Ubuntu Security Advisories

USN-8870-1: OpenStack Aodh and Watcher vulnerability

6 hours 40 minutes ago
Chen YuXiang discovered that OpenStack Aodh did not correctly enforce project scoping in its alarm list API and that the OpenStack Watcher webhook trigger endpoint did not apply authorization. An attacker could possibly use this issue to access sensitive alarm metadata or trigger unauthorized action plans.

USN-8871-1: Linux kernel (Raspberry Pi) vulnerabilities

6 hours 56 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8851-3: Linux kernel (Azure) vulnerabilities

7 hours 1 minute ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8868-1: LibreOffice vulnerabilities

8 hours 30 minutes ago
It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63272) It was discovered that LibreOffice incorrectly handled PDF document imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63273, CVE-2026-63274) It was discovered that LibreOffice incorrectly handled CFF fonts embedded in documents. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63275, CVE-2026-63276) It was discovered that LibreOffice incorrectly validated package URLs. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-63278) It was discovered that LibreOffice incorrectly handled PICT image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or obtain sensitive information. (CVE-2026-63279) It was discovered that LibreOffice incorrectly mitigated out-of-bounds writes via Graphite font actions. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-50593)

USN-8867-1: Ceph vulnerability

10 hours 13 minutes ago
It was discovered that the Ceph Object Gateway (RGW) SigV4 handler did not reject requests carrying x-amz-* headers that were absent from the signed header set. An attacker holding a presigned URL could possibly use this issue to attach arbitrary unsigned x-amz-* headers that RGW would honor, allowing them to escalate their privileges beyond what the URL's signer intended.

USN-8865-1: EDK II vulnerabilities

10 hours 38 minutes ago
It was discovered that EDK II incorrectly handled CMS key unwrapping in the embedded OpenSSL library. An attacker could possibly use this issue to cause a heap buffer overflow, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63072) It was discovered that EDK II incorrectly handled CMP protection verification in the embedded OpenSSL library. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-63076) It was discovered that EDK II incorrectly buffered DTLS records in the embedded OpenSSL library. A remote attacker could possibly use this issue to cause EDK II to consume excessive memory, resulting in a denial of service. (CVE-2026-54874) It was discovered that EDK II incorrectly verified AEAD tags in the embedded OpenSSL library. An attacker could possibly use this issue to cause EDK II to accept forged messages. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-75803)

USN-8864-1: Linux kernel vulnerabilities

3 days 14 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8816-4: Linux kernel (GKE) vulnerabilities

3 days 15 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - S390 architecture; - x86 architecture; - DRBD Distributed Replicated Block Device drivers; - InfiniBand drivers; - IOMMU subsystem; - Multiple devices driver; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - NVME drivers; - TCM subsystem; - Virtio Host (VHOST) subsystem; - Xen hypervisor drivers; - AFS file system; - File systems infrastructure; - Network file systems library; - Network file system (NFS) client; - NTFS3 file system; - OCFS2 file system; - OrangeFS file system; - SMB network file system; - IPv4 networking; - Sun RPC protocol; - IPv6 networking; - IP tunnels definitions; - Netfilter; - TCP network protocol; - Locking primitives; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Networking core; - IFE protocol; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - TIPC protocol; - XFRM subsystem; (CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541, CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476, CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033, CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065, CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085, CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137, CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194, CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222, CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249, CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279, CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296, CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329, CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355, CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398, CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422, CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451, CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473, CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494, CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255, CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287, CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361, CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398, CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428, CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439, CVE-2026-80665)

USN-8818-6: Linux kernel (FIPS) vulnerabilities

3 days 15 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8851-2: Linux kernel (Raspberry Pi) vulnerabilities

3 days 15 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

USN-8863-1: GStreamer Good Plugins vulnerabilities

4 days 4 hours ago
Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled certain FLAC audio streams. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-17072) Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed certain AVI files. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-73433) Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse certain AVI files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-73434) Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled certain closed caption data. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-88914)

USN-8862-1: libXpm vulnerability

4 days 8 hours ago
It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause libXpm to use excessive resources, leading to a denial of service.

USN-8861-1: OpenSSL vulnerabilities

4 days 9 hours ago
It was discovered that OpenSSL had an inefficient algorithm in its QUIC stream reassembly implementation. A remote attacker could possibly use this issue to cause OpenSSL to use excessive CPU resources, leading to a denial of service. (CVE-2026-42772) It was discovered that OpenSSL did not properly limit memory allocated for QUIC packet buffers. A remote attacker could possibly use this issue to cause OpenSSL to use excessive memory resources, leading to a denial of service. (CVE-2026-54873)

USN-8857-1: KCoreAddons vulnerability

4 days 10 hours ago
It was discovered that KCoreAddons incorrectly handled shell argument quoting in KShell::quoteArgs. The parsing did not adequately handle shell metacharacters, which could lead to a shell escape. An attacker could possibly use this issue to execute arbitrary commands in applications that relied on this method to handle user input.

USN-8859-1: ImageMagick vulnerabilities

5 days 5 hours ago
It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-56367) It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-93586) It was discovered that ImageMagick did not correctly handle certain images. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93587, CVE-2026-93588) It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93589) It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-93590)

USN-8855-1: GStreamer Bad Plugins vulnerability

5 days 5 hours ago
It was discovered that GStreamer Bad Plugins incorrectly validated the size of multi-channel audio blocks. An attacker could possibly use this issue with a specially crafted WAV file to cause the program to crash, resulting in a denial of service, or possibly execute arbitrary code.

USN-8845-1: GVfs vulnerabilities

5 days 5 hours ago
Keith Linneman discovered that GVfs did not properly validate data received from SFTP servers. An attacker could possibly use this issue to cause a heap buffer overflow, resulting in arbitrary code execution or a denial of service. (CVE-2026-84268) It was discovered that GVfs incorrectly handled file ownership when creating private D-Bus sockets in the admin backend. A local attacker could possibly use this issue to change the ownership of arbitrary system files, resulting in privilege escalation to root. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-88924)
Checked
10 minutes 9 seconds ago