<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Tue, 01 Sep 2026 11:01:57 +0000</lastBuildDate><item><title>USN-8690-1: Pillow vulnerability</title><link>https://ubuntu.com/security/notices/USN-8690-1</link><description>It was discovered that Pillow did not properly manage memory when
processing certain image files. An attacker could possibly use this  issue
to cause a denial of service or read sensitive data.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8690-1</guid><pubDate>Tue, 01 Sep 2026 06:27:48 +0000</pubDate></item><item><title>USN-8705-2: OpenZFS vulnerability</title><link>https://ubuntu.com/security/notices/USN-8705-2</link><description>USN-8705-1 fixed vulnerabilities in OpenZFS. This update provides the
corresponding fix for OpenZFS on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that OpenZFS incorrectly handled authorization checks for
certain ioctl operations on Linux. A local attacker could possibly use this
issue to perform pool-administrative operations or access privileged
information, resulting in an authorization bypass.
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8705-2</guid><pubDate>Mon, 31 Aug 2026 21:36:58 +0000</pubDate></item><item><title>USN-8706-1: zlib vulnerability</title><link>https://ubuntu.com/security/notices/USN-8706-1</link><description>It was discovered that zlib incorrectly handled negative length parameters
in CRC32 combine functions. An attacker could use this issue to cause a denial
of service via excessive CPU consumption.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8706-1</guid><pubDate>Mon, 31 Aug 2026 17:30:43 +0000</pubDate></item><item><title>USN-8704-1: GNU cpio vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8704-1</link><description>It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)

It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485)

It was discovered that cpio did not properly escape archive member names
when listing archive contents. If a user or automated system were tricked
into listing a specially crafted archive, an attacker could possibly use
this issue to inject misleading output or malicious terminal control
sequences. (CVE-2026-66486)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8704-1</guid><pubDate>Mon, 31 Aug 2026 13:12:09 +0000</pubDate></item><item><title>USN-8705-1: OpenZFS vulnerability</title><link>https://ubuntu.com/security/notices/USN-8705-1</link><description>It was discovered that OpenZFS incorrectly handled authorization checks for
certain ioctl operations on Linux. A local attacker could possibly use this
issue to perform pool-administrative operations or access privileged
information, resulting in an authorization bypass.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8705-1</guid><pubDate>Mon, 31 Aug 2026 12:57:46 +0000</pubDate></item><item><title>USN-8703-1: WebKitGTK vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8703-1</link><description>Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8703-1</guid><pubDate>Mon, 31 Aug 2026 12:46:51 +0000</pubDate></item><item><title>USN-8702-1: util-linux vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8702-1</link><description>It was discovered that libblkid in util-linux had a heap use-after-free
vulnerability during nested partition probing. An attacker who could
present a crafted block device image could possibly use this issue to
obtain sensitive information or cause a denial of service. (CVE-2026-13595)

It was discovered that the mount utility in util-linux had a time-of-check-
time-of-use vulnerability when setting up loop devices. A local attacker
could possibly use this issue to obtain unauthorized read access to root-
protected files and block devices. (CVE-2026-27456)

It was discovered that the login utility in util-linux improperly
canonicalized hostnames when invoked with the -h option. A remote attacker
could possibly use this issue to bypass host-based access control rules.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-3184)

It was discovered that libmount in util-linux had a time-of-check-time-of-
use vulnerability in its ownership hook. A local attacker could possibly
use this issue to gain elevated privileges. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53612)

It was discovered that libmount in util-linux had a time-of-check-time-of-
use vulnerability that allowed target path redirection during mount
operations. A local attacker could possibly use this issue to gain elevated
privileges. (CVE-2026-53613)

It was discovered that libmount in util-linux improperly handled the
LIBMOUNT_FORCE_MOUNT2 environment variable in the SUID mount utility. A
local attacker could possibly use this issue to bypass nosuid and noexec
mount options and gain elevated privileges. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53614)

It was discovered that libblkid in util-linux had an integer overflow
vulnerability when parsing DOS partition tables. An attacker who could
present a crafted block device image could possibly use this issue to cause
a denial of service. (CVE-2026-53615)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8702-1</guid><pubDate>Mon, 31 Aug 2026 12:39:05 +0000</pubDate></item><item><title>USN-8701-1: UDisks vulnerability</title><link>https://ubuntu.com/security/notices/USN-8701-1</link><description>It was discovered that UDisks did not correctly validate the caller
identity when handling the as-user option in the
org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. A local attacker
with an active console session could possibly use this issue to mount
filesystems on behalf of arbitrary users, including privileged accounts,
leading to local privilege escalation.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8701-1</guid><pubDate>Mon, 31 Aug 2026 12:24:24 +0000</pubDate></item><item><title>USN-8678-3: OpenSSL vulnerability</title><link>https://ubuntu.com/security/notices/USN-8678-3</link><description>USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left
out the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the
problem.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that OpenSSL incorrectly handled the QUIC server incoming
 channel queue. A remote attacker could possibly use this issue to cause
 OpenSSL to use excessive resources, leading to a denial of service. This
 issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)

 It was discovered that OpenSSL incorrectly handled signature algorithm
 selection when using Raw Public Keys. A remote attacker could possibly use
 this issue to cause OpenSSL to crash, resulting in a denial of service.
 This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)

 It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
 processing. A remote attacker could possibly use this issue to cause
 OpenSSL to crash, resulting in a denial of service. This issue only
 affected Ubuntu 26.04 LTS. (CVE-2026-18798)

 It was discovered that OpenSSL incorrectly handled buffering of DTLS
 records for a future epoch. A remote attacker could possibly use this issue
 to cause OpenSSL to use excessive resources, leading to a denial of
 service. (CVE-2026-54874)

 It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
 remote attacker could possibly use this issue to cause a heap buffer
 overflow, leading to a denial of service or arbitrary code execution.
 (CVE-2026-63072)

 It was discovered that OpenSSL incorrectly validated the sender
 distinguished name in CMP response messages. A remote attacker could
 possibly use this issue to cause OpenSSL to crash, resulting in a denial of
 service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)

 It was discovered that OpenSSL incorrectly limited the growth of an
 internal certificate cache used during CMP operations. A remote attacker
 could possibly use this issue to cause OpenSSL to use excessive resources,
 leading to a denial of service. (CVE-2026-63074)

 It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
 retention. A remote attacker could possibly use this issue to cause OpenSSL
 to use excessive resources, leading to a denial of service. This issue only
 affected Ubuntu 26.04 LTS. (CVE-2026-63075)

 It was discovered that OpenSSL incorrectly handled CMP protection algorithm
 validation. A remote attacker could possibly use this issue to cause
 OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)

 It was discovered that OpenSSL incorrectly verified authentication tags
 when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
 could possibly use this issue to perform AEAD forgery attacks.
 (CVE-2026-75803)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8678-3</guid><pubDate>Mon, 31 Aug 2026 12:18:40 +0000</pubDate></item><item><title>USN-8700-1: MySQL vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8700-1</link><description>Multiple security issues were discovered in MySQL.

MySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS. Ubuntu 22.04 LTS and
Ubuntu 24.04 LTS packages have been updated with backported patches.

In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:

https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-11.html
https://www.oracle.com/security-alerts/cpujul2026.html</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8700-1</guid><pubDate>Mon, 31 Aug 2026 12:09:27 +0000</pubDate></item></channel></rss>