<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Mon, 15 Jun 2026 18:50:19 +0000</lastBuildDate><item><title>USN-8431-1: Ruby vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8431-1</link><description>It was discovered that Ruby's Net::IMAP library did not properly verify
that Transport Layer Security (TLS) encryption was started after issuing a STARTTLS command. A remote
attacker could possibly use this issue to perform a machine-in-the-middle attack and silently
bypass TLS encryption. (CVE-2026-42246)

It was also discovered that Ruby's Net::IMAP library did not validate
string arguments passed to certain commands. A remote attacker could possibly use this issue to
inject arbitrary IMAP commands. (CVE-2026-42257)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8431-1</guid><pubDate>Mon, 15 Jun 2026 17:24:17 +0000</pubDate></item><item><title>USN-8428-1: tmux vulnerability</title><link>https://ubuntu.com/security/notices/USN-8428-1</link><description>It was discovered that tmux incorrectly handled image cleanup, leading to
a use-after-free vulnerability. A local attacker could possibly use this
issue to cause tmux to crash, resulting in a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8428-1</guid><pubDate>Mon, 15 Jun 2026 13:03:51 +0000</pubDate></item><item><title>USN-8398-3: nginx vulnerability</title><link>https://ubuntu.com/security/notices/USN-8398-3</link><description>USN-8398-1 fixed a vulnerability in nginx. The update caused a regression
and was temporarily reverted in USN-8398-2. This update introduces a
complete fix for CVE-2026-49975.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that nginx incorrectly handled certain cookie headers in
 the HTTP/2 implementation. A remote attacker could possibly use this issue
 to cause nginx to consume excessive resources, resulting in a denial of
 service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8398-3</guid><pubDate>Mon, 15 Jun 2026 12:44:22 +0000</pubDate></item><item><title>USN-8405-2: CUPS regression</title><link>https://ubuntu.com/security/notices/USN-8405-2</link><description>USN-8405-1 fixed vulnerabilities in CUPS. The update introduced a
regression that cause CUPS to crash when parsing certain large printer PPD
files. This update fixes the problem.

Original advisory details:

 Ariel Silver discovered that CUPS incorrectly handled username comparisons
 during authorization checks. A local attacker could possibly use this issue
 to gain unauthorized access to restricted operations. (CVE-2026-27447)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 notify-recipient-uri values in the RSS notifier. A remote attacker could
 possibly use this issue to overwrite lp-writable files and cause a denial
 of service. (CVE-2026-34978)

 Jacob Newman discovered that CUPS incorrectly handled filter option strings
 when processing job attributes. An attacker could use this issue to cause
 CUPS to crash, resulting in a denial of service, or possibly execute
 arbitrary code. (CVE-2026-34979)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 page-border values in shared PostScript queues. A remote attacker could
 possibly use this issue to execute arbitrary code. (CVE-2026-34980)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 localhost authentication to attacker-controlled IPP services. A local
 attacker could possibly use this issue to overwrite arbitrary files
 and execute arbitrary code. (CVE-2026-34990)

 Tomer Fichman discovered that CUPS incorrectly handled negative
 job-password-supported values. A local attacker could possibly use this
 issue to cause CUPS to crash, resulting in a denial of service.
 (CVE-2026-39314)

 Tomer Fichman discovered that CUPS incorrectly handled temporary printer
 deletion. An attacker could possibly use this issue to cause CUPS to crash,
 resulting in a denial of service, or to execute arbitrary code.
 (CVE-2026-39316)

 Tomer Fichman discovered that CUPS incorrectly handled certain malformed
 SNMP responses. An attacker could possibly use this issue to obtain
 sensitive information. (CVE-2026-41079)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8405-2</guid><pubDate>Mon, 15 Jun 2026 12:12:13 +0000</pubDate></item><item><title>USN-8427-1: Mesa vulnerability</title><link>https://ubuntu.com/security/notices/USN-8427-1</link><description>It was discovered that Mesa did not properly validate memory allocation
sizes in WebGPU under certain circumstances. An attacker could use this
issue to cause Mesa to crash, resulting in a denial of service, or possibly
execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8427-1</guid><pubDate>Mon, 15 Jun 2026 12:01:35 +0000</pubDate></item><item><title>USN-8426-1: Linux kernel (Azure) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8426-1</link><description>It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)

It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500)

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503,
CVE-2026-46300)

Qualys discovered that a race condition existed in the ptrace subsystem of
the Linux kernel when privileged processes are exiting. An unprivileged
local attacker could use this issue to expose sensitive information.
(CVE-2026-46333)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - Ethernet bonding driver;
  - SMB network file system;
  - Netfilter;
  - io_uring subsystem;
  - Packet sockets;
  - RDS protocol;
  - TLS protocol;
(CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351,
CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033,
CVE-2026-43077, CVE-2026-43078, CVE-2026-43494, CVE-2026-46028)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8426-1</guid><pubDate>Thu, 11 Jun 2026 21:57:52 +0000</pubDate></item><item><title>USN-8423-1: lwIP vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8423-1</link><description>It was discovered that lwIP contained a buffer overflow in the EAP
authentication handling code. An attacker could possibly use this issue
to trigger a buffer overflow, resulting in arbitrary code execution or a
denial of service. This issue only affected Ubuntu 20.04 LTS.
(CVE-2020-8597)

It was discovered that lwIP incorrectly handled certain ICMPv6 or
6LoWPAN packets. An attacker could possibly use this issue to trigger a
buffer overflow, resulting in information disclosure. This issue only
affected Ubuntu 20.04 LTS. (CVE-2020-22283, CVE-2020-22284)

It was discovered that lwIP did not properly validate certain SNMPv3
authentication parameters. An attacker could possibly use this issue to
trigger a stack-based buffer overflow, resulting in arbitrary code
execution or a denial of service. (CVE-2026-8836)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8423-1</guid><pubDate>Thu, 11 Jun 2026 18:54:54 +0000</pubDate></item><item><title>USN-8424-1: Ubuntu Kylin Software Center vulnerability</title><link>https://ubuntu.com/security/notices/USN-8424-1</link><description>It was discovered that Ubuntu Kylin Software Center incorrectly
handled user-supplied input in its D-Bus service. A local attacker
could possibly use this issue to gain administrative privileges.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8424-1</guid><pubDate>Thu, 11 Jun 2026 15:20:07 +0000</pubDate></item><item><title>USN-8422-1: Mistral vulnerability</title><link>https://ubuntu.com/security/notices/USN-8422-1</link><description>Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that Mistral
did not properly enforce access policies on some API endpoints. An
attacker could possibly execute arbitrary code on a Mistral worker and
possibly extract sensitive data including service credentials from it.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8422-1</guid><pubDate>Thu, 11 Jun 2026 12:55:21 +0000</pubDate></item><item><title>USN-8421-1: Ironic vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8421-1</link><description>Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate file paths when handling ISO images. A privileged
authenticated remote user could use this issue to perform path
traversal via a crafted ISO image and overwrite arbitrary files on
the Ironic conductor. (CVE-2026-48681)

Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate kernel command line parameters. A privileged
authenticated remote user could use this issue to inject
scripts during node boot and possibly execute arbitrary code.
(CVE-2026-46447)

Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic
incorrectly restricted access to custom PXE templates. A privileged
authenticated remote user could use this issue to read arbitrary
sensitive files on the Ironic conductor. (CVE-2026-44917)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8421-1</guid><pubDate>Thu, 11 Jun 2026 12:22:01 +0000</pubDate></item></channel></rss>