C-Media CMI8x38 ALSA driver;
- ESS Solo-1 ALSA driver;
- ICE1712/ICE1724 (Envy24) ALSA driver;
- Yamaha YMFPCI ALSA driver;
- Wolfson Microelectronics audio codecs;
- SoundWire (SDCA) ASoC drivers;
- USB sound devices;
- Virtio sound driver;
(CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52917,
CVE-2026-52929, CVE-2026-52930, CVE-2026-52935, CVE-2026-52938,
CVE-2026-52939, CVE-2026-52940, CVE-2026-52942, CVE-2026-52947,
CVE-2026-52948, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134,
CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138,
CVE-2026-53139, CVE-2026-53140, CVE-2026-53141, CVE-2026-53142,
CVE-2026-53143, CVE-2026-53144, CVE-2026-53145, CVE-2026-53146,
CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150,
CVE-2026-53152, CVE-2026-53153, CVE-2026-53154, CVE-2026-53155,
CVE-2026-53156, CVE-2026-53157, CVE-2026-53158, CVE-2026-53159,
CVE-2026-53160, CVE-2026-53161, CVE-2026-53162, CVE-2026-53163,
CVE-2026-53164, CVE-2026-53165, CVE-2026-53167, CVE-2026-53168,
CVE-2026-53169, CVE-2026-53170, CVE-2026-53171, CVE-2026-53172,
CVE-2026-53173, CVE-2026-53177, CVE-2026-53178, CVE-2026-53179,
CVE-2026-53180, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183,
CVE-2026-53184, CVE-2026-53185, CVE-2026-53187, CVE-2026-53188,
CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53192,
CVE-2026-53193, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196,
CVE-2026-53197, CVE-2026-53198, CVE-2026-53199, CVE-2026-53200,
CVE-2026-53201, CVE-2026-53202, CVE-2026-53203, CVE-2026-53204,
CVE-2026-53205, CVE-2026-53206, CVE-2026-53207, CVE-2026-53208,
CVE-2026-53209, CVE-2026-53210, CVE-2026-53211, CVE-2026-53213,
CVE-2026-53214, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219,
CVE-2026-53220, CVE-2026-53222, CVE-2026-53223, CVE-2026-53226,
CVE-2026-53227, CVE-2026-53229, CVE-2026-53230, CVE-2026-53231,
CVE-2026-53232, CVE-2026-53233, CVE-2026-53234, CVE-2026-53235,
CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239,
CVE-2026-53240, CVE-2026-53241, CVE-2026-53242, CVE-2026-53243,
CVE-2026-53244, CVE-2026-53245, CVE-2026-53248, CVE-2026-53249,
CVE-2026-53250, CVE-2026-53251, CVE-2026-53252, CVE-2026-53253,
CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53257,
CVE-2026-53258, CVE-2026-53259, CVE-2026-53261, CVE-2026-53262,
CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266,
CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270,
CVE-2026-53271, CVE-2026-53272, CVE-2026-53273, CVE-2026-53274,
CVE-2026-53275, CVE-2026-53276, CVE-2026-53325, CVE-2026-53326,
CVE-2026-53327, CVE-2026-53328, CVE-2026-53329, CVE-2026-53330,
CVE-2026-53331, CVE-2026-53332, CVE-2026-53333, CVE-2026-53334,
CVE-2026-53335, CVE-2026-53336, CVE-2026-53337, CVE-2026-53338,
CVE-2026-53339, CVE-2026-53340, CVE-2026-53341, CVE-2026-53342,
CVE-2026-53343, CVE-2026-53344, CVE-2026-53345, CVE-2026-53346,
CVE-2026-53347, CVE-2026-53348, CVE-2026-53349, CVE-2026-53350,
CVE-2026-53351, CVE-2026-53352, CVE-2026-53353, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53356, CVE-2026-53361, CVE-2026-53362,
CVE-2026-53363, CVE-2026-53366, CVE-2026-53381, CVE-2026-53382,
CVE-2026-53383, CVE-2026-53384, CVE-2026-53385, CVE-2026-53386,
CVE-2026-53387, CVE-2026-53388, CVE-2026-53389, CVE-2026-53390,
CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394,
CVE-2026-53395, CVE-2026-53396, CVE-2026-53397, CVE-2026-53398,
CVE-2026-53399, CVE-2026-53400, CVE-2026-53401, CVE-2026-53402,
CVE-2026-53403, CVE-2026-63794, CVE-2026-63795, CVE-2026-63796,
CVE-2026-63797, CVE-2026-63798, CVE-2026-63799, CVE-2026-63800,
CVE-2026-63801, CVE-2026-63802, CVE-2026-63803, CVE-2026-63804,
