<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Thu, 24 Sep 2026 11:38:55 +0000</lastBuildDate><item><title>USN-8811-1: urllib3 vulnerability</title><link>https://ubuntu.com/security/notices/USN-8811-1</link><description>It was discovered that urllib3 did not correctly strip sensitive HTTP
headers during cross-origin redirects. An attacker could possibly use this
issue to leak sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8811-1</guid><pubDate>Thu, 24 Sep 2026 01:39:52 +0000</pubDate></item><item><title>USN-8810-1: ImageMagick vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8810-1</link><description>It was discovered that ImageMagick did not correctly handle certain
memory operations. An attacker could possibly use this issue to cause
a denial of service. This issue affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS
and Ubuntu 24.04 LTS. (CVE-2026-33535)

Kamil Frankowicz discovered that ImageMagick did not correctly handle
certain memory operations. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. This issue affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-33536)

It was discovered that ImageMagick did not correctly handle certain
integer arithmetic. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary code. (CVE-2026-34238)

Jake Lamberson discovered that ImageMagick did not correctly handle
certain memory operations. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. This issue affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40310)

Junmin Zhu discovered that ImageMagick did not correctly handle certain
memory operations. An attacker could possibly use this issue to cause a
denial of service. This issue affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-40311)

It was discovered that ImageMagick did not correctly handle opening
certain MSL files. If a user or automated system were tricked into
opening a specially crafted file, an attacker could possibly cause a
denial of service. This issue affected Ubuntu 26.04 LTS. (CVE-2026-40312)

It was discovered that ImageMagick did not correctly handle certain
memory operations. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2026-56361)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8810-1</guid><pubDate>Thu, 24 Sep 2026 00:20:47 +0000</pubDate></item><item><title>USN-8287-2: XDG Desktop Portal regression</title><link>https://ubuntu.com/security/notices/USN-8287-2</link><description>USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the
fix for CVE-2026-40354 was incomplete and introduced a regression when
trashing files. This update fixes the problem and provides the
corresponding update for Ubuntu 26.04 LTS.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that XDG Desktop Portal incorrectly handled
 trashing files. A local attacker could possibly use this issue to
 delete arbitrary files on the host file system via a symlink attack.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8287-2</guid><pubDate>Wed, 23 Sep 2026 18:40:07 +0000</pubDate></item><item><title>USN-8809-1: libgit2 vulnerability</title><link>https://ubuntu.com/security/notices/USN-8809-1</link><description>Kazuma Matsumoto and Isabel Mill discovered that libgit2 incorrectly
handled certain repository URLs when using the SSH transport. A remote
attacker could possibly use this issue to execute arbitrary commands.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8809-1</guid><pubDate>Wed, 23 Sep 2026 18:29:41 +0000</pubDate></item><item><title>USN-8808-1: SQL parse vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8808-1</link><description>It was discovered that SQL parse contained multiple algorithmic complexity
flaws when parsing SQL statements with deeply nested parentheses, comments,
or dollar-quoted string literals. An attacker could use this issue to cause
SQL parse to consume excessive CPU resources, resulting in a denial of
service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8808-1</guid><pubDate>Wed, 23 Sep 2026 18:19:12 +0000</pubDate></item><item><title>USN-8807-1: Open-iSNS vulnerability</title><link>https://ubuntu.com/security/notices/USN-8807-1</link><description>It was discovered that Open-iSNS contained a double-free vulnerability when
decoding malformed iSNS attributes. An unauthenticated attacker could possibly
 use this to cause a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8807-1</guid><pubDate>Wed, 23 Sep 2026 17:07:59 +0000</pubDate></item><item><title>USN-8805-1: Moodle vulnerability</title><link>https://ubuntu.com/security/notices/USN-8805-1</link><description>It was discovered that Moodle did not properly restrict URLs.
An authenticated user could possibly use this issue to perform a
server-side request forgery attack and expose sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8805-1</guid><pubDate>Wed, 23 Sep 2026 14:43:05 +0000</pubDate></item><item><title>USN-8806-1: NetworkManager vulnerability</title><link>https://ubuntu.com/security/notices/USN-8806-1</link><description>It was discovered that NetworkManager did not properly restrict the
ca-path and phase2-ca-path certificate authority settings for private
(single-user) 802.1X network connections. An attacker could use this issue
to point their own private 802.1X connection profile at a directory under
their control, causing NetworkManager to trust an attacker-chosen
certificate authority and potentially exposing network credentials via a
rogue authentication server.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8806-1</guid><pubDate>Wed, 23 Sep 2026 13:24:45 +0000</pubDate></item><item><title>USN-8733-2: Gzip vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8733-2</link><description>USN-8733-1 fixed vulnerabilities in Gzip. This update provides the
corresponding fix for Gzip on Ubuntu 14.04 LTS, Ubuntu 18.04 LTS and Ubuntu
20.04 LTS.

