Vendor advisories

Ubuntu Security Notices

Browse 129 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 12 minutes ago Checked every 15 minutes

129 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Ubuntu Security NoticesUSN-8688-1
Severity not listed

USN-8688-1: PAM vulnerability

Juthawong Naisanguansee discovered that PAM incorrectly cleared failed login attempt records when certain services invoked the account phase without first performing authentication. An attacker could possibly use this issue to reset failed login counters, resulting in authenti...

Ubuntu Security NoticesUSN-8685-1
Severity not listed

USN-8685-1: bzip2 vulnerability

It was discovered that bzip2 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause a crash, resulting in a denial of service.

Ubuntu Security NoticesUSN-8684-1
Severity not listed

USN-8684-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered that Perl incorrectly handled regular ...

Ubuntu Security Notices
Severity not listed

LSN-0121-1: Kernel Live Patch Security Notice

In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry on the stack. In the Linux kernel, the following vulnerability has b...

Vendor guidance

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf.

Ubuntu Security NoticesUSN-8681-1
Severity not listed

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 25 did not correctly authorize ...

Ubuntu Security NoticesUSN-8659-4
Severity not listed

USN-8659-4: Linux kernel (Oracle) vulnerability

A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch;

Vendor guidance

This update corrects flaws in the following subsystems: - Open vSwitch;

Ubuntu Security NoticesUSN-8666-2
Severity not listed

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject p...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - Fil...

Ubuntu Security NoticesUSN-8630-5
Severity not listed

USN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File s...

Vendor guidance

This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic cont...

Ubuntu Security NoticesUSN-8658-3
Severity not listed

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)

Vendor guidance

This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)

Ubuntu Security NoticesUSN-8643-4
Severity not listed

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-532...

Vendor guidance

This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)

Ubuntu Security NoticesUSN-8659-3
Severity not listed

USN-8659-3: Linux kernel (Azure) vulnerability

A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch;

Vendor guidance

This update corrects flaws in the following subsystems: - Open vSwitch;

Ubuntu Security NoticesUSN-8680-1
Severity not listed

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectly handled certain video files. An att...

Ubuntu Security NoticesUSN-8678-2
Severity not listed

USN-8678-2: OpenSSL, OpenSSL 1.0 vulnerabilities

USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. In addition, this update also fixes the following issues that were not previously addressed in those...

Vendor guidance

USN-8678-1 fixed vulnerabilities in OpenSSL.

Ubuntu Security NoticesUSN-8678-1
Severity not listed

USN-8678-1: OpenSSL vulnerabilities

It was discovered that OpenSSL incorrectly handled the QUIC server incoming channel queue. A remote attacker could possibly use this issue to cause OpenSSL to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456) I...

Ubuntu Security NoticesUSN-8670-2
Severity not listed

USN-8670-2: curl vulnerability

USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate s...

Vendor guidance

USN-8670-1 fixed a vulnerability in curl.

Ubuntu Security NoticesUSN-8675-1
Severity not listed

USN-8675-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled short source addresses in the Socket module. An attacker could possibly use this issue to trigger an out-of-bounds heap read, resulting in information disclosure. (CVE-2026-12087) It was discovered that Perl incorrectly handled r...

Vendor guidance

(CVE-2026-12087) It was discovered that Perl incorrectly handled regular expressions containing a large number of fixed string alternatives.

Ubuntu Security NoticesUSN-8670-1
Severity not listed

USN-8670-1: curl vulnerability

Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

Ubuntu Security NoticesUSN-8658-2
Severity not listed

USN-8658-2: Linux kernel (IBM) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)

Vendor guidance

This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.