Ubuntu Security Advisories

USN-8782-1: Rclone vulnerability

6 hours 23 minutes ago
It was discovered that Rclone incorrectly handled unauthenticated requests to the remote control API. An attacker could possibly use this issue to execute arbitrary commands as the user invoking rclone. (CVE-2026-49980)

USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities

8 hours 10 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - User-Mode Linux (UML); - x86 architecture; - Cryptographic API; - Intel NPU Driver; - Compute Acceleration Framework; - ACPI drivers; - Drivers core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Ublk userspace block driver; - Compressed RAM block device driver; - Bluetooth drivers; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - FPGA Framework; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - I3C subsystem; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - IOMMU subsystem; - Multiple devices driver; - Media drivers; - Fastrpc Driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - MediaTek network drivers; - NVME drivers; - Operating Performance Points (OPP) driver; - PCI subsystem; - PTP clock framework; - RPMSG subsystem; - SCSI subsystem; - SoundWire subsystem; - SPI subsystem; - Greybus lights staging drivers; - Media staging drivers; - NVIDIA Tegra embedded controller (NVEC) staging driver; - Realtek RTL8723BS SDIO drivers; - TCM subsystem; - Trusted Execution Environment drivers; - Thunderbolt and USB4 drivers; - TTY drivers; - USB Gadget drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - vDPA drivers; - VFIO drivers; - Virtio Host (VHOST) subsystem; - Virtio drivers; - Xen hypervisor drivers; - 9P distributed file system; - AFS file system; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - exFAT file system; - F2FS file system; - GFS2 file system; - HFS file system; - HFS+ file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - OCFS2 file system; - OrangeFS file system; - SMB network file system; - BPF subsystem; - File system encryption (fscrypt); - Software nodes and device properties; - IPv4 networking; - KVM subsystem; - Mellanox drivers; - Memory management; - Networking core; - Netfilter; - Socket messages infrastructure; - MediaTek SoC drivers; - Sun RPC protocol; - Network traffic control; - IPv6 networking; - Amateur Radio drivers; - Bluetooth subsystem; - IP tunnels definitions; - KCM (Kernel Connection Multiplexor) sockets driver; - MultiProtocol Label Switching driver; - TCP network protocol; - XFRM subsystem; - Tracing infrastructure; - io_uring subsystem; - Control group (cgroup); - Perf events; - IRQ subsystem; - Locking primitives; - KProbes tracing; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - CAN network layer; - Ceph Core library; - Handshake API; - HSR network protocol; - IFE protocol; - L2TP protocol; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NFC subsystem; - Open vSwitch; - Phonet protocol; - RDS protocol; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - X.25 network layer; - eXpress Data Path; - Rust bindings mechanism; - AppArmor security module; - Key management; - Linux Security Modules (LSM) Framework; - SELinux security module; - ALSA framework; - AudioScience HPI driver; - Intel ASoC drivers; - USB sound