CVE-2026-63805, CVE-2026-63806, CVE-2026-63807, CVE-2026-63808,
CVE-2026-63809, CVE-2026-63810, CVE-2026-63811, CVE-2026-63812,
CVE-2026-63813, CVE-2026-63814, CVE-2026-63815, CVE-2026-63816,
CVE-2026-63817, CVE-2026-63818, CVE-2026-63819, CVE-2026-63820,
CVE-2026-63821, CVE-2026-63822, CVE-2026-63823, CVE-2026-63824,
CVE-2026-63825, CVE-2026-63826, CVE-2026-63827, CVE-2026-63828,
CVE-2026-63829, CVE-2026-63830, CVE-2026-63831, CVE-2026-63832,
CVE-2026-63833, CVE-2026-63834, CVE-2026-63835, CVE-2026-63836,
CVE-2026-63867, CVE-2026-63868, CVE-2026-63869, CVE-2026-63870,
CVE-2026-63871, CVE-2026-63873, CVE-2026-63874, CVE-2026-64187,
CVE-2026-64188, CVE-2026-64189, CVE-2026-64191, CVE-2026-64192,
CVE-2026-64205, CVE-2026-64206, CVE-2026-64207, CVE-2026-64244,
CVE-2026-64245, CVE-2026-64246, CVE-2026-64247, CVE-2026-64249,
CVE-2026-64251, CVE-2026-64253, CVE-2026-64254, CVE-2026-64255,
CVE-2026-64256, CVE-2026-64258, CVE-2026-64259, CVE-2026-64260,
CVE-2026-64261, CVE-2026-64262, CVE-2026-64263, CVE-2026-64264,
CVE-2026-64265, CVE-2026-64266, CVE-2026-64267, CVE-2026-64268,
CVE-2026-64269, CVE-2026-64270, CVE-2026-64271, CVE-2026-64272,
CVE-2026-64273, CVE-2026-64274, CVE-2026-64275, CVE-2026-64276,
CVE-2026-64277, CVE-2026-64278, CVE-2026-64279, CVE-2026-64280,
CVE-2026-64282, CVE-2026-64283, CVE-2026-64284, CVE-2026-64285,
CVE-2026-64286, CVE-2026-64287, CVE-2026-64288, CVE-2026-64289,
CVE-2026-64290, CVE-2026-64291, CVE-2026-64292, CVE-2026-64293,
CVE-2026-64294, CVE-2026-64295, CVE-2026-64296, CVE-2026-64297,
CVE-2026-64298, CVE-2026-64299, CVE-2026-64300, CVE-2026-64301,
CVE-2026-64302, CVE-2026-64303, CVE-2026-64304, CVE-2026-64305,
CVE-2026-64306, CVE-2026-64307, CVE-2026-64308, CVE-2026-64309,
CVE-2026-64310, CVE-2026-64312, CVE-2026-64313, CVE-2026-64314,
CVE-2026-64315, CVE-2026-64316, CVE-2026-64317, CVE-2026-64318,
CVE-2026-64319, CVE-2026-64320, CVE-2026-64321, CVE-2026-64322,
CVE-2026-64323, CVE-2026-64324, CVE-2026-64325, CVE-2026-64326,
CVE-2026-64327, CVE-2026-64328, CVE-2026-64329, CVE-2026-64330,
CVE-2026-64331, CVE-2026-64332, CVE-2026-64333, CVE-2026-64334,
CVE-2026-64335, CVE-2026-64336, CVE-2026-64337, CVE-2026-64338,
CVE-2026-64339, CVE-2026-64340, CVE-2026-64341, CVE-2026-64342,
CVE-2026-64343, CVE-2026-64344, CVE-2026-64345, CVE-2026-64346,
CVE-2026-64347, CVE-2026-64348, CVE-2026-64350, CVE-2026-64351,
CVE-2026-64352, CVE-2026-64353, CVE-2026-64354, CVE-2026-64355,
CVE-2026-64356, CVE-2026-64357, CVE-2026-64358, CVE-2026-64359,
CVE-2026-64360, CVE-2026-64361, CVE-2026-64362, CVE-2026-64363,
CVE-2026-64364, CVE-2026-64365, CVE-2026-64366, CVE-2026-64367,
CVE-2026-64368, CVE-2026-64369, CVE-2026-64370, CVE-2026-64371,
CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375,
CVE-2026-64376, CVE-2026-64377, CVE-2026-64378, CVE-2026-64379,
CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383,
CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387,
CVE-2026-64388, CVE-2026-64389, CVE-2026-64390, CVE-2026-64391,
CVE-2026-64392, CVE-2026-64393, CVE-2026-64394, CVE-2026-64395,
CVE-2026-64396, CVE-2026-64397, CVE-2026-64398, CVE-2026-64399,
CVE-2026-64400, CVE-2026-64401, CVE-2026-64402, CVE-2026-64403,
CVE-2026-64404, CVE-2026-64405, CVE-2026-64406, CVE-2026-64407,
CVE-2026-64408, CVE-2026-64409, CVE-2026-64410, CVE-2026-64411,
CVE-2026-64412, CVE-2026-64413, CVE-2026-64414, CVE-2026-64415,
CVE-2026-64416, CVE-2026-64417, CVE-2026-64418, CVE-2026-64419,
CVE-2026-64420, CVE-2026-64421, CVE-2026-64422, CVE-2026-64423,
CVE-2026-64424, CVE-2026-64425, CVE-2026-64426, CVE-2026-64428,
CVE-2026-64429, CVE-2026-64430, CVE-2026-64432, CVE-2026-64433,
CVE-2026-64434, CVE-2026-64435, CVE-2026-64436, CVE-2026-64438,
