<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Tue, 15 Sep 2026 08:10:06 +0000</lastBuildDate><item><title>USN-8758-1: dracut vulnerability</title><link>https://ubuntu.com/security/notices/USN-8758-1</link><description>It was discovered that dracut did not properly shell-quote messages
written by the die() function to the emergency hook directory. An
attacker on the adjacent network controlling a rogue DHCP server could
use this issue to inject commands that execute as root during
boot-failure handling. (CVE-2026-15816)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8758-1</guid><pubDate>Mon, 14 Sep 2026 20:28:17 +0000</pubDate></item><item><title>USN-8739-2: ImageMagick vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8739-2</link><description>USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding fixes for Ubuntu 24.04 LTS.

Original advisory details:

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
 Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368,
 CVE-2026-56371, CVE-2026-56373)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service or
 execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and
 Ubuntu 26.04 LTS. (CVE-2026-56370)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service or
 expose sensitive information. This issue only affected Ubuntu 14.04 LTS,
 Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04
 LTS. (CVE-2026-56378)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to execute arbitrary code. This
 issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
 Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379)

 It was discovered that ImageMagick incorrectly handled memory allocation
 in certain operations. An attacker could possibly use this issue to cause
 a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu
 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS.
 (CVE-2026-61465)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS.
 (CVE-2026-61857)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service.
 (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
 Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866)

 It was discovered that ImageMagick incorrectly handled certain images on
 32-bit systems. An attacker could possibly use this issue to cause a
 denial of service or execute arbitrary code. This issue only affected
 Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
 and Ubuntu 26.04 LTS. (CVE-2026-62946)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8739-2</guid><pubDate>Mon, 14 Sep 2026 18:22:59 +0000</pubDate></item><item><title>USN-8757-1: cgit vulnerability</title><link>https://ubuntu.com/security/notices/USN-8757-1</link><description>It was discovered that cgit incorrectly handled repository paths when HTTP
cloning was enabled. A remote attacker could possibly use this issue to
access files outside the repository and obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8757-1</guid><pubDate>Mon, 14 Sep 2026 13:13:19 +0000</pubDate></item><item><title>USN-8756-1: Yelp vulnerability</title><link>https://ubuntu.com/security/notices/USN-8756-1</link><description>It was discovered that Yelp allowed help documents to execute arbitrary
scripts. An attacker could possibly use this issue to trick a user into
opening a specially crafted help document and obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8756-1</guid><pubDate>Mon, 14 Sep 2026 12:55:09 +0000</pubDate></item><item><title>USN-8755-1: libvips vulnerability</title><link>https://ubuntu.com/security/notices/USN-8755-1</link><description>It was discovered that libvips incorrectly handled specially crafted TIFF
images when saving them as HEIF images. An attacker could possibly use this
issue to cause libvips to crash, resulting in a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8755-1</guid><pubDate>Mon, 14 Sep 2026 12:47:26 +0000</pubDate></item><item><title>USN-8754-1: Freeciv vulnerability</title><link>https://ubuntu.com/security/notices/USN-8754-1</link><description>It was discovered that Freeciv incorrectly handled certain network packets,
resulting in a stack overflow. A remote attacker could possibly use this
issue to cause Freeciv clients or servers to crash, resulting in a denial
of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8754-1</guid><pubDate>Mon, 14 Sep 2026 12:40:26 +0000</pubDate></item><item><title>USN-8753-1: libinput vulnerability</title><link>https://ubuntu.com/security/notices/USN-8753-1</link><description>It was discovered that libinput did not properly escape device
properties. A local attacker could possibly use this issue to inject
arbitrary udev properties and execute arbitrary code as root.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8753-1</guid><pubDate>Mon, 14 Sep 2026 12:28:51 +0000</pubDate></item><item><title>USN-8752-1: Konsole vulnerability</title><link>https://ubuntu.com/security/notices/USN-8752-1</link><description>It was discovered that Konsole incorrectly handled certain URLs under
specific circumstances. A remote attacker could possibly use this issue to
execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8752-1</guid><pubDate>Mon, 14 Sep 2026 11:52:42 +0000</pubDate></item><item><title>USN-8563-5: nginx vulnerability</title><link>https://ubuntu.com/security/notices/USN-8563-5</link><description>USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was
backed out in USN-8563-2 because it could cause a regression. This update
includes a better fix for CVE-2026-42533.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that nginx incorrectly handled certain map directives
 using regex matching and capture variables. A remote attacker could use
 this issue to cause nginx to crash, resulting in a denial of service, or
 possibly execute arbitrary code. (CVE-2026-42533)

 It was discovered that nginx had a use-after-free vulnerability in the
 ngx_http_ssi_module module when configured with Server-Side Includes,
 proxy_pass, and proxy buffering disabled directives. An attacker able to
 intercept traffic and control responses from an upstream server could
 possibly use this issue to cause nginx to crash, resulting in a denial of
 service. (CVE-2026-56434)

 It was discovered that nginx incorrectly handled certain requests in the
 ngx_http_slice_module module. A remote attacker could possibly use this
 issue to obtain sensitive information or cause nginx to crash, resulting
 in a denial of service. (CVE-2026-60005)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8563-5</guid><pubDate>Mon, 14 Sep 2026 11:35:12 +0000</pubDate></item><item><title>USN-8751-1: Urwid vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8751-1</link><description>Katriel Moses discovered that Urwid used a weak PRNG. A local attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8751-1</guid><pubDate>Mon, 14 Sep 2026 03:34:34 +0000</pubDate></item></channel></rss>