2 hours 51 minutes ago
It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when
an early failure occurred. An authenticated user could possibly use this
issue to execute arbitrary SQL commands. (CVE-2026-6464)
It was discovered that PostgreSQL incorrectly reset extended statistics
ownership during ALTER TABLE ALTER TYPE operations. An attacker could
possibly use this issue to obtain sensitive information or gain unintended
privileges. (CVE-2026-6469)
It was discovered that PostgreSQL failed to check the USAGE privilege on
types. An authenticated user could possibly use this issue to obtain
sensitive information. (CVE-2026-6470)
It was discovered that PostgreSQL logical decoding could load arbitrary
shared libraries. An authenticated user could possibly use this issue to
execute arbitrary code. (CVE-2026-6471)
It was discovered that PostgreSQL had integer wraparound issues in tsvector
and tsquery allocations. An authenticated user could possibly use this
issue to execute arbitrary code. (CVE-2026-14662)
It was discovered that PostgreSQL pgcrypto silently used cleartext when
OpenSSL-disabled ciphers were requested. An authenticated user could
possibly use this issue to obtain sensitive information. (CVE-2026-14663)
It was discovered that PostgreSQL had a heap buffer overflow in regular
expression processing. An authenticated user could possibly use this issue
to execute arbitrary code. (CVE-2026-14664)
It was discovered that PostgreSQL row security policies were not properly
invalidated when roles were modified. An attacker could possibly use this
issue to bypass intended row security restrictions. (CVE-2026-14666)
It was discovered that PostgreSQL had a type confusion issue in the
selectivity estimator involving ctid. An authenticated user could possibly
use this issue to obtain sensitive information. (CVE-2026-14668)
It was discovered that PostgreSQL had a heap buffer overflow in the to_char
function. An authenticated user could possibly use this issue to execute
arbitrary code. (CVE-2026-14669)
It was discovered that PostgreSQL had a heap buffer overflow in the PL/Perl
tied object handling. An authenticated user could possibly use this issue
to execute arbitrary code. (CVE-2026-14670)
It was discovered that PostgreSQL had a type confusion issue in the
referential integrity plan cache. An authenticated user could possibly use
this issue to execute arbitrary code. (CVE-2026-14671)
It was discovered that PostgreSQL had an observable response discrepancy
when non-default scram_iterations were used. A remote attacker could
possibly use this issue to enumerate valid usernames. This issue only
affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-14672)
It was discovered that PostgreSQL amcheck did not clear untrusted search
paths. An authenticated user could possibly use this issue to execute
arbitrary code. (CVE-2026-14673)
It was discovered that PostgreSQL had a heap buffer overflow in
pg_stat_statements. An authenticated user could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-14676)
It was discovered that PostgreSQL had integer wraparound issues in PL/Tcl
and PL/Perl allocations on 32-bit systems. An authenticated user could
possibly use this issue to execute arbitrary code. (CVE-2026-14677)
It was discovered that PostgreSQL pg_trgm read past the end of a buffer
during picksplit operations. An authenticated user could possibly use this
issue to obtain sensitive information. (CVE-2026-14678)
It was discovered that PostgreSQL had a stack buffer overflow in argument
matching. An authenticated user could possibly use this issue to corrupt
server memory. (CVE-2026-14679)
It was discovered that PostgreSQL had a type confusion issue when functions
used internal arguments. An authenticated user could possibly use this
issue to execute arbitrary code. (CVE-2026-14680)
It was discovered that PostgreSQL did not properly enforce GSSAPI
encryption when used together with SSL. An attacker could possibly use this
issue to perform a machine-in-the-middle attack and obtain sensitive
information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14681)
It was discovered that PostgreSQL allowed SQL injection through EXTRACT
arguments during expression deparsing. An authenticated user could possibly
use this issue to perform SQL injection attacks. (CVE-2026-15741)
It was discovered that PostgreSQL fuzzystrmatch had integer wraparound
issues that could write to arbitrary addresses. An authenticated user could
possibly use this issue to execute arbitrary code. (CVE-2026-15742)
It was discovered that PostgreSQL had a type confusion issue in
pg_restore_attribute_stats(). An authenticated user could possibly use this
issue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-16238)
It was discovered that PostgreSQL had a type confusion issue when handling
cursor CLOSE and DECLARE operations. An authenticated user could possibly
use this issue to execute arbitrary code. (CVE-2026-16239)
It was discovered that PostgreSQL had an integer underflow in the ECPG
client library. An attacker could possibly use this issue to cause
PostgreSQL to crash, resulting in a denial of service. (CVE-2026-16241)
It was discovered that PostgreSQL had an out-of-bounds read in the ascii()
function. An authenticated user could possibly use this issue to obtain
sensitive information. (CVE-2026-18024)
It was discovered that the psql \unrestrict command allowed the superuser
of a pg_dump origin server to execute arbitrary code in the psql client. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-18408)
It was discovered that PostgreSQL pg_dump had a heap buffer overflow. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-19385)
19 hours 3 minutes ago
USN-8563-3 fixed a vulnerability in nginx. The fix introduced a regression
in certain environments. This update reverts the fix for CVE-2026-42533
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain map directives
using regex matching and capture variables. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had a use-after-free vulnerability in the
ngx_http_ssi_module module when configured with Server-Side Includes,
proxy_pass, and proxy buffering disabled directives. An attacker able to
intercept traffic and control responses from an upstream server could
possibly use this issue to cause nginx to crash, resulting in a denial of
service. (CVE-2026-56434)
It was discovered that nginx incorrectly handled certain requests in the
ngx_http_slice_module module. A remote attacker could possibly use this
issue to obtain sensitive information or cause nginx to crash, resulting
in a denial of service. (CVE-2026-60005)
21 hours 50 minutes ago
It was discovered that curl incorrectly handled reusing connections
when the origin changed between transfers. A remote attacker could
possibly use this issue to obtain sensitive information.