CVE-2026-64439, CVE-2026-64440, CVE-2026-64441, CVE-2026-64442,
CVE-2026-64443, CVE-2026-64444, CVE-2026-64445, CVE-2026-64446,
CVE-2026-64447, CVE-2026-64448, CVE-2026-64449, CVE-2026-64450,
CVE-2026-64451, CVE-2026-64452, CVE-2026-64453, CVE-2026-64454,
CVE-2026-64455, CVE-2026-64456, CVE-2026-64457, CVE-2026-64458,
CVE-2026-64459, CVE-2026-64460, CVE-2026-64461, CVE-2026-64462,
CVE-2026-64463, CVE-2026-64464, CVE-2026-64465, CVE-2026-64466,
CVE-2026-64467, CVE-2026-64468, CVE-2026-64469, CVE-2026-64470,
CVE-2026-64471, CVE-2026-64472, CVE-2026-64473, CVE-2026-64474,
CVE-2026-64475, CVE-2026-64476, CVE-2026-64477, CVE-2026-64478,
CVE-2026-64479, CVE-2026-64480, CVE-2026-64481, CVE-2026-64482,
CVE-2026-64483, CVE-2026-64484, CVE-2026-64485, CVE-2026-64486,
CVE-2026-64487, CVE-2026-64488, CVE-2026-64489, CVE-2026-64490,
CVE-2026-64491, CVE-2026-64492, CVE-2026-64493, CVE-2026-64494,
CVE-2026-64495, CVE-2026-64496, CVE-2026-64497, CVE-2026-64499,
CVE-2026-64500, CVE-2026-64501, CVE-2026-64502, CVE-2026-64503,
CVE-2026-64504, CVE-2026-64505, CVE-2026-64507, CVE-2026-64508,
CVE-2026-64509, CVE-2026-64510, CVE-2026-64511, CVE-2026-64512,
CVE-2026-64513, CVE-2026-64514, CVE-2026-64529, CVE-2026-64536,
CVE-2026-64556, CVE-2026-64588, CVE-2026-64589, CVE-2026-64590,
CVE-2026-64591, CVE-2026-64592, CVE-2026-64593, CVE-2026-64594,
CVE-2026-64596, CVE-2026-64597, CVE-2026-64598, CVE-2026-64599,
CVE-2026-64600, CVE-2026-64601, CVE-2026-64602, CVE-2026-64603,
CVE-2026-64604, CVE-2026-68084, CVE-2026-68085, CVE-2026-68087,
CVE-2026-68088, CVE-2026-68089, CVE-2026-68090, CVE-2026-68091,
CVE-2026-68092, CVE-2026-68459, CVE-2026-68460, CVE-2026-68461,
CVE-2026-74584, CVE-2026-80591)
8 hours 20 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- NVIDIA Tegra memory controller driver;
- File systems infrastructure;
- Network file system (NFS) server daemon;
- OCFS2 file system;
- B.A.T.M.A.N. meshing protocol;
- Netfilter;
- SCTP protocol;
(CVE-2022-50401, CVE-2026-43071, CVE-2026-52914, CVE-2026-53002,
CVE-2026-53043, CVE-2026-53045, CVE-2026-53224, CVE-2026-53309)
8 hours 21 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- NVME drivers;
- File systems infrastructure;
- Ext4 file system;
- OCFS2 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53043, CVE-2026-53045, CVE-2026-53088,
CVE-2026-53176, CVE-2026-53212, CVE-2026-53224, CVE-2026-53225,
CVE-2026-53228, CVE-2026-53246, CVE-2026-53309, CVE-2026-53359)
8 hours 23 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- OCFS2 file system;
- SCTP protocol;
(CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-53246,
CVE-2026-53309)
18 hours 40 minutes ago
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for
CVE-2026-87766 introduced a regression in symlink resolution, preventing
certain Flatpak applications from launching. This update reverts that fix
until a complete fix is available.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Bubblewrap incorrectly handled certain temporary
directories. A local attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-12439)
It was discovered that Bubblewrap incorrectly handled certain symlinks
during sandbox setup. A local attacker could possibly use this issue to
create files outside of the sandbox. (CVE-2026-87766)
1 day ago
It was discovered that libsoup incorrectly handled certain URLs when
using an HTTP proxy. A remote attacker could possibly use this issue to
inject arbitrary HTTP headers. (CVE-2026-1467)
It was discovered that libsoup did not remove proxy authentication
credentials when following HTTP redirects. A remote attacker could
possibly use this issue to obtain sensitive information.
