<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 30 Sep 2026 22:30:02 +0000</lastBuildDate><item><title>USN-8858-1: Authen::SASL vulnerability</title><link>https://ubuntu.com/security/notices/USN-8858-1</link><description>It was discovered that Authen::SASL, a Perl authentication library, did
not properly validate login attempts. An attacker could possibly use
this issue to gain unauthorized access.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8858-1</guid><pubDate>Wed, 30 Sep 2026 16:40:43 +0000</pubDate></item><item><title>USN-8859-1: ImageMagick vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8859-1</link><description>It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service or
obtain sensitive information. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-56367)

It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2026-93586)

It was discovered that ImageMagick did not correctly handle certain images.
A local attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93587, CVE-2026-93588)

It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93589)

It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-93590)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8859-1</guid><pubDate>Wed, 30 Sep 2026 16:39:48 +0000</pubDate></item><item><title>USN-8856-1: Kdenlive, MLT vulnerability</title><link>https://ubuntu.com/security/notices/USN-8856-1</link><description>It was discovered that Kdenlive allowed dangerous proxy parameters when
processing attacker-controlled project files. An attacker could use this to
execute arbitrary commands via the MLT framework's ante/post consumer
properties.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8856-1</guid><pubDate>Wed, 30 Sep 2026 15:59:30 +0000</pubDate></item><item><title>USN-8845-1: GVfs vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8845-1</link><description>Keith Linneman discovered that GVfs did not properly validate data
received from SFTP servers. An attacker could possibly use this issue to
cause a heap buffer overflow, resulting in arbitrary code execution or a
denial of service. (CVE-2026-84268)

It was discovered that GVfs incorrectly handled file ownership when
creating private D-Bus sockets in the admin backend. A local attacker
could possibly use this issue to change the ownership of arbitrary
system files, resulting in privilege escalation to root. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88924)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8845-1</guid><pubDate>Wed, 30 Sep 2026 15:54:56 +0000</pubDate></item><item><title>USN-8816-3: Linux kernel (Oracle) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8816-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - DRBD Distributed Replicated Block Device drivers;
  - InfiniBand drivers;
  - IOMMU subsystem;
  - Multiple devices driver;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NVME drivers;
  - TCM subsystem;
  - Virtio Host (VHOST) subsystem;
  - Xen hypervisor drivers;
  - AFS file system;
  - File systems infrastructure;
  - Network file systems library;
  - Network file system (NFS) client;
  - NTFS3 file system;
  - OCFS2 file system;
  - OrangeFS file system;
  - SMB network file system;
  - IPv4 networking;
  - Sun RPC protocol;
  - IPv6 networking;
  - IP tunnels definitions;
  - Netfilter;
  - TCP network protocol;
  - Locking primitives;
  - 9P file system network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - Networking core;
  - IFE protocol;
  - RxRPC session sockets;
  - Network traffic control;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
  - XFRM subsystem;
(CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541,
CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476,
CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033,
CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065,
CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085,
CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137,
CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194,
CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222,
CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249,
CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279,
CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296,
CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319,
CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329,
CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355,
CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398,
CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422,
CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451,
CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473,
CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494,
CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255,
CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287,
CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361,
CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398,
CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428,
CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439,
CVE-2026-80665)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8816-3</guid><pubDate>Wed, 30 Sep 2026 14:04:57 +0000</pubDate></item><item><title>USN-8817-3: Linux kernel (AWS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8817-3</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - HSR network protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8817-3</guid><pubDate>Wed, 30 Sep 2026 14:04:57 +0000</pubDate></item><item><title>USN-8818-5: Linux kernel (NVIDIA Tegra) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8818-5</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8818-5</guid><pubDate>Wed, 30 Sep 2026 14:04:56 +0000</pubDate></item><item><title>USN-8854-1: OpenStack Keystone vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8854-1</link><description>Grzegorz Grasza discovered that OpenStack Keystone did not consistently
enforce restrictions for delegated authentication tokens. An authenticated
attacker could possibly use this issue to create credentials or delegations
 that outlasted the delegated token. (CVE-2026-80182)

It was discovered that OpenStack Keystone incorrectly handled role
assignment queries under certain circumstances. An authenticated attacker
could possibly use this issue to obtain sensitive information. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-80183)

Tim Shephard discovered that OpenStack Keystone did not properly
restrict reauthentication using delegated tokens. An authenticated
attacker could possibly use this issue to escape their intended
project scope and obtain unauthorized access. (CVE-2026-80184)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8854-1</guid><pubDate>Wed, 30 Sep 2026 13:07:45 +0000</pubDate></item><item><title>USN-8853-1: OpenSBI vulnerability</title><link>https://ubuntu.com/security/notices/USN-8853-1</link><description>It was discovered that OpenSBI did not properly validate the counter index
mask in SBI PMU extension requests. An attacker could use this issue to
cause a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8853-1</guid><pubDate>Wed, 30 Sep 2026 13:02:21 +0000</pubDate></item><item><title>USN-8852-1: OpenVPN vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8852-1</link><description>It was discovered that OpenVPN had a use-after-free vulnerability in
its TLS session handling. An attacker could possibly use this issue
to cause OpenVPN to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2026-84471)

It was discovered that OpenVPN incorrectly handled retransmissions of
ACK packet IDs, which could trigger a timeout integer overflow. A
remote attacker could possibly use this issue to cause a denial of
service. (CVE-2026-84732)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8852-1</guid><pubDate>Wed, 30 Sep 2026 11:53:54 +0000</pubDate></item></channel></rss>