3 hours 13 minutes ago
Maher Azzouzi discovered that LXC did not correctly handle logging
certain failure messages. An attacker could possibly use this issue
to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2022-47952)
Sam Sanoop discovered that LXC did not correctly handle certain forms
of user authorization. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-39402)
7 hours 2 minutes ago
It was discovered that Requests did not correctly handle generating
random temporary file paths. An attacker could possibly use this issue
to execute arbitrary code.
2 days 21 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055,
CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096,
CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103,
CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126,
CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134,
CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138,
CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180,
CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64518)
2 days 21 hours ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
2 days 21 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
2 days 21 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
3 days ago
It was discovered that libpcap did not properly validate BPF instructions
in some situation. An attacker could possibly use this issue to perform out
of bound memory operations.
3 days 1 hour ago
It was discovered that PyJWT incorrectly handled certain URIs when using
PyJWKClient. A remote attacker could possibly use this issue to perform
server-side request forgery (SSRF) or expose sensitive local files.
This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu
26.04 LTS. (CVE-2026-48522)
It was discovered that PyJWT incorrectly verified cryptographic signatures
when decoding tokens with PyJWK keys. A remote attacker could possibly
use this issue to bypass signature verification and forge valid JSON Web
Tokens. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-48523)
It was discovered that PyJWT incorrectly handled unknown key identifiers
in PyJWKClient. A remote attacker could possibly use this issue to cause
PyJWT to make excessive network requests, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-48524)
It was discovered that PyJWT incorrectly handled payload decoding during
detached JWS token verification. A remote attacker could possibly use
this issue to cause PyJWT to consume excessive resources, resulting in
a denial of service. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 26.04 LTS. (CVE-2026-48525)
It was discovered that PyJWT incorrectly validated JSON Web Keys when
decoding tokens with both HMAC and asymmetric algorithms enabled. A remote
attacker could possibly use this issue to forge valid tokens, resulting
in an authentication bypass. (CVE-2026-48526)
3 days 6 hours ago
It was discovered that Libwebsockets incorrectly handled certain SSH
protocol messages in its SSH protocol handler. A remote attacker could
possibly use this issue to cause Libwebsockets to consume excessive
resources, resulting in a denial of service. (CVE-2026-10650)
It was discovered that Libwebsockets incorrectly handled certain malformed
CBOR data. A remote attacker could possibly use this issue to cause
Libwebsockets to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04
LTS. (CVE-2026-78161)
3 days 12 hours ago
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)
Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)
Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
possibly use this issue to cause curl to crash, resulting in a denial of
service, or execute arbitrary code. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-80229)
Stanislav Fort discovered that curl did not properly enforce public key
pinning when certificate verification was disabled in certain
circumstances. A remote attacker could possibly use this issue to bypass
pinning checks and cause curl to accept connections that should have been
rejected. (CVE-2026-80230)
Stanislav Fort discovered that curl incorrectly handled the Secure
attribute of cookies in certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-80255)
Stanislav Fort discovered that curl did not properly enforce Public
Suffix List boundaries when handling cookies in certain circumstances. A
remote attacker could possibly use this issue to cause cookies to be sent
to unrelated domains, resulting in sensitive information being exposed.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-82209)
Ady Elouej discovered that curl did not clear proxy authentication state
between requests when reusing a handle with environment-variable proxy
configuration. A remote attacker could possibly use this issue to obtain
sensitive credentials. This issue was previously fixed in USN-8487-1, but
that fix was incomplete for Ubuntu 16.04 LTS. (CVE-2026-8927)
3 days 13 hours ago
It was discovered that OpenStack Swift incorrectly handled truncated
aws-chunked PUT request bodies in its s3api middleware. An authenticated
attacker could possibly use this issue to cause OpenStack Swift to use
excessive resources, leading to a denial of service.
