<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Tue, 15 Sep 2026 09:44:20 +0000</lastBuildDate><item><title>USN-8760-1: Linux kernel (NVIDIA) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8760-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - User-space API (UAPI);
  - Kernel build system;
  - ARM32 architecture;
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - Intel NPU Driver;
  - ACPI drivers;
  - Android drivers;
  - Drivers core;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Character device driver;
  - Hardware random number generator core;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - Buffer Sharing and Synchronization framework;
  - Intel Stratix 10 firmware drivers;
  - FPGA Framework;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - CoreSight HW tracing drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Mouse) drivers;
  - IOMMU subsystem;
  - IRQ chip drivers;
  - Multiple devices driver;
  - Media drivers;
  - Multifunction device drivers;
  - Fastrpc Driver;
  - MMC subsystem;
  - Ethernet bonding driver;
  - Network drivers;
  - Mellanox network drivers;
  - MediaTek network drivers;
  - NTB driver;
  - NVME drivers;
  - NVMEM (Non Volatile Memory) drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - System reset/shutdown drivers;
  - Power sequencing drivers;
  - PTP clock framework;
  - Voltage and Current Regulator drivers;
  - RPMSG subsystem;
  - SLIMbus drivers;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - VME bus staging drivers;
  - Trusted Execution Environment drivers;
  - Thunderbolt and USB4 drivers;
  - TTY drivers;
  - Cadence USB3 driver;
  - ULPI bus;
  - DesignWare USB3 driver;
  - Faraday FOTG210 USB2 dual-role controller driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - USB ChaosKey driver;
  - Siemens ID Mouse USB driver;
  - IOWarrior USB driver;
  - LD Didactic USB driver;
  - LEGO USB Tower driver;
  - Intel USBIO USB I/O expander driver;
  - USS720 USB parallel port adapter driver;
  - MediaTek USB3 DRD driver;
  - USB Serial drivers;
  - USB Type-C Port Controller Manager driver;
  - USB Type-C Connector System Software Interface driver;
  - USB over IP driver;
  - VFIO drivers;
  - Framebuffer layer;
  - Virtio drivers;
  - BTRFS file system;
  - EROFS file system;
  - exFAT file system;
  - F2FS file system;
  - File systems infrastructure;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS file system;
  - HFS+ file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - SMB network file system;
  - UDF file system;
  - XFS file system;
  - Key management;
  - BPF subsystem;
  - Memory management;
  - Software nodes and device properties;
  - Glob pattern matching library;
  - Memory Management;
  - KVM subsystem;
  - Mellanox drivers;
  - Restartable sequences system call mechanism;
  - Socket messages infrastructure;
  - Network traffic control;
  - Bluetooth subsystem;
  - Netfilter;
  - Networking core;
  - Network sockets;
  - TCP network protocol;
  - io_uring subsystem;
  - IPC subsystem;
  - Audit subsystem;
  - Perf events;
  - Kernel fork() syscall;
  - Locking primitives;
  - Kernel module support;
  - Scheduler infrastructure;
  - Signal handling mechanism;
  - Timer subsystem;
  - Tracing infrastructure;
  - Debug objects infrastructure;
  - 6LoWPAN network protocol;
  - IEEE 802 network protocols;
  - 9P file system network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - Devlink API;
  - HSR network protocol;
