<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 26 Aug 2026 05:53:13 +0000</lastBuildDate><item><title>USN-8659-4: Linux kernel (Oracle) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8659-4</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8659-4</guid><pubDate>Wed, 26 Aug 2026 00:14:56 +0000</pubDate></item><item><title>USN-8666-2: Linux kernel (Azure) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8666-2</link><description>Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - Cryptographic API;
  - InfiniBand drivers;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - Network drivers;
  - NVME drivers;
  - File systems infrastructure;
  - Ext4 file system;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - Locking primitives;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8666-2</guid><pubDate>Tue, 25 Aug 2026 21:15:06 +0000</pubDate></item><item><title>USN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8630-5</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - Mellanox network drivers;
  - File systems infrastructure;
  - IPv4 networking;
  - Network traffic control;
  - TCP network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8630-5</guid><pubDate>Tue, 25 Aug 2026 21:12:04 +0000</pubDate></item><item><title>USN-8658-3: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8658-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8658-3</guid><pubDate>Tue, 25 Aug 2026 20:27:36 +0000</pubDate></item><item><title>USN-8643-4: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8643-4</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network drivers;
  - Open vSwitch;
  - SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8643-4</guid><pubDate>Tue, 25 Aug 2026 20:21:07 +0000</pubDate></item><item><title>USN-8659-3: Linux kernel (Azure) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8659-3</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - Open vSwitch;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8659-3</guid><pubDate>Tue, 25 Aug 2026 20:14:19 +0000</pubDate></item><item><title>USN-8680-1: FFmpeg vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8680-1</link><description>Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
data. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)

Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-70632)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8680-1</guid><pubDate>Tue, 25 Aug 2026 20:01:39 +0000</pubDate></item><item><title>USN-8679-1: Vim vulnerability</title><link>https://ubuntu.com/security/notices/USN-8679-1</link><description>It was discovered that Vim incorrectly handled certain tags files. An
attacker could possibly use this issue to execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8679-1</guid><pubDate>Tue, 25 Aug 2026 19:29:14 +0000</pubDate></item><item><title>USN-8678-1: OpenSSL vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8678-1</link><description>It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)

It was discovered that OpenSSL incorrectly handled signature algorithm
selection when using Raw Public Keys. A remote attacker could possibly use
this issue to cause OpenSSL to crash, resulting in a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)

It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
processing. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-18798)

It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)

It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)

It was discovered that OpenSSL incorrectly validated the sender
distinguished name in CMP response messages. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)

It was discovered that OpenSSL incorrectly limited the growth of an
internal certificate cache used during CMP operations. A remote attacker
could possibly use this issue to cause OpenSSL to use excessive resources,
leading to a denial of service. (CVE-2026-63074)

It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
retention. A remote attacker could possibly use this issue to cause OpenSSL
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-63075)

It was discovered that OpenSSL incorrectly handled CMP protection algorithm
validation. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)

It was discovered that OpenSSL incorrectly verified authentication tags
when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
could possibly use this issue to perform AEAD forgery attacks.
(CVE-2026-75803)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8678-1</guid><pubDate>Tue, 25 Aug 2026 17:38:49 +0000</pubDate></item><item><title>USN-8670-2: curl vulnerability</title><link>https://ubuntu.com/security/notices/USN-8670-2</link><description>USN-8670-1 fixed a vulnerability in curl. This update provides the
corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS.

Original advisory details:

 Joshua Rogers discovered that curl incorrectly handled reusing
 connections when client certificate settings changed. This could result
 in the wrong client certificates being used, contrary to expectations.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8670-2</guid><pubDate>Tue, 25 Aug 2026 16:30:06 +0000</pubDate></item></channel></rss>