Aggregator

USN-8812-1: GDAL vulnerabilities

4 days 6 hours ago
It was discovered that GDAL incorrectly handled certain netCDF files. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-49014) It was discovered that GDAL incorrectly handled certain HDF-EOS files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2026-8086, CVE-2026-8087, CVE-2026-8212, CVE-2026-8213) It was discovered that GDAL incorrectly handled certain HDF-EOS file metadata. An attacker could possibly use this issue to cause GDAL to crash, resulting in a denial of service. (CVE-2026-8084, CVE-2026-8088)

USN-8810-1: ImageMagick vulnerabilities

4 days 17 hours ago
It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33535) Kamil Frankowicz discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33536) It was discovered that ImageMagick did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-34238) Jake Lamberson discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40310) Junmin Zhu discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40311) It was discovered that ImageMagick did not correctly handle opening certain MSL files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly cause a denial of service. This issue affected Ubuntu 26.04 LTS. (CVE-2026-40312) It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56361)

USN-8287-2: XDG Desktop Portal regression

4 days 23 hours ago
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

USN-8808-1: SQL parse vulnerabilities

5 days ago
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.