Aggregator

USN-8770-1: SimpleSAMLphp vulnerabilities

3 days 19 hours ago
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents. A remote attacker could possibly use this issue to obtain sensitive information. This issue did not affect Ubuntu 24.04 LTS. (CVE-2024-52596) It was discovered that SimpleSAMLphp incorrectly verified signatures in SAML messages using the HTTP-Redirect binding. A remote attacker could possibly use this issue to bypass authentication and impersonate users. (CVE-2025-27773)

USN-8769-1: phpseclib vulnerability

3 days 20 hours ago
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.

USN-8766-1: Suricata-Update vulnerability

3 days 20 hours ago
Guillem Lefait discovered that Suricata-Update did not properly validate destination paths when extracting files referenced by downloaded rule archives. An attacker could possibly use this issue to write arbitrary files outside the configured rules directory.

USN-8764-1: SRT vulnerabilities

3 days 22 hours ago
It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an encrypted connection and inject arbitrary content or interrupt a media stream. (CVE-2026-55868) It was discovered that SRT did not properly validate certain control packets during connection setup and key refresh operations. A remote attacker could possibly use this issue to cause SRT to crash, resulting in a denial of service. (CVE-2026-55869)

USN-8763-1: kitty vulnerabilities

3 days 22 hours ago
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-42850) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. (CVE-2026-42851) Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. (CVE-2026-54055) It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54057)

USN-8761-1: Linux kernel (Azure) vulnerabilities

4 days 2 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPU drivers; - Hardware monitoring drivers; - InfiniBand drivers; - Network drivers; - SCSI subsystem; - SPI subsystem; - Network file systems library; - NTFS3 file system; - SMB network file system; - File systems infrastructure; - Software nodes and device properties; - Bluetooth subsystem; - Netfilter; - Tracing infrastructure; - io_uring subsystem; - IRQ subsystem; - KProbes tracing; - Memory management; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - Phonet protocol; - SMC sockets; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - Key management; - Linux Security Modules (LSM) Framework; - ALSA framework; - AudioScience HPI driver; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)