devices; (CVE-2024-14040, CVE-2024-35948, CVE-2024-41008, CVE-2024-43872, CVE-2024-44932, CVE-2024-44964, CVE-2024-49932, CVE-2024-49940, CVE-2024-50106, CVE-2024-50217, CVE-2024-52560, CVE-2024-53098, CVE-2024-56552, CVE-2024-56591, CVE-2024-57857, CVE-2024-58089, CVE-2024-58094, CVE-2024-58098, CVE-2024-58100, CVE-2024-58241, CVE-2025-21687, CVE-2025-21693, CVE-2025-21984, CVE-2025-21985, CVE-2025-22104, CVE-2025-22108, CVE-2025-22109, CVE-2025-23132, CVE-2025-37776, CVE-2025-37876, CVE-2025-37906, CVE-2025-38064, CVE-2025-38069, CVE-2025-38187, CVE-2025-38204, CVE-2025-38206, CVE-2025-38242, CVE-2025-38498, CVE-2025-38563, CVE-2025-38565, CVE-2025-38636, CVE-2025-38717, CVE-2025-39677, CVE-2025-39789, CVE-2025-39859, CVE-2025-39862, CVE-2025-39896, CVE-2025-39933, CVE-2025-39958, CVE-2025-39990, CVE-2025-40025, CVE-2025-40040, CVE-2025-40054, CVE-2025-40064, CVE-2025-40074, CVE-2025-40075, CVE-2025-40139, CVE-2025-40158, CVE-2025-40168, CVE-2025-40170, CVE-2025-40203, CVE-2025-40274, CVE-2025-40344, CVE-2025-40354, CVE-2025-68174, CVE-2025-68304, CVE-2025-68360, CVE-2025-68745, CVE-2025-68822, CVE-2025-71073, CVE-2025-71074, CVE-2025-71202, CVE-2025-71289, CVE-2026-23208, CVE-2026-23239, CVE-2026-23240, CVE-2026-23327, CVE-2026-23393, CVE-2026-23469, CVE-2026-31420, CVE-2026-31479, CVE-2026-31486, CVE-2026-31493, CVE-2026-31560, CVE-2026-31568, CVE-2026-31630, CVE-2026-31663, CVE-2026-31771, CVE-2026-43009, CVE-2026-43029, CVE-2026-43042, CVE-2026-43048, CVE-2026-43101, CVE-2026-43116, CVE-2026-43126, CVE-2026-43172, CVE-2026-43213, CVE-2026-43263, CVE-2026-43303, CVE-2026-43352, CVE-2026-43353, CVE-2026-43464, CVE-2026-45850, CVE-2026-45894, CVE-2026-45932, CVE-2026-45944, CVE-2026-46054, CVE-2026-46130, CVE-2026-46158, CVE-2026-46170, CVE-2026-46175, CVE-2026-46181, CVE-2026-46203, CVE-2026-46275, CVE-2026-46315, CVE-2026-46320, CVE-2026-46324, CVE-2026-46330, CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52926, CVE-2026-52934, CVE-2026-52941, CVE-2026-52956, CVE-2026-52988, CVE-2026-52991, CVE-2026-53000, CVE-2026-53005, CVE-2026-53009, CVE-2026-53024, CVE-2026-53025, CVE-2026-53053, CVE-2026-53070, CVE-2026-53078, CVE-2026-53089, CVE-2026-53090, CVE-2026-53091, CVE-2026-53109, CVE-2026-53118, CVE-2026-53120, CVE-2026-53129, CVE-2026-53131, CVE-2026-53132, CVE-2026-53133, CVE-2026-53148, CVE-2026-53159, CVE-2026-53182, CVE-2026-53183, CVE-2026-53185, CVE-2026-53186, CVE-2026-53196, CVE-2026-53198, CVE-2026-53216, CVE-2026-53217, CVE-2026-53221, CVE-2026-53230, CVE-2026-53232, CVE-2026-53239, CVE-2026-53250, CVE-2026-53254, CVE-2026-53256, CVE-2026-53262, CVE-2026-53264, CVE-2026-53266, CVE-2026-53269, CVE-2026-53270, CVE-2026-53273, CVE-2026-53275, CVE-2026-53281, CVE-2026-53284, CVE-2026-53354, CVE-2026-53355, CVE-2026-53357, CVE-2026-53358, CVE-2026-53361, CVE-2026-53368, CVE-2026-53384, CVE-2026-53398, CVE-2026-53399, CVE-2026-63795, CVE-2026-63796, CVE-2026-63797, CVE-2026-63800, CVE-2026-63801, CVE-2026-63804, CVE-2026-63807, CVE-2026-63808, CVE-2026-63815, CVE-2026-63818, CVE-2026-63825, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63831, CVE-2026-63853, CVE-2026-63858, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63893, CVE-2026-63906, CVE-2026-63912, CVE-2026-63914, CVE-2026-63915, CVE-2026-63916, CVE-2026-63917, CVE-2026-63919, CVE-2026-63921, CVE-2026-63922, CVE-2026-63924, CVE-2026-63926, CVE-2026-63940, CVE-2026-63944, CVE-2026-63945, CVE-2026-63946, CVE-2026-63947, CVE-2026-63948, CVE-2026-63952, CVE-2026-63974, CVE-2026-63975, CVE-2026-63976, CVE-2026-63978, CVE-2026-63979, CVE-2026-63980, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007, CVE-2026-64010, CVE-2026-64011, CVE-2026-64015, CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64076, CVE-