22 hours 34 minutes ago
Chanho Kim and Jihyeok Han discovered that Cap'n Proto incorrectly
handled negative Content-Length values or excessively large chunk sizes
when processing HTTP messages. An attacker could possibly use these
issues to cause HTTP messages to be interpreted inconsistently,
resulting in HTTP request or response smuggling. (CVE-2026-32239,
CVE-2026-32240)
1 day 1 hour ago
It was discovered that libheif had an integer underflow in the Fraction
constructor when a clap transform was applied twice. An attacker could
possibly use this issue to cause libheif to crash, resulting in a denial of
service. (CVE-2026-62289)
It was discovered that libheif had an out-of-bounds read in uncompressed
tile range slicing. An attacker could possibly use this issue to cause
libheif to crash, resulting in a denial of service. This issue only
affected Ubuntu 25.10. (CVE-2026-62292)
1 day 2 hours ago
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was
backed out in USN-8563-2 because it could cause a regression. This update
includes a better fix for CVE-2026-42533.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain map directives
using regex matching and capture variables. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had a use-after-free vulnerability in the
ngx_http_ssi_module module when configured with Server-Side Includes,
proxy_pass, and proxy buffering disabled directives. An attacker able to
intercept traffic and control responses from an upstream server could
possibly use this issue to cause nginx to crash, resulting in a denial of
service. (CVE-2026-56434)
It was discovered that nginx incorrectly handled certain requests in the
ngx_http_slice_module module. A remote attacker could possibly use this
issue to obtain sensitive information or cause nginx to crash, resulting
in a denial of service. (CVE-2026-60005)
1 day 2 hours ago
It was discovered that Bind incorrectly accepted NSEC3 records whose signer
name did not match the owning zone. A remote attacker could possibly use
this issue to perform NSEC3 impersonation attacks, bypassing DNSSEC
validation. (CVE-2026-10723)
It was discovered that Bind incorrectly handled Key Records using the
PRIVATEDNS algorithm. A remote attacker could possibly use this issue to
cause Bind to crash, resulting in a denial of service. (CVE-2026-10822)
It was discovered that Bind incorrectly handled wildcard CNAME expansion in
Response Policy Zones. A remote attacker could possibly use this issue to
bypass configured RPZ policies. (CVE-2026-11331)
It was discovered that Bind performed unnecessary validation of DNSSEC
signed records. A remote attacker could possibly use this issue to cause
Bind to use excessive resources, leading to a denial of service. This issue
only affected Ubuntu 26.04 LTS. (CVE-2026-11605)
It was discovered that Bind incorrectly tracked memory usage in the DNS
cache. A remote attacker could possibly use this issue to cause Bind to use
memory beyond configured limits, leading to a denial of service.
(CVE-2026-11622)
It was discovered that Bind incorrectly handled signed wildcard records
with label count discrepancies and RRSIG validation. A remote attacker
could possibly use this issue to perform cache poisoning attacks.
(CVE-2026-11721)
It was discovered that Bind incorrectly handled certain CNAME and DNAME
record orderings in the resolver. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service.
(CVE-2026-12617)
It was discovered that Bind incorrectly validated out-of-zone NSEC next
owner names during DNSSEC validation. A remote attacker could possibly use
this issue to bypass DNSSEC validation. (CVE-2026-13321)
1 day 6 hours ago
USN-8093-1 fixed a vulnerability in libssh. This update provides
the corresponsing fix for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that libssh incorrectly performed bounds checking when
processing SFTP extensions. If a client application queried extension data out
of bounds, it could cause the application to crash, resulting in a denial of
service, or exhibit unintended behavior.
