<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 26 Aug 2026 15:15:11 +0000</lastBuildDate><item><title>USN-8681-1: OpenJDK 25 vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8681-1</link><description>It was discovered that the JSSE component of OpenJDK 25 did not correctly
authenticate users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-46968)

It was discovered that the JSSE component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-46917)

It was discovered that the ImageIO component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-47010)

It was discovered that the 2D component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-47021, CVE-2026-47059)

It was discovered that the Libraries component of OpenJDK 25 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-47027)

It was discovered that the Security component of OpenJDK 25 did not correctly
authenticate users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-60147)

It was discovered that the Libraries component of OpenJDK 25 did not correctly
authenticate users. A remote attacker could possibly use this issue to read or
modify sensitive data. (CVE-2026-47063)

Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not
correctly handle certain integer arithmetic. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-41254)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8681-1</guid><pubDate>Wed, 26 Aug 2026 01:40:39 +0000</pubDate></item><item><title>USN-8659-4: Linux kernel (Oracle) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8659-4</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8659-4</guid><pubDate>Wed, 26 Aug 2026 00:14:56 +0000</pubDate></item><item><title>USN-8666-2: Linux kernel (Azure) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8666-2</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - Ext4 file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8666-2</guid><pubDate>Tue, 25 Aug 2026 21:15:06 +0000</pubDate></item><item><title>USN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8630-5</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Mellanox network drivers;
  - File systems infrastructure;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8630-5</guid><pubDate>Tue, 25 Aug 2026 21:12:04 +0000</pubDate></item><item><title>USN-8658-3: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8658-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8658-3</guid><pubDate>Tue, 25 Aug 2026 20:27:36 +0000</pubDate></item><item><title>USN-8643-4: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8643-4</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network drivers;
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8643-4</guid><pubDate>Tue, 25 Aug 2026 20:21:07 +0000</pubDate></item><item><title>USN-8659-3: Linux kernel (Azure) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8659-3</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8659-3</guid><pubDate>Tue, 25 Aug 2026 20:14:19 +0000</pubDate></item><item><title>USN-8680-1: FFmpeg vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8680-1</link><description>Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
data. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)

Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-70632)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8680-1</guid><pubDate>Tue, 25 Aug 2026 20:01:39 +0000</pubDate></item><item><title>USN-8679-1: Vim vulnerability</title><link>https://ubuntu.com/security/notices/USN-8679-1</link><description>It was discovered that Vim incorrectly handled certain tags files. An
attacker could possibly use this issue to execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8679-1</guid><pubDate>Tue, 25 Aug 2026 19:29:14 +0000</pubDate></item><item><title>USN-8678-2: OpenSSL, OpenSSL 1.0 vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8678-2</link><description>USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.

In addition, this update also fixes the following issues that were
not previously addressed in those releases:

It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)

It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)

It was discovered that OpenSSL incorrectly handled the SSL_select_next_proto
function when called with an empty client protocol list. A remote attacker
could possibly use this issue to cause OpenSSL to disclose private memory
contents to the peer, leading to a loss of confidentiality. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)

Original advisory details:

 It was discovered that OpenSSL incorrectly handled buffering of DTLS
 records for a future epoch. A remote attacker could possibly use this issue
 to cause OpenSSL to use excessive resources, leading to a denial of
 service. (CVE-2026-54874)

 It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
 remote attacker could possibly use this issue to cause a heap buffer
 overflow, leading to a denial of service or arbitrary code execution.
 (CVE-2026-63072)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8678-2</guid><pubDate>Tue, 25 Aug 2026 18:15:33 +0000</pubDate></item></channel></rss>