Ubuntu Security Advisories

USN-7977-1: Git LFS vulnerabilities

3 weeks 1 day ago
Ryota K discovered that Git LFS may leak login credentials in certain instances due to failing to check for URL-encoded characters. An attacker could possibly use this issue to learn sensitive information. (CVE-2024-53263) It was discovered that Git LFS could have its git lfs checkout and git lfs pull commands abused to write to any file on a user's system. An attacker could possibly use this issue to execute arbitrary code. This issue was only addressed in Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-26625)

USN-7976-1: Form-Data vulnerability

3 weeks 1 day ago
Ben Shonaldmann discovered that Form-data incorrectly generated boundary values for multipart form-encoded data, leading to predictable values. A remote attacker could possibly use this issue to make arbitrary requests to internal systems.

USN-7973-1: cJSON vulnerabilities

3 weeks 5 days ago
It was discovered that cJSON incorrectly handled parsing large numbers. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-26819) It was discovered that cJSON may perform out-of-bounds read when processing specially crafted JSON files using parse_object. An attacker could possibly use this issue to expose sensitive information or crash the program. (CVE-2023-53154) It was discovered that cJSON incorrectly validated array indices in JSON pointers, which could result in an out-of-bounds memory access. An attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. (CVE-2025-57052)

USN-7975-1: pyasn1 vulnerability

3 weeks 5 days ago
It was discovered that pyasn1 incorrectly handled malformed RELATIVE-OIDs with excessive continuation octets. An attacker could possibly use this issue to cause pyasn1 to consume memory, leading to a denial of service.

USN-7974-1: libxml2 vulnerabilities

3 weeks 5 days ago
It was discovered that libxml2 incorrectly handled maliciously crafted SGML catalog files. An attacker could possibly use this issue to cause libxml2 to consume excessive resources, leading to a denial of service. (CVE-2025-8732) It was discovered that libxml2 incorrectly handled recursive include directories with the RelaxNG parser. An attacker could possibly use this issue to cause libxml2 to consume excessive resources, leading to a denial of service. (CVE-2026-0989) Nick Wellnhofer discovered that libxml2 incorrectly parsed catalogs with self-referencing URI delegates. An attacker could possibly use this issue to cause libxml2 to consume excessive resources, leading to a denial of service. (CVE-2026-0990) Nick Wellnhofer discovered that libxml2 inefficiently parsed catalogs linked with repeating nextCatalog elements. An attacker could possibly use this issue to cause libxml2 to use excessive resources, leading to a denial of service. (CVE-2026-0992)

USN-7971-1: GLib vulnerability

3 weeks 6 days ago
It was discovered that GLib incorrectly handled the buffered input stream API. An attacker could use this issue to cause GLib to crash, resulting in a denial of service, or possibly execute arbitrary code.
Checked
7 minutes 2 seconds ago