<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Thu, 18 Jun 2026 22:30:03 +0000</lastBuildDate><item><title>USN-8447-2: LXD vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8447-2</link><description>USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides
the corresponding updates for Go Cryptography code embedded in LXD for
CVE-2026-39830, CVE-2026-39833, CVE-2026-39834, and CVE-2026-42508.

Original advisory details:

 It was discovered that Go Cryptography did not properly handle SSH global
 request responses. A remote attacker could possibly use this issue to cause
 a denial of service. (CVE-2026-39830)

 It was discovered that Go Cryptography did not properly verify user
 presence when using FIDO/U2F security keys. An attacker could possibly use
 this issue to bypass user presence verification for hardware security keys.
 This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)

 It was discovered that Go Cryptography did not properly serialize SSH agent
 key constraint extensions. An attacker could possibly use this issue to
 bypass intended key usage restrictions. This issue only affected Ubuntu
 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
 (CVE-2026-39832)

 It was discovered that Go Cryptography did not properly enforce the
 confirm-before-use constraint in the SSH agent keyring. An attacker could
 possibly use this issue to use SSH keys without the required user
 confirmation. (CVE-2026-39833)

 It was discovered that Go Cryptography had an integer overflow when
 handling large SSH channel writes. A remote attacker could possibly use
 this issue to cause a denial of service. (CVE-2026-39834)

 It was discovered that Go Cryptography did not properly check certificate
 authority key revocation. An attacker could possibly use this issue to
 bypass certificate authority revocation checks. This issue only affected
 Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
 Ubuntu 26.04 LTS. (CVE-2026-42508)

 It was discovered that Go Cryptography did not properly enforce the source-
 address critical option for all SSH server callback types. An attacker
 could possibly use this issue to bypass source address authorization
 restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8447-2</guid><pubDate>Thu, 18 Jun 2026 20:05:09 +0000</pubDate></item><item><title>USN-8454-1: libheif vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8454-1</link><description>Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)

Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files, leading to an infinite loop. An attacker
could possibly use this issue to cause libheif to use excessive
resources, resulting in a denial of service. This issue only affected
Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)

Elhanan Haenel discovered that libheif incorrectly handled certain
crafted HEIF/AVIF image files. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32740)

It was discovered that libheif incorrectly handled certain crafted HEIF
files containing mask images. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.
(CVE-2026-32741)

It was discovered that libheif incorrectly handled certain crafted
grid-based HEIF/AVIF files. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.
(CVE-2026-32814)

It was discovered that libheif incorrectly handled certain crafted HEIF
files when compositing overlay images. An attacker could possibly use this
issue to cause a denial of service or obtain sensitive information.
(CVE-2026-32882)

It was discovered that libheif incorrectly handled certain crafted
files. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-3950)

It was discovered that libheif incorrectly handled certain malformed
HEIF sequence files. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04
LTS. (CVE-2026-41069)

It was discovered that libheif incorrectly handled certain crafted HEIF
sequence files. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(CVE-2026-41071)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8454-1</guid><pubDate>Thu, 18 Jun 2026 16:41:59 +0000</pubDate></item><item><title>USN-8452-1: pbkdf2 vulnerability</title><link>https://ubuntu.com/security/notices/USN-8452-1</link><description>Nikita Skovoroda discovered that pbkdf2 did not properly validate
certain algorithm names. An attacker could possibly use this issue to
generate predictable cryptographic keys, resulting in signature spoofing.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8452-1</guid><pubDate>Thu, 18 Jun 2026 16:30:44 +0000</pubDate></item><item><title>USN-8453-1: Net::CIDR::Lite vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8453-1</link><description>It was discovered that Net::CIDR::Lite incorrectly validated IP address and
CIDR mask inputs. An attacker could possibly use this issue to bypass IP
access control lists. (CVE-2026-45190)

It was discovered that Net::CIDR::Lite incorrectly handled extraneous zero
characters in CIDR mask values. An attacker could possibly use this issue
to bypass IP access control lists. (CVE-2026-45191)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8453-1</guid><pubDate>Thu, 18 Jun 2026 16:15:55 +0000</pubDate></item><item><title>USN-8451-1: Vim vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8451-1</link><description>Srinivas Piskala Ganesh Babu discovered that Vim incorrectly handled
directory names when serializing browsed paths to the netrw history file.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-47162)

It was discovered that Vim incorrectly handled step-definition patterns in
the cucumber filetype plugin. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-47167)

It was discovered that Vim incorrectly handled import statements during
Python omni-completion. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-52858)

Andrej Tomči discovered that Vim incorrectly handled certain terminal
screen cells when taking a snapshot, leading to an out-of-bounds read. An
attacker could possibly use this issue to cause Vim to crash, resulting in
a denial of service. (CVE-2026-52859)

David Carliez discovered that Vim incorrectly handled reconstructed
function and class definitions during Python omni-completion. An attacker
could possibly use this issue to execute arbitrary code. (CVE-2026-52860)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8451-1</guid><pubDate>Thu, 18 Jun 2026 16:05:59 +0000</pubDate></item><item><title>USN-8450-1: Tomcat vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8450-1</link><description>It was discovered that Tomcat did not properly limit the size of
WebDAV LOCK and PROPFIND request bodies. A remote attacker could
possibly use this issue to cause Tomcat to consume excessive memory,
resulting in a denial of service. (CVE-2026-41284)

It was discovered that Tomcat incorrectly validated HTTP/2 header
fields. A remote attacker could use this issue to cause Tomcat to
crash or possibly execute arbitrary code. (CVE-2026-41293)

It was discovered that Tomcat did not properly clear HTTP
authentication headers during WebSocket connection upgrades and
redirects. A remote attacker could possibly use this issue to obtain
sensitive credentials. (CVE-2026-42498)

It was discovered that Tomcat incorrectly handled authorization
when multiple method constraints defined the same HTTP method. A
remote attacker could possibly use this issue to bypass
authorization restrictions. (CVE-2026-43515)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8450-1</guid><pubDate>Thu, 18 Jun 2026 15:56:22 +0000</pubDate></item><item><title>USN-8449-1: ldns vulnerability</title><link>https://ubuntu.com/security/notices/USN-8449-1</link><description>Pablo Ruiz discovered that ldns did not properly validate DNS
responses when used as a stub resolver over UDP. A remote
attacker could possibly use this issue to inject arbitrary DNS
responses.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8449-1</guid><pubDate>Thu, 18 Jun 2026 13:33:51 +0000</pubDate></item><item><title>USN-8442-1: kitty vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8442-1</link><description>It was discovered that kitty incorrectly handled certain image data. An
attacker able to write to the terminal's input could possibly use this
issue to cause kitty to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-33633)

It was discovered that kitty incorrectly handled certain graphics commands.
An attacker able to write escape sequences to a kitty terminal could
possibly use this issue to cause kitty to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-33642)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8442-1</guid><pubDate>Wed, 17 Jun 2026 15:37:12 +0000</pubDate></item><item><title>USN-8390-2: Linux kernel vulnerability</title><link>https://ubuntu.com/security/notices/USN-8390-2</link><description>It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container.
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8390-2</guid><pubDate>Wed, 17 Jun 2026 10:34:42 +0000</pubDate></item><item><title>USN-8441-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8441-1</link><description>It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)


Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - Packet sockets;
(CVE-2026-31504, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078,
CVE-2026-46028)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8441-1</guid><pubDate>Wed, 17 Jun 2026 10:27:10 +0000</pubDate></item></channel></rss>