3 days 17 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
3 days 17 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
3 days 17 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- B.A.T.M.A.N. meshing protocol;
- HSR network protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
3 days 18 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- S390 architecture;
- x86 architecture;
- DRBD Distributed Replicated Block Device drivers;
- InfiniBand drivers;
- IOMMU subsystem;
- Multiple devices driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- NVME drivers;
- TCM subsystem;
- Virtio Host (VHOST) subsystem;
- Xen hypervisor drivers;
- AFS file system;
- File systems infrastructure;
- Network file systems library;
- Network file system (NFS) client;
- NTFS3 file system;
- OCFS2 file system;
- OrangeFS file system;
- SMB network file system;
- IPv4 networking;
- Sun RPC protocol;
- IPv6 networking;
- IP tunnels definitions;
- Netfilter;
- TCP network protocol;
- Locking primitives;
- 9P file system network protocol;
- B.A.T.M.A.N. meshing protocol;
- Networking core;
- IFE protocol;
- RxRPC session sockets;
- Network traffic control;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
- XFRM subsystem;
(CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541,
CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476,
CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033,
CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065,
CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085,
CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137,
CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194,
CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222,
CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249,
CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279,
CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296,
CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319,
CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329,
CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355,
CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398,
CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422,
CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451,
CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473,
CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494,
CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255,
CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287,
CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361,
CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398,
CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428,
CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439,
CVE-2026-80665)
3 days 18 hours ago
It was discovered that libass incorrectly handled parsing operations for
specific nested character strings. An attacker could use this issue to
cause libass to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-24994)
It was discovered that libass incorrectly handled certain outline
processing operations. An attacker could use this issue to cause libass
to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-26682)
It was discovered that libass incorrectly handled certain ASS subtitle
files when measuring wrapped lines. An attacker could use this issue to
cause libass to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 26.04 LTS. (CVE-2026-61627)
It was discovered that libass incorrectly handled certain Matroska
subtitle chunks with negative ReadOrder values. An attacker could use
this issue to cause libass to crash, resulting in a denial of service,
or possibly execute arbitrary code. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-61626)
3 days 20 hours ago
It was discovered that Expat did not correctly handle certain integer
arithmetic. An attacker could possibly use this issue to cause a denial of
service.
(CVE-2026-56406, CVE-2026-56407, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411)
It was discovered that Expat did not correctly track handler call depth. An
attacker could possibly use this issue to cause Expat to crash or execute
arbitrary code. (CVE-2026-56131)
It was discovered that Expat did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause Expat to
crash or execute arbitrary code. (CVE-2026-56132)
It was discovered that Expat did not correctly handle certain Unicode
characters. An attacker could possibly use this issue to cause Expat to use
excessive resources, leading to a denial of service. (CVE-2026-72522)
It was discovered that Expat did not correctly process certain XML
attributes. A remote attacker could possibly use this issue to cause Expat
to use excessive resources, leading to a denial of service.
(CVE-2026-66046)
It was discovered that Expat did not correctly handle certain external
entities. An attacker could possibly use this issue to cause Expat to crash
or execute arbitrary code. (CVE-2026-76641)
It was discovered that Expat did not correctly track handler call depth
with custom encodings. An attacker could possibly use this issue to cause
Expat to crash or execute arbitrary code. (CVE-2026-76957)
3 days 20 hours ago
It was discovered that Octavia did not properly validate TLS cipher
string fields in the Amphora provider driver. An authenticated
attacker who owns a TLS-enabled load balancer could possibly use
this issue to inject arbitrary HAProxy configuration directives.
(CVE-2026-94572)
It was discovered that Octavia did not properly validate L7 policy
redirect URL fields in the Amphora provider driver. An authenticated
attacker who owns a load balancer could possibly use this issue to
inject arbitrary HAProxy configuration directives. (CVE-2026-94571)
It was discovered that Octavia incorrectly handled quality of service
policy authorization. An authenticated attacker could possibly use
this issue to prevent deletion of another project's QoS policy.
(CVE-2026-74248)
3 days 21 hours ago
It was discovered that GDAL incorrectly handled certain netCDF files. An
attacker could possibly use this issue to execute arbitrary code. This issue
only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-49014)
It was discovered that GDAL incorrectly handled certain HDF-EOS files. An
attacker could possibly use this issue to cause a crash or execute arbitrary
code. (CVE-2026-8086, CVE-2026-8087, CVE-2026-8212, CVE-2026-8213)
It was discovered that GDAL incorrectly handled certain HDF-EOS file
metadata. An attacker could possibly use this issue to cause GDAL to crash,
resulting in a denial of service. (CVE-2026-8084, CVE-2026-8088)
4 days 7 hours ago
It was discovered that urllib3 did not correctly strip sensitive HTTP
headers during cross-origin redirects. An attacker could possibly use this
issue to leak sensitive information.
Checked
2 minutes 20 seconds ago