2026-64077, CVE-2026-64082, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64091, CVE-2026-64092, CVE-2026-64093, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098, CVE-2026-64099, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64112, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64117, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64160, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64191, CVE-2026-64206, CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231, CVE-2026-64237, CVE-2026-64247, CVE-2026-64249, CVE-2026-64268, CVE-2026-64269, CVE-2026-64280, CVE-2026-64303, CVE-2026-64313, CVE-2026-64315, CVE-2026-64319, CVE-2026-64320, CVE-2026-64355, CVE-2026-64361, CVE-2026-64364, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64390, CVE-2026-64391, CVE-2026-64392, CVE-2026-64393, CVE-2026-64394, CVE-2026-64396, CVE-2026-64397, CVE-2026-64399, CVE-2026-64400, CVE-2026-64408, CVE-2026-64438, CVE-2026-64441, CVE-2026-64445, CVE-2026-64450, CVE-2026-64475, CVE-2026-64510, CVE-2026-64518, CVE-2026-64523, CVE-2026-64529, CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541, CVE-2026-64548, CVE-2026-64551, CVE-2026-64552, CVE-2026-64554, CVE-2026-64555, CVE-2026-64557, CVE-2026-64561, CVE-2026-64562, CVE-2026-64564, CVE-2026-64586, CVE-2026-64597, CVE-2026-64598, CVE-2026-68082, CVE-2026-68083, CVE-2026-68117, CVE-2026-68123, CVE-2026-68124, CVE-2026-68127, CVE-2026-68136, CVE-2026-68137, CVE-2026-68138, CVE-2026-68144, CVE-2026-68147, CVE-2026-68152, CVE-2026-68154, CVE-2026-68156, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160, CVE-2026-68161, CVE-2026-68162, CVE-2026-68198, CVE-2026-68206, CVE-2026-68209, CVE-2026-68210, CVE-2026-68213, CVE-2026-68228, CVE-2026-68229, CVE-2026-68300, CVE-2026-68302, CVE-2026-68343, CVE-2026-68381, CVE-2026-68388, CVE-2026-68426, CVE-2026-68431, CVE-2026-68457, CVE-2026-68461, CVE-2026-68470, CVE-2026-68476, CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033, CVE-2026-72041, CVE-2026-72065, CVE-2026-72069, CVE-2026-72071, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085, CVE-2026-72098, CVE-2026-72111, CVE-2026-72124, CVE-2026-72125, CVE-2026-72126, CVE-2026-72129, CVE-2026-72130, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194, CVE-2026-72200, CVE-2026-72217, CVE-2026-72221, CVE-2026-72222, CVE-2026-72226, CVE-2026-72234, CVE-2026-72251, CVE-2026-72255, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296, CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329, CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72380, CVE-2026-72383, CVE-2026-72398, CVE-2026-72399, CVE-2026-72421, CVE-2026-72422, CVE-2026-72434, CVE-2026-72436, CVE-2026-72451, CVE-2026-72454, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473, CVE-2026-72487, CVE-2026-72488, CVE-2026-72489, CVE-2026-72491, CVE-2026-72494, CVE-2026-72495, CVE-2026-72496, CVE-2026-72499, CVE-2026-74255, CVE-2026-74264, CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74279, CVE-2026-74280, CVE-2026-74287, CVE-2026-74302, CVE-2026-74305, CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398, CVE-2026-74401, CVE-2026-74405, CVE-2026-74406, CVE-2026-74407, CVE-2026-74408, CVE-2026-74410, CVE-2026-74411, CVE-2026-74417, CVE-2026-74427, CVE-2026-74436, CVE-2026-74439, CVE-2026-74440, CVE-2026-74473, CVE-2026-74474, CVE-2026-74475, CVE-2026-74476, CVE-2026-74478, CVE-2026-74480, CVE-2026-74493, CVE-2026-74495, CVE-2026-74521, CVE-2026-74538, CVE-2026-74541, CVE-2026-74556, CVE-2026-74569)

