Aggregator

USN-8367-1: tar-fs vulnerabilities

3 weeks 6 days ago
It was discovered that tar-fs did not properly limit paths when extracting crafted tar files. An attacker could possibly use this issue to write or overwrite files outside the intended extraction directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-12905) It was discovered that tar-fs did not properly validate extraction paths for certain crafted tar archives. An attacker could possibly use this issue to write files outside the intended extraction directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-48387) It was discovered that tar-fs had a symlink validation bypass when extracting crafted tar files. An attacker could possibly use this issue to write files outside the intended extraction directory. (CVE-2025-59343)

USN-8366-1: Luanti vulnerabilities

3 weeks 6 days ago
It was discovered that Luanti, when using LuaJIT, did not properly enforce Lua sandbox restrictions. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-40959) It was discovered that Luanti did not properly restrict access to insecure environments. An attacker could possibly use this issue to obtain unintended access to the insecure environment or HTTP API. (CVE-2026-40960)

USN-8365-1: Dovecot vulnerabilities

3 weeks 6 days ago
It was discovered that Dovecot incorrectly treated some variable expansion pipelines as safe in authentication filters. An attacker could possibly use this issue to perform SQL or LDAP injection attacks. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-27851) It was discovered that Dovecot incorrectly verified SCRAM TLS channel binding in certain base64 exchanges. A remote attacker could possibly use this issue to obtain sensitive information in a machine-in-the-middle attack. (CVE-2026-33603) It was discovered that Dovecot incorrectly enforced Sieve script CPU limits. An attacker could possibly use this issue to cause Dovecot to use excessive resources, leading to a denial of service. (CVE-2026-40016) It was discovered that Dovecot incorrectly handled certain IMAP SETACL commands. An attacker could possibly use this issue to spam folders to other users. (CVE-2026-40020) It was discovered that Dovecot incorrectly handled excessive IMAP bracing. An attacker could possibly use this issue to cause Dovecot to use excessive resources, leading to a denial of service. (CVE-2026-42006)

USN-8363-1: MySQL vulnerabilities

3 weeks 6 days ago
Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.46 in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. Ubuntu 25.10 and Ubuntu 26.04 LTS have been updated to MySQL 8.4.9. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-9.html https://www.oracle.com/security-alerts/cpuapr2026.html