  - IEEE802154.4 network protocol;
  - IPv4 networking;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - MAC80211 subsystem;
  - IEEE 802.15.4 subsystem;
  - Multipath TCP;
  - NetLabel subsystem;
  - Open vSwitch;
  - Phonet protocol;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - eXpress Data Path;
  - AppArmor security module;
  - Linux Security Modules (LSM) Framework;
  - Apple Onboard Audio ALSA driver;
  - ALSA framework;
  - FireWire sound drivers;
  - HD-audio driver;
  - Gravis UltraSound ALSA driver;
  - C-Media CMI8x38 ALSA driver;
  - ESS Solo-1 ALSA driver;
  - ICE1712/ICE1724 (Envy24) ALSA driver;
  - Yamaha YMFPCI ALSA driver;
  - Wolfson Microelectronics audio codecs;
  - SoundWire (SDCA) ASoC drivers;
  - USB sound devices;
  - Virtio sound driver;
(CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52917,
CVE-2026-52929, CVE-2026-52930, CVE-2026-52935, CVE-2026-52938,
CVE-2026-52939, CVE-2026-52940, CVE-2026-52942, CVE-2026-52947,
CVE-2026-52948, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134,
CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138,
CVE-2026-53139, CVE-2026-53140, CVE-2026-53141, CVE-2026-53142,
CVE-2026-53143, CVE-2026-53144, CVE-2026-53145, CVE-2026-53146,
CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150,
CVE-2026-53152, CVE-2026-53153, CVE-2026-53154, CVE-2026-53155,
CVE-2026-53156, CVE-2026-53157, CVE-2026-53158, CVE-2026-53159,
CVE-2026-53160, CVE-2026-53161, CVE-2026-53162, CVE-2026-53163,
CVE-2026-53164, CVE-2026-53165, CVE-2026-53167, CVE-2026-53168,
CVE-2026-53169, CVE-2026-53170, CVE-2026-53171, CVE-2026-53172,
CVE-2026-53173, CVE-2026-53177, CVE-2026-53178, CVE-2026-53179,
CVE-2026-53180, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183,
CVE-2026-53184, CVE-2026-53185, CVE-2026-53187, CVE-2026-53188,
CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53192,
CVE-2026-53193, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196,
CVE-2026-53197, CVE-2026-53198, CVE-2026-53199, CVE-2026-53200,
CVE-2026-53201, CVE-2026-53202, CVE-2026-53203, CVE-2026-53204,
CVE-2026-53205, CVE-2026-53206, CVE-2026-53207, CVE-2026-53208,
CVE-2026-53209, CVE-2026-53210, CVE-2026-53211, CVE-2026-53213,
CVE-2026-53214, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219,
CVE-2026-53220, CVE-2026-53222, CVE-2026-53223, CVE-2026-53226,
CVE-2026-53227, CVE-2026-53229, CVE-2026-53230, CVE-2026-53231,
CVE-2026-53232, CVE-2026-53233, CVE-2026-53234, CVE-2026-53235,
CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239,
CVE-2026-53240, CVE-2026-53241, CVE-2026-53242, CVE-2026-53243,
CVE-2026-53244, CVE-2026-53245, CVE-2026-53248, CVE-2026-53249,
CVE-2026-53250, CVE-2026-53251, CVE-2026-53252, CVE-2026-53253,
CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53257,
CVE-2026-53258, CVE-2026-53259, CVE-2026-53261, CVE-2026-53262,
CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266,
CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270,
CVE-2026-53271, CVE-2026-53272, CVE-2026-53273, CVE-2026-53274,
CVE-2026-53275, CVE-2026-53276, CVE-2026-53325, CVE-2026-53326,
CVE-2026-53327, CVE-2026-53328, CVE-2026-53329, CVE-2026-53330,
CVE-2026-53331, CVE-2026-53332, CVE-2026-53333, CVE-2026-53334,
CVE-2026-53335, CVE-2026-53336, CVE-2026-53337, CVE-2026-53338,
CVE-2026-53339, CVE-2026-53340, CVE-2026-53341, CVE-2026-53342,
CVE-2026-53343, CVE-2026-53344, CVE-2026-53345, CVE-2026-53346,
CVE-2026-53347, CVE-2026-53348, CVE-2026-53349, CVE-2026-53350,
