Vendor advisories

Ubuntu Security Notices

Browse 129 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 12 minutes ago Checked every 15 minutes

129 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Ubuntu Security NoticesUSN-8730-1
Severity not listed

USN-8730-1: Linux kernel vulnerability

A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - IPv6 networking; - Netfilter;

Vendor guidance

This update corrects flaws in the following subsystems: - IPv6 networking; - Netfilter;

Ubuntu Security NoticesUSN-8729-1
Severity not listed

USN-8729-1: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framew...

Vendor guidance

This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framewo...

Ubuntu Security NoticesUSN-8728-1
Severity not listed

USN-8728-1: Linux kernel (GCP) vulnerabilities

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permiss...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 platform drivers; - ARM64 architecture; - Cryptographic API; - PSP security protocol; - User-space API (UAPI); - Kernel build system; - ARM32 architecture;...

Ubuntu Security NoticesUSN-8727-1
Severity not listed

USN-8727-1: Linux kernel (OEM) vulnerabilities

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permiss...

Vendor guidance

This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Blo...

Ubuntu Security NoticesUSN-8726-1
Severity not listed

USN-8726-1: Linux kernel vulnerabilities

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permiss...

Vendor guidance

This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Blo...

Ubuntu Security NoticesUSN-8714-2
Severity not listed

USN-8714-2: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-5...

Vendor guidance

This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)

Ubuntu Security NoticesUSN-8725-1
Severity not listed

USN-8725-1: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - NVIDIA Tegra memory controller driver; - File systems infrastructure; - Network file system (NF...

Vendor guidance

This update corrects flaws in the following subsystems: - NVIDIA Tegra memory controller driver; - File systems infrastructure; - Network file system (NFS) server daemon; - OCFS2 file system; - B.A.T.M.A.N.

Ubuntu Security NoticesUSN-8720-1
Severity not listed

USN-8720-1: GnuPG vulnerability

It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could possibly use this issue to bypass message integrity checks.

Ubuntu Security NoticesUSN-8718-1
Severity not listed

USN-8718-1: SSSD vulnerability

It was discovered that SSSD did not properly validate authentication token lengths when processing PAM responder requests. A local attacker could possibly use this issue to cause SSSD to crash, resulting in a denial of service.

Ubuntu Security NoticesUSN-8716-1
Severity not listed

USN-8716-1: FFmpeg vulnerabilities

It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled ce...

Ubuntu Security NoticesUSN-8717-1
Severity not listed

USN-8717-1: Apache Tika vulnerability

It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emit...

Ubuntu Security NoticesUSN-8661-4
Severity not listed

USN-8661-4: Linux kernel vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject p...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic ...

Ubuntu Security NoticesUSN-8715-1
Severity not listed

USN-8715-1: Linux kernel (Oracle) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject p...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - Fil...

Ubuntu Security NoticesUSN-8714-1
Severity not listed

USN-8714-1: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-5...

Vendor guidance

This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)

Ubuntu Security NoticesUSN-8711-1
Severity not listed

USN-8711-1: Libgcrypt vulnerability

It was discovered that Libgcrypt had a timing-based side-channel flaw in its RSA implementation. A remote attacker could possibly use this issue to obtain sensitive information.

Ubuntu Security NoticesUSN-8688-2
Severity not listed

USN-8688-2: PAM vulnerability

USN-8688-1 fixed a vulnerability in PAM. This update provides the corresponding fix for PAM on Ubuntu 26.04 LTS. Original advisory details: Juthawong Naisanguansee discovered that PAM incorrectly cleared failed login attempt records when certain services invoked the account ph...

Vendor guidance

USN-8688-1 fixed a vulnerability in PAM.

Ubuntu Security NoticesUSN-8555-2
Severity not listed

USN-8555-2: Ubuntu Advantage Tools (pro client) regression

USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu 14.04 LTS only, it was discovered that some machines were unable to enable esm-infra-legacy due to a preemptive apt-helper check. This update fixes the problem. We apologize for the inconvenience. Original a...

Vendor guidance

USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.