<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Tue, 29 Sep 2026 02:00:09 +0000</lastBuildDate><item><title>USN-8487-2: curl regression</title><link>https://ubuntu.com/security/notices/USN-8487-2</link><description>USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update
contained an incomplete fix for CVE-2026-8927. This update fixes the
problem.

Original advisory details:

 Andrew Nesbitt discovered that curl could reuse an existing live
 connection during STARTTLS-based connection upgrades even when the TLS
 configuration did not match. A remote attacker could possibly use this
 issue to cause curl to use an unintended TLS configuration.
 (CVE-2026-8286)

 Muhamad Arga Reksapati discovered that curl incorrectly reused connections
 for Negotiate-authenticated requests when different services were
 involved. A remote attacker could possibly use this issue to access
 resources authenticated for another service. This issue only affected
 Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
 Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)

 It was discovered that curl incorrectly handled cookie parsing in certain
 circumstances. A remote attacker could possibly use this issue to set
 cookies that would be transmitted to unrelated third-party domains. This
 issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
 Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.
 (CVE-2026-8924)

 Joshua Rogers discovered that curl could double-free a GSASL context when
 handling SASL authentication. A remote attacker could possibly use this
 issue to cause a denial of service, or execute arbitrary code. This issue
 only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu
 26.04 LTS. (CVE-2026-8925)

 Joshua Rogers discovered that curl could select the wrong password from a
 .netrc file when a username was specified in the URL without a password. A
 remote attacker could possibly use this issue to obtain sensitive
 information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
 (CVE-2026-8926)

 Ady Elouej discovered that curl did not clear proxy authentication state
 between requests when reusing a handle with environment-variable proxy
 configuration. A remote attacker could possibly use this issue to obtain
 sensitive credentials. (CVE-2026-8927)

 Guannan Wang, Zhanpeng Liu, Jiashuo Liang, and Guancheng Li discovered
 that curl did not properly clear proxy authentication credentials when
 instructed to do so. A remote attacker could possibly use this issue to
 obtain sensitive credentials. This issue only affected Ubuntu 25.10 and
 Ubuntu 26.04 LTS. (CVE-2026-9079)

 Joshua Rogers discovered that curl contained a use-after-free when
 curl_easy_pause() was called within the event-based socket callback. A
 remote attacker could possibly use this issue to cause a denial of service
 or possibly execute arbitrary code. This issue only affected Ubuntu 25.10
 and Ubuntu 26.04 LTS. (CVE-2026-9080)

 Eunsoo Kim discovered that curl could send early data on a resumed TLS
 session before enforcing certificate verification failure. A  machine-in-
 the-middle attacker could possibly use this issue to obtain  sensitive
 information. This issue only affected Ubuntu 25.10 and Ubuntu  26.04 LTS.
 (CVE-2026-9545)

 Joshua Rogers discovered that curl did not properly reject host key type
 mismatches when using the SSH key callback for SCP and SFTP transfers. A
 machine-in-the-middle attacker could possibly use this issue to
 impersonate a trusted server. This issue only affected Ubuntu 22.04 LTS,
 Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-9547)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8487-2</guid><pubDate>Mon, 28 Sep 2026 20:29:10 +0000</pubDate></item><item><title>USN-8839-1: Atril vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8839-1</link><description>It was discovered that Atril did not properly sanitize command-line
arguments in PDF /GoToR actions. If a user opened a specially crafted PDF
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-46529)

It was discovered that Atril incorrectly handled certain PDF files. An
attacker could possibly use this issue to cause a denial of service or
to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)

Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8839-1</guid><pubDate>Mon, 28 Sep 2026 15:12:25 +0000</pubDate></item><item><title>USN-8838-1: catdoc vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8838-1</link><description>It was discovered that catdoc had an integer overflow when processing
shared string tables in malformed spreadsheet files. An attacker could
possibly use this issue to cause catdoc to crash or execute arbitrary code.
(CVE-2024-48877)

It was discovered that catdoc had an integer overflow when processing file
allocation tables in malformed document files. An attacker could possibly
use this issue to cause catdoc to crash or execute arbitrary code.
(CVE-2024-52035)

It was discovered that catdoc incorrectly validated sector sizes when
processing malformed document files, leading to an integer underflow. An
attacker could possibly use this issue to cause catdoc to crash or execute
arbitrary code. (CVE-2024-54028)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8838-1</guid><pubDate>Mon, 28 Sep 2026 15:01:41 +0000</pubDate></item><item><title>USN-8837-1: pdfminer vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8837-1</link><description>It was discovered that pdfminer did not safely parse specially crafted
PDF files. An attacker could possibly use these issues to execute
arbitrary code. (CVE-2025-64512, CVE-2025-70559)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8837-1</guid><pubDate>Mon, 28 Sep 2026 14:43:34 +0000</pubDate></item><item><title>USN-8835-1: Emacs vulnerability</title><link>https://ubuntu.com/security/notices/USN-8835-1</link><description>It was discovered that Emacs improperly handled specially crafted SVG
images, resulting in memory corruption. An attacker could possibly use
this issue to cause Emacs to crash, resulting in a denial of service, or
obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8835-1</guid><pubDate>Mon, 28 Sep 2026 14:33:51 +0000</pubDate></item><item><title>USN-8832-1: Booth vulnerability</title><link>https://ubuntu.com/security/notices/USN-8832-1</link><description>It was discovered that Booth did not properly validate message
authentication codes under certain circumstances. A remote attacker
could possibly use this issue to bypass authentication.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8832-1</guid><pubDate>Mon, 28 Sep 2026 14:20:51 +0000</pubDate></item><item><title>USN-8830-1: phpseclib vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8830-1</link><description>It was discovered that phpseclib did not perform constant-time padding
validation when using AES in CBC mode. A remote attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-32935)