CVE-2026-53351, CVE-2026-53352, CVE-2026-53353, CVE-2026-53355,
CVE-2026-53356, CVE-2026-53361, CVE-2026-53362, CVE-2026-53363,
CVE-2026-53366, CVE-2026-53381, CVE-2026-53382, CVE-2026-53383,
CVE-2026-53384, CVE-2026-53385, CVE-2026-53386, CVE-2026-53387,
CVE-2026-53388, CVE-2026-53389, CVE-2026-53390, CVE-2026-53391,
CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53395,
CVE-2026-53396, CVE-2026-53397, CVE-2026-53398, CVE-2026-53399,
CVE-2026-53400, CVE-2026-53401, CVE-2026-53402, CVE-2026-53403,
CVE-2026-63794, CVE-2026-63795, CVE-2026-63796, CVE-2026-63797,
CVE-2026-63798, CVE-2026-63799, CVE-2026-63800, CVE-2026-63801,
CVE-2026-63802, CVE-2026-63803, CVE-2026-63804, CVE-2026-63805,
CVE-2026-63806, CVE-2026-63807, CVE-2026-63808, CVE-2026-63809,
CVE-2026-63810, CVE-2026-63811, CVE-2026-63812, CVE-2026-63813,
CVE-2026-63814, CVE-2026-63815, CVE-2026-63816, CVE-2026-63817,
CVE-2026-63818, CVE-2026-63819, CVE-2026-63820, CVE-2026-63821,
CVE-2026-63822, CVE-2026-63823, CVE-2026-63824, CVE-2026-63825,
CVE-2026-63826, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829,
CVE-2026-63830, CVE-2026-63831, CVE-2026-63832, CVE-2026-63833,
CVE-2026-63834, CVE-2026-63835, CVE-2026-63836, CVE-2026-63867,
CVE-2026-63868, CVE-2026-63869, CVE-2026-63870, CVE-2026-63871,
CVE-2026-63873, CVE-2026-63874, CVE-2026-64187, CVE-2026-64188,
CVE-2026-64189, CVE-2026-64191, CVE-2026-64192, CVE-2026-64205,
CVE-2026-64206, CVE-2026-64207, CVE-2026-64244, CVE-2026-64245,
CVE-2026-64246, CVE-2026-64247, CVE-2026-64249, CVE-2026-64251,
CVE-2026-64253, CVE-2026-64254, CVE-2026-64255, CVE-2026-64256,
CVE-2026-64258, CVE-2026-64259, CVE-2026-64260, CVE-2026-64261,
CVE-2026-64262, CVE-2026-64263, CVE-2026-64264, CVE-2026-64265,
CVE-2026-64266, CVE-2026-64267, CVE-2026-64268, CVE-2026-64269,
CVE-2026-64270, CVE-2026-64271, CVE-2026-64272, CVE-2026-64273,
CVE-2026-64274, CVE-2026-64275, CVE-2026-64276, CVE-2026-64277,
CVE-2026-64278, CVE-2026-64279, CVE-2026-64280, CVE-2026-64282,
CVE-2026-64283, CVE-2026-64284, CVE-2026-64285, CVE-2026-64286,
CVE-2026-64287, CVE-2026-64288, CVE-2026-64289, CVE-2026-64290,
CVE-2026-64291, CVE-2026-64292, CVE-2026-64293, CVE-2026-64294,
CVE-2026-64295, CVE-2026-64296, CVE-2026-64297, CVE-2026-64298,
CVE-2026-64299, CVE-2026-64300, CVE-2026-64301, CVE-2026-64302,
CVE-2026-64303, CVE-2026-64304, CVE-2026-64305, CVE-2026-64306,
CVE-2026-64307, CVE-2026-64308, CVE-2026-64309, CVE-2026-64310,
CVE-2026-64312, CVE-2026-64313, CVE-2026-64314, CVE-2026-64315,
CVE-2026-64316, CVE-2026-64317, CVE-2026-64318, CVE-2026-64319,
CVE-2026-64320, CVE-2026-64321, CVE-2026-64322, CVE-2026-64323,
CVE-2026-64324, CVE-2026-64325, CVE-2026-64326, CVE-2026-64327,
CVE-2026-64328, CVE-2026-64329, CVE-2026-64330, CVE-2026-64331,
CVE-2026-64332, CVE-2026-64333, CVE-2026-64334, CVE-2026-64335,
CVE-2026-64336, CVE-2026-64337, CVE-2026-64338, CVE-2026-64339,
CVE-2026-64340, CVE-2026-64341, CVE-2026-64342, CVE-2026-64343,
CVE-2026-64344, CVE-2026-64345, CVE-2026-64346, CVE-2026-64347,
CVE-2026-64348, CVE-2026-64350, CVE-2026-64351, CVE-2026-64352,
CVE-2026-64353, CVE-2026-64354, CVE-2026-64355, CVE-2026-64356,
CVE-2026-64357, CVE-2026-64358, CVE-2026-64359, CVE-2026-64360,
CVE-2026-64361, CVE-2026-64362, CVE-2026-64363, CVE-2026-64364,
CVE-2026-64365, CVE-2026-64366, CVE-2026-64367, CVE-2026-64368,
CVE-2026-64369, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372,
CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64376,
CVE-2026-64377, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380,
CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384,
CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64388,
CVE-2026-64389, CVE-2026-64390, CVE-2026-64391, CVE-2026-64392,
CVE-2026-64393, CVE-2026-64394, CVE-2026-64395, CVE-2026-64396,
CVE-2026-64397, CVE-2026-64398, CVE-2026-64399, CVE-2026-64400,
CVE-2026-64401, CVE-2026-64402, CVE-2026-64403, CVE-2026-64404,
CVE-2026-64405, CVE-2026-64406, CVE-2026-64407, CVE-2026-64408,
CVE-2026-64409, CVE-2026-64410, CVE-2026-64411, CVE-2026-64412,
CVE-2026-64413, CVE-2026-64414, CVE-2026-64415, CVE-2026-64416,
CVE-2026-64417, CVE-2026-64418, CVE-2026-64419, CVE-2026-64420,
CVE-2026-64421, CVE-2026-64422, CVE-2026-64423, CVE-2026-64424,
CVE-2026-64425, CVE-2026-64426, CVE-2026-64428, CVE-2026-64429,
CVE-2026-64430, CVE-2026-64432, CVE-2026-64433, CVE-2026-64434,
CVE-2026-64435, CVE-2026-64436, CVE-2026-64438, CVE-2026-64439,
CVE-2026-64440, CVE-2026-64441, CVE-2026-64442, CVE-2026-64443,
CVE-2026-64444, CVE-2026-64445, CVE-2026-64446, CVE-2026-64447,
CVE-2026-64448, CVE-2026-64449, CVE-2026-64450, CVE-2026-64451,
CVE-2026-64452, CVE-2026-64453, CVE-2026-64454, CVE-2026-64455,
CVE-2026-64456, CVE-2026-64457, CVE-2026-64458, CVE-2026-64459,
CVE-2026-64460, CVE-2026-64461, CVE-2026-64462, CVE-2026-64463,
CVE-2026-64464, CVE-2026-64465, CVE-2026-64466, CVE-2026-64467,
CVE-2026-64468, CVE-2026-64469, CVE-2026-64470, CVE-2026-64471,
CVE-2026-64472, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475,
CVE-2026-64476, CVE-2026-64477, CVE-2026-64478, CVE-2026-64479,
CVE-2026-64480, CVE-2026-64481, CVE-2026-64482, CVE-2026-64483,
CVE-2026-64484, CVE-2026-64485, CVE-2026-64486, CVE-2026-64487,
CVE-2026-64488, CVE-2026-64489, CVE-2026-64490, CVE-2026-64491,
CVE-2026-64492, CVE-2026-64493, CVE-2026-64494, CVE-2026-64495,
CVE-2026-64496, CVE-2026-64497, CVE-2026-64499, CVE-2026-64500,
CVE-2026-64501, CVE-2026-64502, CVE-2026-64503, CVE-2026-64504,
CVE-2026-64505, CVE-2026-64507, CVE-2026-64508, CVE-2026-64509,
CVE-2026-64510, CVE-2026-64511, CVE-2026-64512, CVE-2026-64513,
CVE-2026-64514, CVE-2026-64529, CVE-2026-64531, CVE-2026-64536,
CVE-2026-64556, CVE-2026-64588, CVE-2026-64589, CVE-2026-64590,
CVE-2026-64591, CVE-2026-64592, CVE-2026-64593, CVE-2026-64594,
CVE-2026-64596, CVE-2026-64597, CVE-2026-64598, CVE-2026-64599,
CVE-2026-64600, CVE-2026-64601, CVE-2026-64602, CVE-2026-64603,
CVE-2026-64604, CVE-2026-68084, CVE-2026-68085, CVE-2026-68087,
CVE-2026-68088, CVE-2026-68089, CVE-2026-68090, CVE-2026-68091,
CVE-2026-68092, CVE-2026-68459, CVE-2026-68460, CVE-2026-68461,
CVE-2026-74584, CVE-2026-80591)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8760-1</guid><pubDate>Tue, 15 Sep 2026 09:15:22 +0000</pubDate></item><item><title>USN-8758-1: dracut vulnerability</title><link>https://ubuntu.com/security/notices/USN-8758-1</link><description>It was discovered that dracut did not properly shell-quote messages
written by the die() function to the emergency hook directory. An
attacker on the adjacent network controlling a rogue DHCP server could
use this issue to inject commands that execute as root during
boot-failure handling. (CVE-2026-15816)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8758-1</guid><pubDate>Mon, 14 Sep 2026 20:28:17 +0000</pubDate></item><item><title>USN-8739-2: ImageMagick vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8739-2</link><description>USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding fixes for Ubuntu 24.04 LTS.

