Vendor advisories

Ubuntu Security Notices

Browse 129 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 13 minutes ago Checked every 15 minutes

129 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Ubuntu Security NoticesUSN-8571-2
Severity not listed

USN-8571-2: Apache HTTP Server regression

USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was incomplete due to a missing library symbol, resulting in a regression that could cause Apache HTTP Server to fail to start when HTTP/2 proxying was enabled. This update fixes the problem. We apologize for the...

Vendor guidance

USN-8571-1 fixed vulnerabilities in Apache HTTP Server.

Ubuntu Security NoticesUSN-8747-1
Severity not listed

USN-8747-1: Beets vulnerability

It was discovered that Beets incorrectly escaped untrusted media metadata in its web interface. An attacker could possibly use this issue to inject arbitrary HTML or execute arbitrary JavaScript code in a user's browser.

Ubuntu Security NoticesUSN-8746-1
Severity not listed

USN-8746-1: libEBML vulnerability

It was discovered that libEBML incorrectly handled certain read and write operations. An attacker could possibly use this issue to cause a buffer overflow, resulting in a denial of service.

Ubuntu Security NoticesUSN-8748-1
Severity not listed

USN-8748-1: Linux kernel (NVIDIA) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - G...

Vendor guidance

This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - GFS2 file system; - OCFS2 file system; - SMB network file system;...

Ubuntu Security NoticesUSN-8737-2
Severity not listed

USN-8737-2: GNU C Library vulnerabilities

USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An att...

Vendor guidance

USN-8737-1 fixed vulnerabilities in GNU C Library.

Ubuntu Security NoticesUSN-8742-1
Severity not listed

USN-8742-1: Netty vulnerability

It was discovered that Netty incorrectly validates the bailiwick of NS records. An attacker could possibly use this issue to facilitate DNS cache poisoning attacks.

Ubuntu Security NoticesUSN-8740-1
Severity not listed

USN-8740-1: .NET vulnerabilities

Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did not properly validate cross-origin WebSocket connections. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-58649) Rajesh Chada discovered that the .NET watch AspireS...

Ubuntu Security NoticesUSN-8716-2
Severity not listed

USN-8716-2: FFmpeg vulnerabilities

USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possi...

Vendor guidance

USN-8716-1 fixed several vulnerabilities in FFmpeg.

Ubuntu Security NoticesUSN-8675-2
Severity not listed

USN-8675-2: Perl vulnerabilities

USN-8675-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 26.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled short source addresses in the Socket module. An attacker could possibly use this issue ...

Vendor guidance

USN-8675-1 fixed vulnerabilities in Perl.

Ubuntu Security NoticesUSN-8739-1
Severity not listed

USN-8739-1: ImageMagick vulnerabilities

It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366...

Ubuntu Security NoticesUSN-8670-3
Severity not listed

USN-8670-3: curl vulnerability

USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in th...

Vendor guidance

USN-8670-1 fixed a vulnerability in curl.

Ubuntu Security NoticesUSN-8679-2
Severity not listed

USN-8679-2: Vim vulnerability

USN-8679-1 fixed a vulnerability in Vim. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: It was discovered that Vim incorrectly handled certain tags files. An attacker could possibly use this issue to execute arbitrary code.

Vendor guidance

USN-8679-1 fixed a vulnerability in Vim.

Ubuntu Security NoticesUSN-8737-1
Severity not listed

USN-8737-1: GNU C Library vulnerabilities

It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-...

Ubuntu Security NoticesUSN-8736-1
Severity not listed

USN-8736-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (CVE-2026-15534) It w...

Ubuntu Security NoticesUSN-8733-1
Severity not listed

USN-8733-1: Gzip vulnerabilities

Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip's gzexe utility created temporary files in an insecure manner when mktemp was unavailable. A local attacker could possibly use this issue to overwrite arbitrary files. (CVE-2026-41991) Elias Hasas, Michał Majchrow...

Ubuntu Security NoticesUSN-8732-1
Severity not listed

USN-8732-1: Minetest vulnerability

It was discovered that Minetest did not properly sanitize the Lua sandbox environment when using LuaJIT. A malicious mod could escape the sandbox to execute arbitrary code and gain full file system access on the server. An attacker could use this issue to compromise the server.

Ubuntu Security NoticesUSN-8731-1
Severity not listed

USN-8731-1: MiniUPnPd vulnerability

It was discovered that MiniUPnPd contained an integer underflow vulnerability in SOAPAction header parsing. A remote attacker could use this issue to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.