Original advisory details:

 Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip's gzexe
utility created temporary files in an insecure manner when mktemp was
unavailable. A local attacker could possibly use this issue to overwrite
arbitrary files. (CVE-2026-41991)

 Elias Hasas, Michał Majchrowicz and Marcin Wyczechowski discovered that
Gzip incorrectly handled certain compressed files. An attacker could
possibly use this issue to obtain sensitive information or cause Gzip to
crash, resulting in a denial of service. (CVE-2026-41992)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8733-2</guid><pubDate>Tue, 22 Sep 2026 16:04:21 +0000</pubDate></item><item><title>USN-8804-1: OpenSSH vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8804-1</link><description>Florian Kohnhäuser discovered that OpenSSH incorrectly handled shell
metacharacters in certain usernames. An attacker could possibly use this
issue to execute arbitrary commands when certain non-default
configurations were used, resulting in arbitrary code execution. This
issue only affected Ubuntu 14.04 LTS. (CVE-2026-35386)

Christos Papakonstantinou discovered that OpenSSH incorrectly handled
ECDSA algorithm restrictions. An attacker could possibly use this issue
to cause unintended ECDSA algorithms to be accepted, resulting in
security restrictions being bypassed. (CVE-2026-35387)

Vladimir Tokarev discovered that OpenSSH incorrectly handled certain
principal restrictions in authorized_keys files. An attacker could
possibly use this issue to bypass principal restrictions, resulting in
unauthorized access. This issue only affected Ubuntu 14.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-35414)

It was discovered that OpenSSH incorrectly handled downloaded file paths
when using sftp with an untrusted server. An attacker could possibly use
this issue to write downloaded files outside the intended location,
resulting in unauthorized file modification. (CVE-2026-59995)

It was discovered that OpenSSH incorrectly handled command-line
arguments in internal-sftp. An attacker could possibly use this issue to
cause certain security-related arguments to be ignored, resulting in
security restrictions being bypassed. (CVE-2026-59997)

It was discovered that OpenSSH incorrectly handled
GSSAPIStrictAcceptorCheck when used with Windows Active Directory. An
attacker could possibly use this issue to bypass GSSAPI security
restrictions, resulting in unauthorized access. (CVE-2026-59998)

It was discovered that OpenSSH incorrectly handled forwarding
restrictions when DisableForwarding and PermitTunnel were used together.
An attacker could possibly use this issue to create tunnels despite
forwarding being disabled, resulting in security restrictions being
bypassed. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2026-59999)

It was discovered that OpenSSH incorrectly handled authentication
attempt limits when using GSSAPI authentication. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-60000)

It was discovered that OpenSSH did not always enforce the minimum
authentication delay. An attacker could possibly use this issue to
perform authentication attempts more rapidly than intended, resulting in
weakened brute-force protections. This issue only affected Ubuntu 20.04
LTS. (CVE-2026-60001)

It was discovered that OpenSSH incorrectly handled certain concurrent
remote forwarding operations. An attacker could possibly use this issue
to trigger a use-after-free, resulting in a denial of service or
arbitrary code execution. (CVE-2026-73282)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8804-1</guid><pubDate>Tue, 22 Sep 2026 14:24:54 +0000</pubDate></item></channel></rss>