<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 12 Aug 2026 22:10:08 +0000</lastBuildDate><item><title>USN-8636-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8636-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Media drivers;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - SMB network file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - Memory management;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-31405, CVE-2026-31414, CVE-2026-31501, CVE-2026-31589,
CVE-2026-31633, CVE-2026-31636, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43379, CVE-2026-43465, CVE-2026-43499, CVE-2026-46113,
CVE-2026-46137, CVE-2026-46242, CVE-2026-46331, CVE-2026-52924,
CVE-2026-52989, CVE-2026-53086, CVE-2026-53131, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8636-1</guid><pubDate>Wed, 12 Aug 2026 20:06:15 +0000</pubDate></item><item><title>USN-8635-1: Linux kernel (Azure) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8635-1</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - GPU drivers;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - STMicroelectronics network drivers;
  - NVME drivers;
  - SCSI subsystem;
  - Thermal drivers;
  - USB over IP driver;
  - Ext4 file system;
  - Network file system (NFS) server daemon;
  - SMB network file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Tracing infrastructure;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - Ceph Core library;
  - DCCP (Datagram Congestion Control Protocol);
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - X.25 network layer;
(CVE-2021-47202, CVE-2021-47354, CVE-2021-47378, CVE-2024-38612,
CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402,
CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31607,
CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659,
CVE-2026-31668, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011,
CVE-2026-43037, CVE-2026-43038, CVE-2026-43198, CVE-2026-43383,
CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43499,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243,
CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8635-1</guid><pubDate>Wed, 12 Aug 2026 20:01:49 +0000</pubDate></item><item><title>USN-8634-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8634-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - InfiniBand drivers;
  - Media drivers;
  - STMicroelectronics network drivers;
  - Network drivers;
  - Ext4 file system;
  - IPv4 networking;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649,
CVE-2026-31659, CVE-2026-31685, CVE-2026-43198, CVE-2026-43493,
CVE-2026-43499, CVE-2026-46266, CVE-2026-52955, CVE-2026-52982,
CVE-2026-52986, CVE-2026-53176, CVE-2026-53225, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8634-1</guid><pubDate>Wed, 12 Aug 2026 19:54:57 +0000</pubDate></item><item><title>USN-8633-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8633-1</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - GPU drivers;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - STMicroelectronics network drivers;
  - NVME drivers;
  - Ext4 file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
(CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405,
CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657,
CVE-2026-31668, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499,
CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8633-1</guid><pubDate>Wed, 12 Aug 2026 19:54:20 +0000</pubDate></item><item><title>USN-8631-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8631-1</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - NVME drivers;
  - Ext4 file system;
  - SMB network file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8631-1</guid><pubDate>Wed, 12 Aug 2026 19:50:11 +0000</pubDate></item><item><title>USN-8630-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8630-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Mellanox network drivers;
  - File systems infrastructure;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8630-1</guid><pubDate>Wed, 12 Aug 2026 19:43:13 +0000</pubDate></item><item><title>USN-8629-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8629-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Network traffic control;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
(CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53151,
CVE-2026-53175, CVE-2026-53176, CVE-2026-53186, CVE-2026-53212,
CVE-2026-53215, CVE-2026-53216, CVE-2026-53221, CVE-2026-53224,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53247,
CVE-2026-53260, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8629-1</guid><pubDate>Wed, 12 Aug 2026 19:36:25 +0000</pubDate></item><item><title>USN-8627-1: Yelp vulnerability</title><link>https://ubuntu.com/security/notices/USN-8627-1</link><description>It was discovered that Yelp incorrectly handled certain crafted help
documents due to an overly permissive Content Security Policy. An
attacker could trick a user into opening a specially crafted document,
possibly resulting in the disclosure of sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8627-1</guid><pubDate>Tue, 11 Aug 2026 19:27:49 +0000</pubDate></item><item><title>USN-8592-1: ImageMagick vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8592-1</link><description>Hao Ren discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operation. An attacker could possibly use
this issue to trigger an out-of-bounds heap write, resulting in
arbitrary code execution. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-30936)

It was discovered that ImageMagick incorrectly handled extremely large
XWD images. An attacker could possibly use this issue to trigger an
out-of-bounds heap write, resulting in arbitrary code execution.
(CVE-2026-30937)

It was discovered that ImageMagick incorrectly handled extremely large
SFW images on 32-bit systems. An attacker could possibly use this issue
to trigger an integer overflow, resulting in a denial of service.
(CVE-2026-31853)

It was discovered that ImageMagick incorrectly handled memory allocation
failures in the sixel encoder. An attacker could possibly use this issue
to trigger a stack buffer overflow, resulting in arbitrary code
execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-32259)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8592-1</guid><pubDate>Mon, 10 Aug 2026 20:04:52 +0000</pubDate></item><item><title>USN-8626-1: systemd vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8626-1</link><description>It was discovered that systemd-homed did not properly verify the signature
of home records. A local attacker could possibly use this issue to add
arbitrary system groups to a logged-in user and gain elevated privileges.
(CVE-2026-16742)

It was discovered that systemd-machined incorrectly handled certain polkit
authorization checks. A local attacker could possibly use this issue to
terminate arbitrary processes, including privileged ones. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-15060)

It was discovered that systemd-oomd did not properly validate certain IPC
requests. A local attacker could possibly use this issue to terminate
arbitrary processes. (CVE-2026-15059)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8626-1</guid><pubDate>Mon, 10 Aug 2026 13:46:07 +0000</pubDate></item></channel></rss>