USN-8761-2: Linux kernel (Azure FIPS) vulnerabilities

8 hours 13 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPU drivers; - Hardware monitoring drivers; - InfiniBand drivers; - Network drivers; - SCSI subsystem; - SPI subsystem; - Network file systems library; - NTFS3 file system; - SMB network file system; - File systems infrastructure; - Software nodes and device properties; - Bluetooth subsystem; - Netfilter; - Tracing infrastructure; - io_uring subsystem; - IRQ subsystem; - KProbes tracing; - Memory management; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - Phonet protocol; - SMC sockets; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - Key management; - Linux Security Modules (LSM) Framework; - ALSA framework; - AudioScience HPI driver; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)

USN-8729-2: Linux kernel (Raspberry Pi Real-time) vulnerabilities

8 hours 15 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPU drivers; - Hardware monitoring drivers; - InfiniBand drivers; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - SCSI subsystem; - SPI subsystem; - Network file systems library; - NTFS3 file system; - SMB network file system; - File systems infrastructure; - Software nodes and device properties; - Bluetooth subsystem; - Netfilter; - Tracing infrastructure; - io_uring subsystem; - IRQ subsystem; - KProbes tracing; - Memory management; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - Phonet protocol; - SMC sockets; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - Key management; - Linux Security Modules (LSM) Framework; - ALSA framework; - AudioScience HPI driver; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015, CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)

USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilities

8 hours 16 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Drivers core; - Compressed RAM block device driver; - Bluetooth drivers; - Character device driver; - Hardware random number generator core; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - Intel Stratix 10 firmware drivers; - FPGA Framework; - GPIO subsystem; - GPU drivers; - HID subsystem; - CoreSight HW tracing drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - Fastrpc Driver; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - MediaTek network drivers; - NTB driver; - NVME drivers; - NVMEM (Non Volatile Memory) drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - System reset/shutdown drivers; - Power sequencing drivers; - PTP clock framework; - Voltage and Current Regulator drivers; - RPMSG subsystem; - SLIMbus drivers; - SPI subsystem; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - VME bus staging drivers; - Trusted Execution Environment drivers; - Thunderbolt and USB4 drivers; - TTY drivers; - Cadence USB3 driver; - ULPI bus; - DesignWare USB3 driver; - Faraday FOTG210 USB2 dual-role controller driver; - USB Gadget drivers; - USB Host Controller drivers; - USB ChaosKey driver; - Siemens ID Mouse USB driver; - IOWarrior USB driver; - LD Didactic USB driver; - LEGO USB Tower driver; - Intel USBIO USB I/O expander driver; - USS720 USB parallel port adapter driver; - MediaTek USB3 DRD driver; - USB Serial drivers; - USB Type-C Port Controller Manager driver; - USB Type-C Connector System Software Interface driver; - USB over IP driver; - VFIO drivers; - Framebuffer layer; - Virtio drivers; - BTRFS file system; - EROFS file system; - exFAT file system; - F2FS file system; - File systems infrastructure; - FUSE (File system in Userspace); - GFS2 file system; - HFS file system; - HFS+ file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - OCFS2 file system; - Proc file system; - SMB network file system; - UDF file system; - XFS file system; - Key management; - BPF subsystem; - Memory management; - Software nodes and device properties; - Glob pattern matching library; - Memory Management; - KVM subsystem; - Mellanox drivers; - Restartable sequences system call mechanism; - Socket messages infrastructure; - Network traffic control; - Bluetooth subsystem; - Netfilter; - Networking core; - Network sockets; - TCP network protocol; - io_uring subsystem; - IPC subsystem; - Audit subsystem; - Perf events; - Kernel fork() syscall; - Locking primitives; - Kernel module support; - Scheduler infrastructure; - Signal handling mechanism; - Timer subsystem; - Tracing infrastructure; - Debug objects infrastructure; - 6LoWPAN network protocol; - IEEE 802 network protocols; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Devlink API; - HSR network protocol; - IEEE802154.4 network protocol; - IPv4 networking; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NetLabel subsystem; - Open vSwitch; - Phonet protocol; - Qualcomm IPC Router (QRTR); - RDS protocol; - SCTP protocol; - SMC sockets; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - eXpress Data Path; - AppArmor security module; - Linux Security Modules (LSM) Framework; - Apple Onboard Audio ALSA driver; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - Gravis UltraSound ALSA driver; - C-Media CMI8x38 ALSA driver; - ESS Solo-1 ALSA driver; - ICE1712/ICE1724 (Envy24) ALSA driver; - Yamaha YMFPCI ALSA driver; - Wolfson Microelectronics audio codecs; - SoundWire (SDCA) ASoC drivers; - USB sound devices; - Virtio sound