1 day 6 hours ago
USN 8113-1 fixed vulnerabilities in tiff. This update
provides the corresponding fixes for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that LibTIFF did not properly handle memory when
processing certain images. An attacker could possibly use this issue to
cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61143)
It was discovered that LibTIFF did not properly handle memory when
processing malformed TIFF directories. An attacker could possibly use this
issue to cause LibTIFF to crash, resulting in a denial of service.
(CVE-2025-61144)
1 day 17 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infrastructure;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- B.A.T.M.A.N. meshing protocol;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
1 day 17 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Media drivers;
- Network drivers;
- Mellanox network drivers;
- Texas Instruments network drivers;
- NVME drivers;
- File systems infrastructure;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- Memory management;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31405, CVE-2026-31414, CVE-2026-31501, CVE-2026-31589,
CVE-2026-31633, CVE-2026-31636, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43379, CVE-2026-43465, CVE-2026-43499, CVE-2026-46113,
CVE-2026-46137, CVE-2026-46242, CVE-2026-46331, CVE-2026-52924,
CVE-2026-52989, CVE-2026-53086, CVE-2026-53131, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
1 day 17 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Network traffic control;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
(CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53151,
CVE-2026-53175, CVE-2026-53176, CVE-2026-53186, CVE-2026-53212,
CVE-2026-53215, CVE-2026-53216, CVE-2026-53221, CVE-2026-53224,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53247,
CVE-2026-53260, CVE-2026-53359)
1 day 20 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- OCFS2 file system;
- B.A.T.M.A.N. meshing protocol;
- Netfilter;
- SCTP protocol;
(CVE-2026-52914, CVE-2026-53002, CVE-2026-53043, CVE-2026-53224,
CVE-2026-53246, CVE-2026-53309)
1 day 20 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- GPU drivers;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- STMicroelectronics network drivers;
- NVME drivers;
- File systems infrastructure;
- Ext4 file system;
- OCFS2 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
(CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405,
CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657,
CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493,
CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982,
CVE-2026-52986, CVE-2026-52993, CVE-2026-53002, CVE-2026-53006,
CVE-2026-53043, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246,
CVE-2026-53309, CVE-2026-53359)
1 day 20 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- File systems infrastructure;
- OCFS2 file system;
- B.A.T.M.A.N. meshing protocol;
- SCTP protocol;
- TIPC protocol;
(CVE-2026-43071, CVE-2026-52914, CVE-2026-52993, CVE-2026-53043,
CVE-2026-53224, CVE-2026-53246, CVE-2026-53309)
1 day 20 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
1 day 23 hours ago
Miha Zupan discovered that .NET did not properly interpret certain HTTP
requests. An attacker could possibly use this issue to perform request
smuggling and bypass a security feature. (CVE-2026-62899)
Ivan Demchuk discovered that .NET did not properly handle the removal of
sensitive information before storage or transfer. An attacker could possibly
use this issue to disclose sensitive information. (CVE-2026-62900)
Kevin Gosse discovered that .NET did not properly check an input for a loop
condition. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-62901)
Kevin Gosse discovered that .NET did not properly perform error checking
when securing shared resources used for diagnostics IPC. An attacker could
possibly use this issue to elevate privileges. (CVE-2026-62909)
2 days 1 hour ago
It was discovered that c3p0 was vulnerable to remote code execution via maliciously
crafted serialized objects and JNDI references. An attacker could use this to
execute arbitrary code, bypass security restrictions, or cause a denial of service.
2 days 21 hours ago
It was discovered that Engrampa incorrectly handled symbolic links when
extracting certain archives. An attacker could possibly use this issue to
write arbitrary files and execute arbitrary code.
2 days 21 hours ago
Patrick Keshishian discovered that libpng incorrectly handled certain
text chunks. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10087)
It was discovered that libpng incorrectly handled certain malformed
images. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-14048)
It was discovered that libpng incorrectly handled memory when freeing
certain images. An attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-7317)
It was discovered that libpng incorrectly handled memory when
processing certain images. An attacker could possibly use this issue
to cause a denial of service, or execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS. (CVE-2026-33416)
It was discovered that libpng incorrectly handled certain images. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 20.04 LTS.
(CVE-2026-33636)
It was discovered that libpng incorrectly handled memory when
processing certain images. An attacker could possibly use this issue
to cause a denial of service or obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-34757)
Seung Min Shin discovered that libpng incorrectly handled certain
animated images. An attacker could possibly use this issue to cause
libpng to misinterpret image data. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2026-40930)
Checked
16 minutes 6 seconds ago