Original advisory details:

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
 Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368,
 CVE-2026-56371, CVE-2026-56373)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service or
 execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and
 Ubuntu 26.04 LTS. (CVE-2026-56370)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service or
 expose sensitive information. This issue only affected Ubuntu 14.04 LTS,
 Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04
 LTS. (CVE-2026-56378)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to execute arbitrary code. This
 issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
 Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379)

 It was discovered that ImageMagick incorrectly handled memory allocation
 in certain operations. An attacker could possibly use this issue to cause
 a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu
 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS.
 (CVE-2026-61465)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS.
 (CVE-2026-61857)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service.
 (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870)

 It was discovered that ImageMagick incorrectly handled certain images. An
 attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
 Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866)

 It was discovered that ImageMagick incorrectly handled certain images on
 32-bit systems. An attacker could possibly use this issue to cause a
 denial of service or execute arbitrary code. This issue only affected
 Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
 and Ubuntu 26.04 LTS. (CVE-2026-62946)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8739-2</guid><pubDate>Mon, 14 Sep 2026 18:22:59 +0000</pubDate></item><item><title>USN-8757-1: cgit vulnerability</title><link>https://ubuntu.com/security/notices/USN-8757-1</link><description>It was discovered that cgit incorrectly handled repository paths when HTTP
cloning was enabled. A remote attacker could possibly use this issue to
access files outside the repository and obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8757-1</guid><pubDate>Mon, 14 Sep 2026 13:13:19 +0000</pubDate></item><item><title>USN-8756-1: Yelp vulnerability</title><link>https://ubuntu.com/security/notices/USN-8756-1</link><description>It was discovered that Yelp allowed help documents to execute arbitrary
scripts. An attacker could possibly use this issue to trick a user into
opening a specially crafted help document and obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8756-1</guid><pubDate>Mon, 14 Sep 2026 12:55:09 +0000</pubDate></item><item><title>USN-8755-1: libvips vulnerability</title><link>https://ubuntu.com/security/notices/USN-8755-1</link><description>It was discovered that libvips incorrectly handled specially crafted TIFF
images when saving them as HEIF images. An attacker could possibly use this
issue to cause libvips to crash, resulting in a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8755-1</guid><pubDate>Mon, 14 Sep 2026 12:47:26 +0000</pubDate></item><item><title>USN-8754-1: Freeciv vulnerability</title><link>https://ubuntu.com/security/notices/USN-8754-1</link><description>It was discovered that Freeciv incorrectly handled certain network packets,
resulting in a stack overflow. A remote attacker could possibly use this
issue to cause Freeciv clients or servers to crash, resulting in a denial
of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8754-1</guid><pubDate>Mon, 14 Sep 2026 12:40:26 +0000</pubDate></item><item><title>USN-8753-1: libinput vulnerability</title><link>https://ubuntu.com/security/notices/USN-8753-1</link><description>It was discovered that libinput did not properly escape device
properties. A local attacker could possibly use this issue to inject
arbitrary udev properties and execute arbitrary code as root.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8753-1</guid><pubDate>Mon, 14 Sep 2026 12:28:51 +0000</pubDate></item><item><title>USN-8752-1: Konsole vulnerability</title><link>https://ubuntu.com/security/notices/USN-8752-1</link><description>It was discovered that Konsole incorrectly handled certain URLs under
specific circumstances. A remote attacker could possibly use this issue to
execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8752-1</guid><pubDate>Mon, 14 Sep 2026 11:52:42 +0000</pubDate></item><item><title>USN-8563-5: nginx vulnerability</title><link>https://ubuntu.com/security/notices/USN-8563-5</link><description>USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was
backed out in USN-8563-2 because it could cause a regression. This update
includes a better fix for CVE-2026-42533.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that nginx incorrectly handled certain map directives
 using regex matching and capture variables. A remote attacker could use
 this issue to cause nginx to crash, resulting in a denial of service, or
 possibly execute arbitrary code. (CVE-2026-42533)

 It was discovered that nginx had a use-after-free vulnerability in the
 ngx_http_ssi_module module when configured with Server-Side Includes,
 proxy_pass, and proxy buffering disabled directives. An attacker able to
 intercept traffic and control responses from an upstream server could
 possibly use this issue to cause nginx to crash, resulting in a denial of
 service. (CVE-2026-56434)

 It was discovered that nginx incorrectly handled certain requests in the
 ngx_http_slice_module module. A remote attacker could possibly use this
 issue to obtain sensitive information or cause nginx to crash, resulting
 in a denial of service. (CVE-2026-60005)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8563-5</guid><pubDate>Mon, 14 Sep 2026 11:35:12 +0000</pubDate></item></channel></rss>