<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 19 Aug 2026 15:10:21 +0000</lastBuildDate><item><title>USN-8649-1: libheif vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8649-1</link><description>It was discovered that libheif had an integer underflow in the Fraction
constructor when a clap transform was applied twice. An attacker could
possibly use this issue to cause libheif to crash, resulting in a denial of
service. (CVE-2026-62289)

It was discovered that libheif had an out-of-bounds read in uncompressed
tile range slicing. An attacker could possibly use this issue to cause
libheif to crash, resulting in a denial of service. This issue only
affected Ubuntu 25.10. (CVE-2026-62292)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8649-1</guid><pubDate>Wed, 19 Aug 2026 12:39:30 +0000</pubDate></item><item><title>USN-8563-3: nginx vulnerability</title><link>https://ubuntu.com/security/notices/USN-8563-3</link><description>USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was
backed out in USN-8563-2 because it could cause a regression. This update
includes a better fix for CVE-2026-42533.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that nginx incorrectly handled certain map directives
 using regex matching and capture variables. A remote attacker could use
 this issue to cause nginx to crash, resulting in a denial of service, or
 possibly execute arbitrary code. (CVE-2026-42533)

 It was discovered that nginx had a use-after-free vulnerability in the
 ngx_http_ssi_module module when configured with Server-Side Includes,
 proxy_pass, and proxy buffering disabled directives. An attacker able to
 intercept traffic and control responses from an upstream server could
 possibly use this issue to cause nginx to crash, resulting in a denial of
 service. (CVE-2026-56434)

 It was discovered that nginx incorrectly handled certain requests in the
 ngx_http_slice_module module. A remote attacker could possibly use this
 issue to obtain sensitive information or cause nginx to crash, resulting
 in a denial of service. (CVE-2026-60005)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8563-3</guid><pubDate>Wed, 19 Aug 2026 12:01:08 +0000</pubDate></item><item><title>USN-8648-1: Bind vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8648-1</link><description>It was discovered that Bind incorrectly accepted NSEC3 records whose signer
name did not match the owning zone. A remote attacker could possibly use
this issue to perform NSEC3 impersonation attacks, bypassing DNSSEC
validation. (CVE-2026-10723)

It was discovered that Bind incorrectly handled Key Records using the
PRIVATEDNS algorithm. A remote attacker could possibly use this issue to
cause Bind to crash, resulting in a denial of service. (CVE-2026-10822)

It was discovered that Bind incorrectly handled wildcard CNAME expansion in
Response Policy Zones. A remote attacker could possibly use this issue to
bypass configured RPZ policies. (CVE-2026-11331)

It was discovered that Bind performed unnecessary validation of DNSSEC
signed records. A remote attacker could possibly use this issue to cause
Bind to use excessive resources, leading to a denial of service. This issue
only affected Ubuntu 26.04 LTS. (CVE-2026-11605)

It was discovered that Bind incorrectly tracked memory usage in the DNS
cache. A remote attacker could possibly use this issue to cause Bind to use
memory beyond configured limits, leading to a denial of service.
(CVE-2026-11622)

It was discovered that Bind incorrectly handled signed wildcard records
with label count discrepancies and RRSIG validation. A remote attacker
could possibly use this issue to perform cache poisoning attacks.
(CVE-2026-11721)

It was discovered that Bind incorrectly handled certain CNAME and DNAME
record orderings in the resolver. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service.
(CVE-2026-12617)

It was discovered that Bind incorrectly validated out-of-zone NSEC next
owner names during DNSSEC validation. A remote attacker could possibly use
this issue to bypass DNSSEC validation. (CVE-2026-13321)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8648-1</guid><pubDate>Wed, 19 Aug 2026 11:45:39 +0000</pubDate></item><item><title>USN-8093-2: libssh vulnerability</title><link>https://ubuntu.com/security/notices/USN-8093-2</link><description>USN-8093-1 fixed a vulnerability in libssh. This update provides
the corresponsing fix for Ubuntu 26.04 LTS.

Original advisory details:

 It was discovered that libssh incorrectly performed bounds checking when
 processing SFTP extensions. If a client application queried extension data out
 of bounds, it could cause the application to crash, resulting in a denial of
 service, or exhibit unintended behavior.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8093-2</guid><pubDate>Wed, 19 Aug 2026 08:15:33 +0000</pubDate></item><item><title>USN-8113-2: LibTIFF vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8113-2</link><description>USN 8113-1 fixed vulnerabilities in tiff. This update
provides the corresponding fixes for Ubuntu 26.04 LTS.

Original advisory details:

 It was discovered that LibTIFF did not properly handle memory when
 processing certain images. An attacker could possibly use this issue to
 cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61143)

 It was discovered that LibTIFF did not properly handle memory when
 processing malformed TIFF directories. An attacker could possibly use this
 issue to cause LibTIFF to crash, resulting in a denial of service.
 (CVE-2025-61144)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8113-2</guid><pubDate>Wed, 19 Aug 2026 07:39:43 +0000</pubDate></item><item><title>USN-8630-3: Linux kernel (Oracle) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8630-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Mellanox network drivers;
  - File systems infrastructure;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8630-3</guid><pubDate>Tue, 18 Aug 2026 21:00:12 +0000</pubDate></item><item><title>USN-8636-2: Linux kernel (Oracle) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8636-2</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Media drivers;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - SMB network file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - Memory management;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-31405, CVE-2026-31414, CVE-2026-31501, CVE-2026-31589,
CVE-2026-31633, CVE-2026-31636, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43379, CVE-2026-43465, CVE-2026-43499, CVE-2026-46113,
CVE-2026-46137, CVE-2026-46242, CVE-2026-46331, CVE-2026-52924,
CVE-2026-52989, CVE-2026-53086, CVE-2026-53131, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8636-2</guid><pubDate>Tue, 18 Aug 2026 20:53:11 +0000</pubDate></item><item><title>USN-8629-3: Linux kernel (HWE) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8629-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Network traffic control;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
(CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53151,
CVE-2026-53175, CVE-2026-53176, CVE-2026-53186, CVE-2026-53212,
CVE-2026-53215, CVE-2026-53216, CVE-2026-53221, CVE-2026-53224,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53247,
CVE-2026-53260, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8629-3</guid><pubDate>Tue, 18 Aug 2026 20:49:14 +0000</pubDate></item><item><title>USN-8646-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8646-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - OCFS2 file system;
  - B.A.T.M.A.N. meshing protocol;
  - Netfilter;
  - SCTP protocol;
(CVE-2026-52914, CVE-2026-53002, CVE-2026-53043, CVE-2026-53224,
CVE-2026-53246, CVE-2026-53309)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8646-1</guid><pubDate>Tue, 18 Aug 2026 18:26:29 +0000</pubDate></item><item><title>USN-8645-1: Linux kernel (Oracle) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8645-1</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - GPU drivers;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - STMicroelectronics network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - Ext4 file system;
  - OCFS2 file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
(CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405,
CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657,
CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493,
CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982,
CVE-2026-52986, CVE-2026-52993, CVE-2026-53002, CVE-2026-53006,
CVE-2026-53043, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246,
CVE-2026-53309, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8645-1</guid><pubDate>Tue, 18 Aug 2026 18:23:33 +0000</pubDate></item></channel></rss>