It was discovered that phpseclib did not use a constant-time comparison
when validating SSH packet authentication codes. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2026-40194)

It was discovered that phpseclib did not properly limit object identifier
lengths when parsing ASN.1 data. An attacker could possibly use this issue
to cause phpseclib to use excessive resources, leading to a denial of
service. (CVE-2026-44167)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8830-1</guid><pubDate>Mon, 28 Sep 2026 13:56:03 +0000</pubDate></item><item><title>USN-8829-1: Plasma Workspace vulnerability</title><link>https://ubuntu.com/security/notices/USN-8829-1</link><description>Fabian Vogt discovered that Plasma Workspace did not properly authenticate
local clients connecting to the session manager. A local attacker could
possibly use this issue to execute arbitrary code as another user.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8829-1</guid><pubDate>Mon, 28 Sep 2026 13:42:58 +0000</pubDate></item><item><title>USN-8828-1: dracut vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8828-1</link><description>It was discovered that dracut created initramfs images with overly
permissive permissions under certain circumstances. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-8637)

It was discovered that dracut did not properly sanitize DHCP options
before writing them to shell scripts under certain circumstances. A remote
attacker controlling a DHCP server on the local network could possibly use
this issue to execute arbitrary code as root during system boot. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)

It was discovered that dracut did not properly quote error messages written
to shell scripts under certain circumstances. A remote attacker controlling
a DHCP server on the local network could possibly use this issue to execute
arbitrary code as root during system boot. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2026-15816)

It was discovered that dracut did not properly sanitize network
configuration data before writing it to a temporary shell script under
certain circumstances. A remote attacker controlling DHCP on the local
network could possibly use this issue to execute arbitrary code as root
during system boot. This issue only affected Ubuntu 22.04 LTS.
(CVE-2026-16445)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8828-1</guid><pubDate>Mon, 28 Sep 2026 13:33:37 +0000</pubDate></item><item><title>USN-8827-1: Erlang vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8827-1</link><description>It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)

It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)

It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)

It was discovered that Erlang incorrectly handled certain packet lengths,
leading to a buffer overflow. A remote attacker could possibly use this
issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538)

It was discovered that the Erlang Megaco flex scanner incorrectly handled
certain input, leading to a buffer overflow. A remote attacker could
possibly use this issue to cause Erlang to crash or execute arbitrary code.
(CVE-2026-59250)

It was discovered that Erlang TLS clients incorrectly accepted cipher
suites that they had not offered. A remote attacker could possibly use
this issue to intercept and modify TLS communications. (CVE-2026-55953)

It was discovered that Erlang incorrectly handled certain certificate
chains. A remote attacker could possibly use this issue to cause Erlang to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58227)

It was discovered that Erlang incorrectly handled certain certificate
policies. A remote attacker could possibly use this issue to cause Erlang
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-59251)

It was discovered that the Erlang HTTP server incorrectly handled certain
conflicting HTTP framing headers. A remote attacker could possibly use this
issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812)

It was discovered that the Erlang HTTP server incorrectly handled certain
malformed chunk sizes. A remote attacker could possibly use this issue to
cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664)

It was discovered that the Erlang HTTP server did not properly limit the
size of chunked request bodies. A remote attacker could possibly use this
issue to cause Erlang to use excessive resources, leading to a denial of
service. (CVE-2026-74835)

It was discovered that the Erlang HTTP server incorrectly handled certain
equivalent request paths and differences in character case. A remote
attacker could possibly use this issue to bypass authentication and gain
unauthorized access. (CVE-2026-66835, CVE-2026-73270)

It was discovered that the Erlang HTTP server did not properly limit
simultaneous connections. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-70399)

It was discovered that the Erlang HTTP server incorrectly handled header
continuation lines. A remote attacker could possibly use this issue to
smuggle HTTP requests. (CVE-2026-66357)

It was discovered that the Erlang HTTP server incorrectly handled certain
malformed header names. A remote attacker could possibly use this issue to
smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-73276)

It was discovered that the Erlang HTTP server incorrectly handled
incomplete request bodies. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
(CVE-2026-71380)

It was discovered that the Erlang HTTP client did not properly limit the
size of HTTP response headers. A malicious HTTP server could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-55951)

It was discovered that Erlang did not properly limit the length of port
numbers when parsing URIs. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696)

It was discovered that the Erlang SNMP application did not properly limit
the size of certain integer values. A remote attacker could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-70405)

It was discovered that the Erlang LDAP client did not properly limit the
length of port numbers in referral URLs. A malicious LDAP server could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. (CVE-2026-70409)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8827-1</guid><pubDate>Mon, 28 Sep 2026 13:21:58 +0000</pubDate></item></channel></rss>