driver; (CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52917, CVE-2026-52929, CVE-2026-52930, CVE-2026-52935, CVE-2026-52938, CVE-2026-52939, CVE-2026-52940, CVE-2026-52942, CVE-2026-52947, CVE-2026-52948, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134, CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138, CVE-2026-53139, CVE-2026-53140, CVE-2026-53141, CVE-2026-53142, CVE-2026-53143, CVE-2026-53144, CVE-2026-53145, CVE-2026-53146, CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53152, CVE-2026-53153, CVE-2026-53154, CVE-2026-53155, CVE-2026-53156, CVE-2026-53157, CVE-2026-53158, CVE-2026-53159, CVE-2026-53160, CVE-2026-53161, CVE-2026-53162, CVE-2026-53163, CVE-2026-53164, CVE-2026-53165, CVE-2026-53167, CVE-2026-53168, CVE-2026-53169, CVE-2026-53170, CVE-2026-53171, CVE-2026-53172, CVE-2026-53173, CVE-2026-53177, CVE-2026-53178, CVE-2026-53179, CVE-2026-53180, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183, CVE-2026-53184, CVE-2026-53185, CVE-2026-53187, CVE-2026-53188, CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53192, CVE-2026-53193, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53197, CVE-2026-53198, CVE-2026-53199, CVE-2026-53200, CVE-2026-53201, CVE-2026-53202, CVE-2026-53203, CVE-2026-53204, CVE-2026-53205, CVE-2026-53206, CVE-2026-53207, CVE-2026-53208, CVE-2026-53209, CVE-2026-53210, CVE-2026-53211, CVE-2026-53213, CVE-2026-53214, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53222, CVE-2026-53223, CVE-2026-53226, CVE-2026-53227, CVE-2026-53229, CVE-2026-53230, CVE-2026-53231, CVE-2026-53232, CVE-2026-53233, CVE-2026-53234, CVE-2026-53235, CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239, CVE-2026-53240, CVE-2026-53241, CVE-2026-53242, CVE-2026-53243, CVE-2026-53244, CVE-2026-53245, CVE-2026-53248, CVE-2026-53249, CVE-2026-53250, CVE-2026-53251, CVE-2026-53252, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53257, CVE-2026-53258, CVE-2026-53259, CVE-2026-53261, CVE-2026-53262, CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53271, CVE-2026-53272, CVE-2026-53273, CVE-2026-53274, CVE-2026-53275, CVE-2026-53276, CVE-2026-53325, CVE-2026-53326, CVE-2026-53327, CVE-2026-53328, CVE-2026-53329, CVE-2026-53330, CVE-2026-53331, CVE-2026-53332, CVE-2026-53333, CVE-2026-53334, CVE-2026-53335, CVE-2026-53336, CVE-2026-53337, CVE-2026-53338, CVE-2026-53339, CVE-2026-53340, CVE-2026-53341, CVE-2026-53342, CVE-2026-53343, CVE-2026-53344, CVE-2026-53345, CVE-2026-53346, CVE-2026-53347, CVE-2026-53348, CVE-2026-53349, CVE-2026-53350, CVE-2026-53351, CVE-2026-53352, CVE-2026-53353, CVE-2026-53354, CVE-2026-53355, CVE-2026-53356, CVE-2026-53361, CVE-2026-53362, CVE-2026-53363, CVE-2026-53366, CVE-2026-53381, CVE-2026-53382, CVE-2026-53383, CVE-2026-53384, CVE-2026-53385, CVE-2026-53386, CVE-2026-53387, CVE-2026-53388, CVE-2026-53389, CVE-2026-53390, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53395, CVE-2026-53396, CVE-2026-53397, CVE-2026-53398, CVE-2026-53399, CVE-2026-53400, CVE-2026-53401, CVE-2026-53402, CVE-2026-53403, CVE-2026-63794, CVE-2026-63795, CVE-2026-63796, CVE-2026-63797, CVE-2026-63798, CVE-2026-63799, CVE-2026-63800, CVE-2026-63801, CVE-2026-63802, CVE-2026-63803, CVE-2026-63804, CVE-2026-63805, CVE-2026-63806, CVE-2026-63807, CVE-2026-63808, CVE-2026-63809, CVE-2026-63810, CVE-2026-63811, CVE-2026-63812, CVE-2026-63813, CVE-2026-63814, CVE-2026-63815, CVE-2026-63816, CVE-2026-63817, CVE-2026-63818, CVE-2026-63819, CVE-2026-63820, CVE-2026-63821, CVE-2026-63822, CVE-2026-63823, CVE-2026-63824, CVE-2026-63825, CVE-2026-63826, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63831, CVE-2026-63832, CVE-2026-63833, CVE-2026-63834, CVE-2026-63835, CVE-2026-63836, CVE-2026-63867, CVE-2026-63868, CVE-2026-63869, CVE-2026-63870, CVE-2026-63871, CVE-2026-63873, CVE-2026-63874, CVE-2026-64187, CVE-2026-64188, CVE-2026-64189, CVE-2026-64191, CVE-2026-64192, CVE-2026-64205, CVE-2026-64206, CVE-2026-64207, CVE-2026-64244, CVE-2026-64245, CVE-2026-64246, CVE-2026-64247, CVE-2026-64249, CVE-2026-64251, CVE-2026-64253, CVE-2026-64254, CVE-2026-64255, CVE-2026-64256, CVE-2026-64258, CVE-2026-64259, CVE-2026-64260, CVE-2026-64261, CVE-2026-64262, CVE-2026-64263, CVE-2026-64264, CVE-2026-64265, CVE-2026-64266, CVE-2026-64267, CVE-2026-64268, CVE-2026-64269, CVE-2026-64270, CVE-2026-64271, CVE-2026-64272, CVE-2026-64273, CVE-2026-64274, CVE-2026-64275, CVE-2026-64276