<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Thu, 27 Aug 2026 05:43:57 +0000</lastBuildDate><item><title>USN-8683-1: libheif vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8683-1</link><description>Feng Ning discovered that libheif incorrectly handled certain image
transforms. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-62289)

Ali Firas discovered that libheif incorrectly handled certain images. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 24.04 LTS.
(CVE-2026-62291)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8683-1</guid><pubDate>Wed, 26 Aug 2026 16:56:18 +0000</pubDate></item><item><title>USN-8682-1: Bind vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8682-1</link><description>Vitaly Simonovich discovered that Bind could exhaust memory during
GSS-API TKEY negotiation. A remote attacker could possibly use this
issue to cause Bind to use excessive resources, leading to a denial of
service. (CVE-2026-3039)

Shuhan Zhang discovered that Bind incorrectly handled self-pointed glue
records. A remote attacker could possibly use this issue to use Bind in
denial of service amplification attacks against other systems.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2026-3592)

It was discovered that Bind incorrectly handled DNS messages whose
class was not IN. A remote attacker could possibly use this issue to
cause Bind to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-5946)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8682-1</guid><pubDate>Wed, 26 Aug 2026 16:49:52 +0000</pubDate></item><item><title>USN-8681-1: OpenJDK 25 vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8681-1</link><description>It was discovered that the JSSE component of OpenJDK 25 did not correctly
authenticate users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-46968)

It was discovered that the JSSE component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-46917)

It was discovered that the ImageIO component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-47010)

It was discovered that the 2D component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-47021, CVE-2026-47059)

It was discovered that the Libraries component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-47027)

It was discovered that the Security component of OpenJDK 25 did not correctly
authenticate users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-60147)

It was discovered that the Libraries component of OpenJDK 25 did not correctly
authenticate users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-47063)

Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not
correctly handle certain integer arithmetic. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-41254)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8681-1</guid><pubDate>Wed, 26 Aug 2026 01:40:39 +0000</pubDate></item><item><title>USN-8659-4: Linux kernel (Oracle) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8659-4</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8659-4</guid><pubDate>Wed, 26 Aug 2026 00:14:56 +0000</pubDate></item><item><title>USN-8666-2: Linux kernel (Azure) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8666-2</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - Ext4 file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8666-2</guid><pubDate>Tue, 25 Aug 2026 21:15:06 +0000</pubDate></item><item><title>USN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8630-5</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Mellanox network drivers;
  - File systems infrastructure;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8630-5</guid><pubDate>Tue, 25 Aug 2026 21:12:04 +0000</pubDate></item><item><title>USN-8658-3: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8658-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8658-3</guid><pubDate>Tue, 25 Aug 2026 20:27:36 +0000</pubDate></item><item><title>USN-8643-4: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8643-4</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network drivers;
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8643-4</guid><pubDate>Tue, 25 Aug 2026 20:21:07 +0000</pubDate></item><item><title>USN-8659-3: Linux kernel (Azure) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8659-3</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8659-3</guid><pubDate>Tue, 25 Aug 2026 20:14:19 +0000</pubDate></item><item><title>USN-8680-1: FFmpeg vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8680-1</link><description>Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
data. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)

Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-70632)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8680-1</guid><pubDate>Tue, 25 Aug 2026 20:01:39 +0000</pubDate></item></channel></rss>