Ubuntu Security Advisories

USN-8816-3: Linux kernel (Oracle) vulnerabilities

3 hours 7 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - S390 architecture; - x86 architecture; - DRBD Distributed Replicated Block Device drivers; - InfiniBand drivers; - IOMMU subsystem; - Multiple devices driver; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - NVME drivers; - TCM subsystem; - Virtio Host (VHOST) subsystem; - Xen hypervisor drivers; - AFS file system; - File systems infrastructure; - Network file systems library; - Network file system (NFS) client; - NTFS3 file system; - OCFS2 file system; - OrangeFS file system; - SMB network file system; - IPv4 networking; - Sun RPC protocol; - IPv6 networking; - IP tunnels definitions; - Netfilter; - TCP network protocol; - Locking primitives; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Networking core; - IFE protocol; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - TIPC protocol; - XFRM subsystem; (CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541, CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476, CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033, CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065, CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085, CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137, CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194, CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222, CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249, CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279, CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296, CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329, CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355, CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398, CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422, CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451, CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473, CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494, CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255, CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287, CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361, CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398, CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428, CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439, CVE-2026-80665)

USN-8817-3: Linux kernel (AWS) vulnerabilities

3 hours 7 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)

USN-8818-5: Linux kernel (NVIDIA Tegra) vulnerabilities

3 hours 7 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8854-1: OpenStack Keystone vulnerabilities

4 hours 5 minutes ago
Grzegorz Grasza discovered that OpenStack Keystone did not consistently enforce restrictions for delegated authentication tokens. An authenticated attacker could possibly use this issue to create credentials or delegations that outlasted the delegated token. (CVE-2026-80182) It was discovered that OpenStack Keystone incorrectly handled role assignment queries under certain circumstances. An authenticated attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-80183) Tim Shephard discovered that OpenStack Keystone did not properly restrict reauthentication using delegated tokens. An authenticated attacker could possibly use this issue to escape their intended project scope and obtain unauthorized access. (CVE-2026-80184)

USN-8852-1: OpenVPN vulnerabilities

5 hours 18 minutes ago
It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-84471) It was discovered that OpenVPN incorrectly handled retransmissions of ACK packet IDs, which could trigger a timeout integer overflow. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-84732)

USN-8851-1: Linux kernel vulnerabilities

7 hours 19 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8850-1: Linux kernel (BlueField) vulnerabilities

9 hours 2 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - OCFS2 file system; - IPv6 networking; - Netfilter; - SCTP protocol; (CVE-2025-38724, CVE-2026-53043, CVE-2026-53131, CVE-2026-53221, CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)

USN-8849-1: Linux kernel (NVIDIA Tegra) vulnerabilities

9 hours 8 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8818-4: Linux kernel vulnerabilities

9 hours 12 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8817-2: Linux kernel (AWS FIPS) vulnerabilities

9 hours 12 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)

USN-8819-4: Linux kernel (FIPS) vulnerabilities

9 hours 12 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8847-2: OpenSSL vulnerabilities

17 hours 44 minutes ago
USN-8847-1 fixed vulnerabilities in OpenSSL. This update provides the corresponding fix for OpenSSL on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. (CVE-2026-35189) It was discovered that OpenSSL incorrectly implemented scalar multiplication for non-NIST elliptic curves. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-54872) It was discovered that OpenSSL incorrectly implemented SM2 signature generation. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-77696) It was discovered that OpenSSL incorrectly handled DTLS retransmission of handshake messages. An attacker could possibly use this issue to cause incorrect handshake behavior or a denial of service. (CVE-2026-84782)

USN-8847-1: OpenSSL vulnerabilities

22 hours 53 minutes ago
It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. (CVE-2026-35189) It was discovered that OpenSSL incorrectly handled QUIC unvalidated amplification credit accounting. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-35191) It was discovered that OpenSSL incorrectly implemented scalar multiplication for non-NIST elliptic curves. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. (CVE-2026-54872) It was discovered that OpenSSL incorrectly implemented SM2 scalar multiplication on ARM64 and RISC-V architectures. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54875) It was discovered that OpenSSL incorrectly handled SSL context switching during a TLS handshake. An attacker could possibly use this issue to cause an out-of-bounds read, resulting in a denial of service or obtaining sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-72897) It was discovered that OpenSSL incorrectly enforced QUIC connection- level flow control for streams. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-75804) It was discovered that OpenSSL incorrectly handled a NULL pointer in CMP client revocation response processing. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-75805) It was discovered that OpenSSL incorrectly handled undersized DTLS 1.2 AEAD records before authentication. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-75806) It was discovered that OpenSSL incorrectly implemented SM2 signature generation. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. (CVE-2026-77696) It was discovered that OpenSSL incorrectly handled DTLS retransmission of handshake messages. An attacker could possibly use this issue to cause incorrect handshake behavior or a denial of service. (CVE-2026-84782) It was discovered that OpenSSL incorrectly handled QUIC RETIRE_CONNECTION_ID frames. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84784)

USN-8846-1: libheif vulnerabilities

1 day ago
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain compressed metadata. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84384) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain HEIF sequence data. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84446) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain image references. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84447) It was discovered that libheif incorrectly handled certain region masks. A local attacker could possibly use this issue to obtain sensitive information or cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84448) It was discovered that libheif incorrectly handled certain images. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-84449)

USN-8844-1: c-ares vulnerability

1 day 1 hour ago
It was discovered that c-ares incorrectly handled certain query completion callbacks. An attacker could possibly use this issue to trigger a use- after-free or double-free, resulting in a denial of service or arbitrary code execution.

USN-8843-1: FreeIPMI vulnerabilities

1 day 2 hours ago
It was discovered that FreeIPMI incorrectly handled certain malformed Fujitsu SEL long-text responses, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-85504) It was discovered that FreeIPMI incorrectly handled short responses when retrieving Fujitsu SEL entries, leading to a stack-based buffer over-read. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service. (CVE-2026-85505) It was discovered that FreeIPMI incorrectly handled certain Dell iDRAC and CMC IPv6 system information responses, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-85506, CVE-2026-85508) It was discovered that FreeIPMI incorrectly handled certain Dell CMC system information responses, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-85507) It was discovered that FreeIPMI incorrectly handled FRU data responses that were larger than requested, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-85509)

USN-8818-3: Linux kernel vulnerabilities

1 day 7 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
Checked
31 seconds ago