, CVE-2026-64277, CVE-2026-64278, CVE-2026-64279, CVE-2026-64280, CVE-2026-64282, CVE-2026-64283, CVE-2026-64284, CVE-2026-64285, CVE-2026-64286, CVE-2026-64287, CVE-2026-64288, CVE-2026-64289, CVE-2026-64290, CVE-2026-64291, CVE-2026-64292, CVE-2026-64293, CVE-2026-64294, CVE-2026-64295, CVE-2026-64296, CVE-2026-64297, CVE-2026-64298, CVE-2026-64299, CVE-2026-64300, CVE-2026-64301, CVE-2026-64302, CVE-2026-64303, CVE-2026-64304, CVE-2026-64305, CVE-2026-64306, CVE-2026-64307, CVE-2026-64308, CVE-2026-64309, CVE-2026-64310, CVE-2026-64312, CVE-2026-64313, CVE-2026-64314, CVE-2026-64315, CVE-2026-64316, CVE-2026-64317, CVE-2026-64318, CVE-2026-64319, CVE-2026-64320, CVE-2026-64321, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64325, CVE-2026-64326, CVE-2026-64327, CVE-2026-64328, CVE-2026-64329, CVE-2026-64330, CVE-2026-64331, CVE-2026-64332, CVE-2026-64333, CVE-2026-64334, CVE-2026-64335, CVE-2026-64336, CVE-2026-64337, CVE-2026-64338, CVE-2026-64339, CVE-2026-64340, CVE-2026-64341, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64345, CVE-2026-64346, CVE-2026-64347, CVE-2026-64348, CVE-2026-64350, CVE-2026-64351, CVE-2026-64352, CVE-2026-64353, CVE-2026-64354, CVE-2026-64355, CVE-2026-64356, CVE-2026-64357, CVE-2026-64358, CVE-2026-64359, CVE-2026-64360, CVE-2026-64361, CVE-2026-64362, CVE-2026-64363, CVE-2026-64364, CVE-2026-64365, CVE-2026-64366, CVE-2026-64367, CVE-2026-64368, CVE-2026-64369, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64376, CVE-2026-64377, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64388, CVE-2026-64389, CVE-2026-64390, CVE-2026-64391, CVE-2026-64392, CVE-2026-64393, CVE-2026-64394, CVE-2026-64395, CVE-2026-64396, CVE-2026-64397, CVE-2026-64398, CVE-2026-64399, CVE-2026-64400, CVE-2026-64401, CVE-2026-64402, CVE-2026-64403, CVE-2026-64404, CVE-2026-64405, CVE-2026-64406, CVE-2026-64407, CVE-2026-64408, CVE-2026-64409, CVE-2026-64410, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64414, CVE-2026-64415, CVE-2026-64416, CVE-2026-64417, CVE-2026-64418, CVE-2026-64419, CVE-2026-64420, CVE-2026-64421, CVE-2026-64422, CVE-2026-64423, CVE-2026-64424, CVE-2026-64425, CVE-2026-64426, CVE-2026-64428, CVE-2026-64429, CVE-2026-64430, CVE-2026-64432, CVE-2026-64433, CVE-2026-64434, CVE-2026-64435, CVE-2026-64436, CVE-2026-64438, CVE-2026-64439, CVE-2026-64440, CVE-2026-64441, CVE-2026-64442, CVE-2026-64443, CVE-2026-64444, CVE-2026-64445, CVE-2026-64446, CVE-2026-64447, CVE-2026-64448, CVE-2026-64449, CVE-2026-64450, CVE-2026-64451, CVE-2026-64452, CVE-2026-64453, CVE-2026-64454, CVE-2026-64455, CVE-2026-64456, CVE-2026-64457, CVE-2026-64458, CVE-2026-64459, CVE-2026-64460, CVE-2026-64461, CVE-2026-64462, CVE-2026-64463, CVE-2026-64464, CVE-2026-64465, CVE-2026-64466, CVE-2026-64467, CVE-2026-64468, CVE-2026-64469, CVE-2026-64470, CVE-2026-64471, CVE-2026-64472, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64476, CVE-2026-64477, CVE-2026-64478, CVE-2026-64479, CVE-2026-64480, CVE-2026-64481, CVE-2026-64482, CVE-2026-64483, CVE-2026-64484, CVE-2026-64485, CVE-2026-64486, CVE-2026-64487, CVE-2026-64488, CVE-2026-64489, CVE-2026-64490, CVE-2026-64491, CVE-2026-64492, CVE-2026-64493, CVE-2026-64494, CVE-2026-64495, CVE-2026-64496, CVE-2026-64497, CVE-2026-64499, CVE-2026-64500, CVE-2026-64501, CVE-2026-64502, CVE-2026-64503, CVE-2026-64504, CVE-2026-64505, CVE-2026-64507, CVE-2026-64508, CVE-2026-64509, CVE-2026-64510, CVE-2026-64511, CVE-2026-64512, CVE-2026-64513, CVE-2026-64514, CVE-2026-64529, CVE-2026-64536, CVE-2026-64556, CVE-2026-64588, CVE-2026-64589, CVE-2026-64590, CVE-2026-64591, CVE-2026-64592, CVE-2026-64593, CVE-2026-64594, CVE-2026-64596, CVE-2026-64597, CVE-2026-64598, CVE-2026-64599, CVE-2026-64600, CVE-2026-64601, CVE-2026-64602, CVE-2026-64603, CVE-2026-64604, CVE-2026-68084, CVE-2026-68085, CVE-2026-68087, CVE-2026-68088, CVE-2026-68089, CVE-2026-68090, CVE-2026-68091, CVE-2026-68092, CVE-2026-68459, CVE-2026-68460, CVE-2026-68461, CVE-2026-74584, CVE-2026-80591)