(CVE-2026-1539)
Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP
requests. A remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2026-1801)
1 day 1 hour ago
It was discovered that Bubblewrap incorrectly handled certain temporary
directories. A local attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-12439)
It was discovered that Bubblewrap incorrectly handled certain symlinks
during sandbox setup. A local attacker could possibly use this issue to
create files outside of the sandbox. (CVE-2026-87766)
1 day 5 hours ago
It was discovered that GStreamer Good Plugins did not limit the size of
reassembly buffers when processing fragmented RTP packets. A remote
attacker could possibly use this issue to cause GStreamer Good Plugins to
use excessive resources, leading to a denial of service.
1 day 5 hours ago
It was discovered that GNU Bison incorrectly handled grammar-defined
configuration variables when generating HTML reports. An attacker could
possibly use this issue to execute arbitrary code.
1 day 20 hours ago
It was discovered that python-cryptography incorrectly accepted objects
with immutable buffers when performing certain cipher operations. This
would result in corrupted output, contrary to expectations. This issue only
affected Ubuntu 18.04 LTS. (CVE-2023-23931)
It was discovered that python-cryptography reported the outcome of
decrypting PKCS#7 enveloped data in distinguishable ways, and with
observable timing differences. A remote attacker could possibly use this
issue to recover the key used to encrypt the message contents, and obtain
sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-69247)
Jack Lloyd discovered that python-cryptography incorrectly handled wildcard
DNS names when enforcing the name constraints of a certificate authority. A
remote attacker could possibly use this issue to have an invalid
certificate chain accepted, and use names outside of the permitted ones.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)
Samuel Judson discovered that python-cryptography incorrectly handled
certificate chains that contained duplicate certificates. A remote attacker
could possibly use this issue to cause python-cryptography to use excessive
resources, leading to a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-69249)
2 days ago
It was discovered that SQLite was vulnerable to a buffer overflow in
the sqlar extension. If a user were tricked into opening a specially
crafted SQLar archive, an attacker could cause a denial of service.
2 days ago
Ali Firas discovered that libheif incorrectly handled certain images. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-62291)
Dmitrijs Trizna discovered that libheif incorrectly handled certain image
sequences. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-62377)
2 days 2 hours ago
USN-8736-1 fixed vulnerabilities in Perl. This update provides the
corresponding fix for Perl on Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that Perl incorrectly handled certain large inputs during
regular expression matching. An attacker could possibly use this issue to
trigger out-of-bounds heap reads or writes, resulting in a denial of
service or arbitrary code execution. (CVE-2026-15534)
It was discovered that Perl incorrectly handled certain regular expression
containing alternative matching branches. An attacker could possibly use
this issue to cause incorrect regular expression matches, resulting in
security restrictions being bypassed. (CVE-2026-19487)
2 days 5 hours ago
It was discovered that GNU Guix incorrectly made build outputs accessible
to local users before their file metadata was finalized. A local attacker
could possibly use this issue to gain elevated privileges.
2 days 7 hours ago
It was discovered that AOM incorrectly handled the first-pass statistics
buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use
this issue to cause a heap buffer overflow, leading to a denial of service
or possibly execute arbitrary code. (CVE-2026-56208)
It was discovered that AOM incorrectly validated spatial and temporal
layer IDs in the SVC (Scalable Video Coding) encoder controls. An attacker
could possibly use this issue to write to an arbitrary memory address, read
out-of-bounds heap memory, or execute arbitrary code. (CVE-2026-56209,
CVE-2026-56210, CVE-2026-56211)
Checked
9 minutes 7 seconds ago