<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Mon, 31 Aug 2026 11:31:32 +0000</lastBuildDate><item><title>USN-8689-1: OpenJDK 26 vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8689-1</link><description>It was discovered that the JSSE component of OpenJDK 26 did not correctly
authenticate users. A remote attacker could possibly use this issue to read
or modify sensitive data. (CVE-2026-46968)

It was discovered that the JSSE component of OpenJDK 26 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-46917)

It was discovered that the ImageIO component of OpenJDK 26 did not
correctly authorize users. A remote attacker could possibly use this issue
to read or modify sensitive data. (CVE-2026-47010)

It was discovered that the 2D component of OpenJDK 26 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-47021, CVE-2026-47059)

It was discovered that the Libraries component of OpenJDK 26 did not
correctly authorize users. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-47027)

It was discovered that the Security component of OpenJDK 26 did not
correctly authenticate users. A remote attacker could possibly use this
issue to read or modify sensitive data. (CVE-2026-60147)

It was discovered that the Libraries component of OpenJDK 26 did not
correctly authenticate users. A remote attacker could possibly use this
issue to read or modify sensitive data. (CVE-2026-47063)

Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did
not correctly handle certain integer arithmetic. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-41254)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8689-1</guid><pubDate>Mon, 31 Aug 2026 00:41:06 +0000</pubDate></item><item><title>USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8666-3</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - Ext4 file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8666-3</guid><pubDate>Thu, 27 Aug 2026 21:41:58 +0000</pubDate></item><item><title>USN-8644-3: Linux kernel (Azure) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8644-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - File systems infrastructure;
  - OCFS2 file system;
  - B.A.T.M.A.N. meshing protocol;
  - SCTP protocol;
  - TIPC protocol;
(CVE-2026-43071, CVE-2026-52914, CVE-2026-52993, CVE-2026-53043,
CVE-2026-53224, CVE-2026-53246, CVE-2026-53309)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8644-3</guid><pubDate>Thu, 27 Aug 2026 21:39:06 +0000</pubDate></item><item><title>USN-8661-3: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8661-3</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - NVME drivers;
  - Ext4 file system;
  - SMB network file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - Open vSwitch;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53224, CVE-2026-53225,
CVE-2026-53228, CVE-2026-53246, CVE-2026-53359, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8661-3</guid><pubDate>Thu, 27 Aug 2026 21:36:04 +0000</pubDate></item><item><title>USN-8658-4: Linux kernel (Azure CVM) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8658-4</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8658-4</guid><pubDate>Thu, 27 Aug 2026 21:32:51 +0000</pubDate></item><item><title>USN-8643-5: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8643-5</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network drivers;
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8643-5</guid><pubDate>Thu, 27 Aug 2026 21:29:15 +0000</pubDate></item><item><title>USN-8688-1: PAM vulnerability</title><link>https://ubuntu.com/security/notices/USN-8688-1</link><description>Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8688-1</guid><pubDate>Thu, 27 Aug 2026 19:43:08 +0000</pubDate></item><item><title>USN-8687-1: p11-kit vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8687-1</link><description>It was discovered that p11-kit incorrectly handled certain RPC messages. A
local attacker could use this issue to cause p11-kit to crash, resulting in
a denial of service. (CVE-2026-13757)

It was discovered that p11-kit incorrectly handled nested attribute
decoding on 32-bit systems. A local attacker could use this issue to cause
p11-kit to crash, resulting in a denial of service. (CVE-2026-18938)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8687-1</guid><pubDate>Thu, 27 Aug 2026 15:20:16 +0000</pubDate></item><item><title>USN-8686-1: openCryptoki vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8686-1</link><description>It was discovered that primitive decoders in openCryptoki produced integer
underflows when the encoded length was zero. An attacker could possibly use
this issue to trigger out-of-bounds reads. (CVE-2026-40253)

It was discovered that openCryptoki incorrectly handled symlinks. An
attacker in the token-group could possibly use this issue to achieve
privilege  escalation or access sensitive information. (CVE-2026-23893)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8686-1</guid><pubDate>Thu, 27 Aug 2026 14:43:29 +0000</pubDate></item><item><title>USN-8685-1: bzip2 vulnerability</title><link>https://ubuntu.com/security/notices/USN-8685-1</link><description>It was discovered that bzip2 did not properly manage memory under certain
circumstances. An attacker could possibly use this issue to cause a crash,
resulting in a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8685-1</guid><pubDate>Thu, 27 Aug 2026 11:18:57 +0000</pubDate></item></channel></rss>