USN-8725-2: Linux kernel (AWS) vulnerabilities

8 hours 20 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - NVIDIA Tegra memory controller driver; - File systems infrastructure; - Network file system (NFS) server daemon; - OCFS2 file system; - B.A.T.M.A.N. meshing protocol; - Netfilter; - SCTP protocol; (CVE-2022-50401, CVE-2026-43071, CVE-2026-52914, CVE-2026-53002, CVE-2026-53043, CVE-2026-53045, CVE-2026-53224, CVE-2026-53309)

USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities

8 hours 21 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - File systems infrastructure; - Ext4 file system; - OCFS2 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; - TIPC protocol; (CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986, CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002, CVE-2026-53006, CVE-2026-53043, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53212, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53309, CVE-2026-53359)

USN-8714-3: Linux kernel vulnerabilities

8 hours 23 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)

USN-8779-2: Bubblewrap regression

18 hours 40 minutes ago
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete fix is available. We apologize for the inconvenience. Original advisory details: It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-12439) It was discovered that Bubblewrap incorrectly handled certain symlinks during sandbox setup. A local attacker could possibly use this issue to create files outside of the sandbox. (CVE-2026-87766)

USN-8780-1: libsoup vulnerabilities

1 day ago
It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1539) Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1801)

USN-8779-1: Bubblewrap vulnerabilities

1 day 1 hour ago
It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-12439) It was discovered that Bubblewrap incorrectly handled certain symlinks during sandbox setup. A local attacker could possibly use this issue to create files outside of the sandbox. (CVE-2026-87766)

USN-8776-1: python-cryptography vulnerabilities

1 day 20 hours ago
It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with observable timing differences. A remote attacker could possibly use this issue to recover the key used to encrypt the message contents, and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69247) Jack Lloyd discovered that python-cryptography incorrectly handled wildcard DNS names when enforcing the name constraints of a certificate authority. A remote attacker could possibly use this issue to have an invalid certificate chain accepted, and use names outside of the permitted ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248) Samuel Judson discovered that python-cryptography incorrectly handled certificate chains that contained duplicate certificates. A remote attacker could possibly use this issue to cause python-cryptography to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69249)

USN-8774-1: libheif vulnerabilities

2 days ago
Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna discovered that libheif incorrectly handled certain image sequences. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-62377)

USN-8736-2: Perl vulnerabilities

2 days 2 hours ago
USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (CVE-2026-15534) It was discovered that Perl incorrectly handled certain regular expression containing alternative matching branches. An attacker could possibly use this issue to cause incorrect regular expression matches, resulting in security restrictions being bypassed. (CVE-2026-19487)

USN-8772-1: AOM vulnerabilities

2 days 7 hours ago
It was discovered that AOM incorrectly handled the first-pass statistics buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use this issue to cause a heap buffer overflow, leading to a denial of service or possibly execute arbitrary code. (CVE-2026-56208) It was discovered that AOM incorrectly validated spatial and temporal layer IDs in the SVC (Scalable Video Coding) encoder controls. An attacker could possibly use this issue to write to an arbitrary memory address, read out-of-bounds heap memory, or execute arbitrary code. (CVE-2026-56209, CVE-2026-56210, CVE-2026-56211)
Checked
9 minutes 7 seconds ago