Vendor advisories

Ubuntu Security Notices

Browse 129 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 13 minutes ago Checked every 15 minutes

129 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Ubuntu Security NoticesUSN-8709-1
Severity not listed

USN-8709-1: ncurses vulnerability

It was discovered that ncurses incorrectly handled specially crafted terminfo database entries. A local attacker could possibly use this issue to cause applications using ncurses to crash, resulting in a denial of service.

Ubuntu Security NoticesUSN-8708-1
Severity not listed

USN-8708-1: sudo-rs vulnerability

It was discovered that sudo-rs incorrectly handled time-of-check vs time- of-use conditions in sudoedit. A local attacker with permission to edit specific files using sudoedit could use this issue to place files in arbitrary directories, and possibly escalate their privileges....

Ubuntu Security NoticesUSN-8690-1
Severity not listed

USN-8690-1: Pillow vulnerability

It was discovered that Pillow did not properly manage memory when processing certain image files. An attacker could possibly use this issue to cause a denial of service or read sensitive data.

Ubuntu Security NoticesUSN-8705-2
Severity not listed

USN-8705-2: OpenZFS vulnerability

USN-8705-1 fixed vulnerabilities in OpenZFS. This update provides the corresponding fix for OpenZFS on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linu...

Vendor guidance

USN-8705-1 fixed vulnerabilities in OpenZFS.

Ubuntu Security NoticesUSN-8706-1
Severity not listed

USN-8706-1: zlib vulnerability

It was discovered that zlib incorrectly handled negative length parameters in CRC32 combine functions. An attacker could use this issue to cause a denial of service via excessive CPU consumption.

Ubuntu Security NoticesUSN-8705-1
Severity not listed

USN-8705-1: OpenZFS vulnerability

It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker could possibly use this issue to perform pool-administrative operations or access privileged information, resulting in an authorization bypass.

Ubuntu Security NoticesUSN-8703-1
Severity not listed

USN-8703-1: WebKitGTK vulnerabilities

Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of ...

Ubuntu Security NoticesUSN-8702-1
Severity not listed

USN-8702-1: util-linux vulnerabilities

It was discovered that libblkid in util-linux had a heap use-after-free vulnerability during nested partition probing. An attacker who could present a crafted block device image could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-20...

Ubuntu Security NoticesUSN-8701-1
Severity not listed

USN-8701-1: UDisks vulnerability

It was discovered that UDisks did not correctly validate the caller identity when handling the as-user option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. A local attacker with an active console session could possibly use this issue to mount filesystems on b...

Ubuntu Security NoticesUSN-8678-3
Severity not listed

USN-8678-3: OpenSSL vulnerability

USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left out the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that OpenSSL incorrectly handled the Q...

Vendor guidance

USN-8673-1 fixed vulnerabilities in OpenSSL.

Ubuntu Security NoticesUSN-8700-1
Severity not listed

USN-8700-1: MySQL vulnerabilities

Multiple security issues were discovered in MySQL. MySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS. Ubuntu 22.04 LTS and Ubuntu 24.04 LTS packages have been updated with backported patches. In addition to security fixes, the updated packages contain bug fixes, new feature...

Vendor guidance

MySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS.

Ubuntu Security NoticesUSN-8699-1
Severity not listed

USN-8699-1: libssh vulnerabilities

It was discovered that libssh had a stack buffer overflow in its SFTP server when constructing directory listing entries for long filenames. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS....

Ubuntu Security NoticesUSN-8698-1
Severity not listed

USN-8698-1: FreeRDP vulnerabilities

It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.

Ubuntu Security NoticesUSN-8696-1
Severity not listed

USN-8696-1: Bind vulnerability

It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service.

Ubuntu Security NoticesUSN-8689-1
Severity not listed

USN-8689-1: OpenJDK 26 vulnerabilities

It was discovered that the JSSE component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 26 did not correctly authorize ...

Ubuntu Security NoticesUSN-8666-3
Severity not listed

USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject p...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - Fil...

Ubuntu Security NoticesUSN-8644-3
Severity not listed

USN-8644-3: Linux kernel (Azure) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - File systems infrastructure; - OCFS2 file system; - B.A.T.M.A.N. meshing protocol; - SCTP proto...

Vendor guidance

This update corrects flaws in the following subsystems: - File systems infrastructure; - OCFS2 file system; - B.A.T.M.A.N.

Ubuntu Security NoticesUSN-8661-3
Severity not listed

USN-8661-3: Linux kernel vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject p...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic ...

Ubuntu Security NoticesUSN-8658-4
Severity not listed

USN-8658-4: Linux kernel (Azure CVM) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)

Vendor guidance

This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)

Ubuntu Security NoticesUSN-8643-5
Severity not listed

USN-8643-5: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-532...

Vendor guidance

This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.