Ubuntu Security Advisories

USN-8729-5: Linux kernel (AWS FIPS) vulnerabilities

18 hours 27 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPU drivers; - Hardware monitoring drivers; - InfiniBand drivers; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - SCSI subsystem; - SPI subsystem; - Network file systems library; - NTFS3 file system; - SMB network file system; - File systems infrastructure; - Software nodes and device properties; - Bluetooth subsystem; - Netfilter; - Tracing infrastructure; - io_uring subsystem; - IRQ subsystem; - KProbes tracing; - Memory management; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - Phonet protocol; - SMC sockets; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - Key management; - Linux Security Modules (LSM) Framework; - ALSA framework; - AudioScience HPI driver; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015, CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)

USN-8818-2: Linux kernel (IBM) vulnerabilities

18 hours 27 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8819-2: Linux kernel vulnerabilities

18 hours 27 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8820-1: curl vulnerabilities

1 day 9 hours ago
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for LDAP authentication in certain circumstances. A machine-in-the-middle attacker could possibly use this issue to bypass peer validation. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13608) Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server Push streams when sharing connections between handles. A remote attacker could possibly use this issue to cause curl to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-18924) Stanislav Fort discovered that curl incorrectly managed the lifetime of pooled TLS connections when using the multi interface. An attacker could possibly use this issue to cause curl to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-80229) Stanislav Fort discovered that curl did not properly enforce public key pinning when certificate verification was disabled in certain circumstances. A remote attacker could possibly use this issue to bypass pinning checks and cause curl to accept connections that should have been rejected. (CVE-2026-80230) Stanislav Fort discovered that curl incorrectly handled the Secure attribute of cookies in certain circumstances. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-80255) Stanislav Fort discovered that curl did not properly enforce Public Suffix List boundaries when handling cookies in certain circumstances. A remote attacker could possibly use this issue to cause cookies to be sent to unrelated domains, resulting in sensitive information being exposed. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-82209) Ady Elouej discovered that curl did not clear proxy authentication state between requests when reusing a handle with environment-variable proxy configuration. A remote attacker could possibly use this issue to obtain sensitive credentials. This issue was previously fixed in USN-8487-1, but that fix was incomplete for Ubuntu 16.04 LTS. (CVE-2026-8927)

USN-8821-1: OpenStack Swift vulnerability

1 day 10 hours ago
It was discovered that OpenStack Swift incorrectly handled truncated aws-chunked PUT request bodies in its s3api middleware. An authenticated attacker could possibly use this issue to cause OpenStack Swift to use excessive resources, leading to a denial of service.

USN-8819-1: Linux kernel vulnerabilities

1 day 15 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8818-1: Linux kernel vulnerabilities

1 day 15 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8817-1: Linux kernel vulnerabilities

1 day 15 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)

USN-8816-1: Linux kernel vulnerabilities

1 day 15 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - S390 architecture; - x86 architecture; - DRBD Distributed Replicated Block Device drivers; - InfiniBand drivers; - IOMMU subsystem; - Multiple devices driver; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - NVME drivers; - TCM subsystem; - Virtio Host (VHOST) subsystem; - Xen hypervisor drivers; - AFS file system; - File systems infrastructure; - Network file systems library; - Network file system (NFS) client; - NTFS3 file system; - OCFS2 file system; - OrangeFS file system; - SMB network file system; - IPv4 networking; - Sun RPC protocol; - IPv6 networking; - IP tunnels definitions; - Netfilter; - TCP network protocol; - Locking primitives; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Networking core; - IFE protocol; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - TIPC protocol; - XFRM subsystem; (CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541, CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476, CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033, CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065, CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085, CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137, CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194, CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222, CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249, CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279, CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296, CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329, CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355, CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398, CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422, CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451, CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473, CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494, CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255, CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287, CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361, CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398, CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428, CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439, CVE-2026-80665)

USN-8815-1: libass vulnerabilities

1 day 15 hours ago
It was discovered that libass incorrectly handled parsing operations for specific nested character strings. An attacker could use this issue to cause libass to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-24994) It was discovered that libass incorrectly handled certain outline processing operations. An attacker could use this issue to cause libass to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-26682) It was discovered that libass incorrectly handled certain ASS subtitle files when measuring wrapped lines. An attacker could use this issue to cause libass to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-61627) It was discovered that libass incorrectly handled certain Matroska subtitle chunks with negative ReadOrder values. An attacker could use this issue to cause libass to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-61626)

USN-8813-1: Expat vulnerabilities

1 day 17 hours ago
It was discovered that Expat did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-56406, CVE-2026-56407, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411) It was discovered that Expat did not correctly track handler call depth. An attacker could possibly use this issue to cause Expat to crash or execute arbitrary code. (CVE-2026-56131) It was discovered that Expat did not correctly handle certain memory operations. An attacker could possibly use this issue to cause Expat to crash or execute arbitrary code. (CVE-2026-56132) It was discovered that Expat did not correctly handle certain Unicode characters. An attacker could possibly use this issue to cause Expat to use excessive resources, leading to a denial of service. (CVE-2026-72522) It was discovered that Expat did not correctly process certain XML attributes. A remote attacker could possibly use this issue to cause Expat to use excessive resources, leading to a denial of service. (CVE-2026-66046) It was discovered that Expat did not correctly handle certain external entities. An attacker could possibly use this issue to cause Expat to crash or execute arbitrary code. (CVE-2026-76641) It was discovered that Expat did not correctly track handler call depth with custom encodings. An attacker could possibly use this issue to cause Expat to crash or execute arbitrary code. (CVE-2026-76957)

USN-8814-1: Octavia vulnerabilities

1 day 17 hours ago
It was discovered that Octavia did not properly validate TLS cipher string fields in the Amphora provider driver. An authenticated attacker who owns a TLS-enabled load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives. (CVE-2026-94572) It was discovered that Octavia did not properly validate L7 policy redirect URL fields in the Amphora provider driver. An authenticated attacker who owns a load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives. (CVE-2026-94571) It was discovered that Octavia incorrectly handled quality of service policy authorization. An authenticated attacker could possibly use this issue to prevent deletion of another project's QoS policy. (CVE-2026-74248)

USN-8812-1: GDAL vulnerabilities

1 day 18 hours ago
It was discovered that GDAL incorrectly handled certain netCDF files. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-49014) It was discovered that GDAL incorrectly handled certain HDF-EOS files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2026-8086, CVE-2026-8087, CVE-2026-8212, CVE-2026-8213) It was discovered that GDAL incorrectly handled certain HDF-EOS file metadata. An attacker could possibly use this issue to cause GDAL to crash, resulting in a denial of service. (CVE-2026-8084, CVE-2026-8088)

USN-8810-1: ImageMagick vulnerabilities

2 days 5 hours ago
It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33535) Kamil Frankowicz discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33536) It was discovered that ImageMagick did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-34238) Jake Lamberson discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40310) Junmin Zhu discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40311) It was discovered that ImageMagick did not correctly handle opening certain MSL files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly cause a denial of service. This issue affected Ubuntu 26.04 LTS. (CVE-2026-40312) It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56361)

USN-8287-2: XDG Desktop Portal regression

2 days 11 hours ago
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

USN-8808-1: SQL parse vulnerabilities

2 days 11 hours ago
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.
Checked
11 minutes 22 seconds ago