Aggregator

USN-8367-1: tar-fs vulnerabilities

6 days 16 hours ago
It was discovered that tar-fs did not properly limit paths when extracting crafted tar files. An attacker could possibly use this issue to write or overwrite files outside the intended extraction directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-12905) It was discovered that tar-fs did not properly validate extraction paths for certain crafted tar archives. An attacker could possibly use this issue to write files outside the intended extraction directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-48387) It was discovered that tar-fs had a symlink validation bypass when extracting crafted tar files. An attacker could possibly use this issue to write files outside the intended extraction directory. (CVE-2025-59343)

USN-8366-1: Luanti vulnerabilities

6 days 17 hours ago
It was discovered that Luanti, when using LuaJIT, did not properly enforce Lua sandbox restrictions. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-40959) It was discovered that Luanti did not properly restrict access to insecure environments. An attacker could possibly use this issue to obtain unintended access to the insecure environment or HTTP API. (CVE-2026-40960)

USN-8365-1: Dovecot vulnerabilities

6 days 17 hours ago
It was discovered that Dovecot incorrectly treated some variable expansion pipelines as safe in authentication filters. An attacker could possibly use this issue to perform SQL or LDAP injection attacks. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-27851) It was discovered that Dovecot incorrectly verified SCRAM TLS channel binding in certain base64 exchanges. A remote attacker could possibly use this issue to obtain sensitive information in a machine-in-the-middle attack. (CVE-2026-33603) It was discovered that Dovecot incorrectly enforced Sieve script CPU limits. An attacker could possibly use this issue to cause Dovecot to use excessive resources, leading to a denial of service. (CVE-2026-40016) It was discovered that Dovecot incorrectly handled certain IMAP SETACL commands. An attacker could possibly use this issue to spam folders to other users. (CVE-2026-40020) It was discovered that Dovecot incorrectly handled excessive IMAP bracing. An attacker could possibly use this issue to cause Dovecot to use excessive resources, leading to a denial of service. (CVE-2026-42006)

USN-8363-1: MySQL vulnerabilities

6 days 17 hours ago
Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.46 in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. Ubuntu 25.10 and Ubuntu 26.04 LTS have been updated to MySQL 8.4.9. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-9.html https://www.oracle.com/security-alerts/cpuapr2026.html

USN-8362-1: XZ Utils vulnerability

6 days 20 hours ago
It was discovered that XZ Utils did not properly manage memory when attempting to append data to a decoded index that contained no records. An attacker could possibly use this issue to cause XZ Utils to crash, resulting in a denial of service, or execute arbitrary code.

xorg-x11-server-Xwayland-24.1.12-1.fc43

1 week ago
FEDORA-2026-557e726e74 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.12-1.fc43
Update description:

Update to xwayland 24.1.12, Security fixes for: ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

xorg-x11-server-21.1.23-1.fc43

1 week ago
FEDORA-2026-c3ea7d7b0e Packages in this update:
  • xorg-x11-server-21.1.23-1.fc43
Update description:

Update to xserver 21.1.23, Security fixes for: ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

xorg-x11-server-21.1.23-1.fc44

1 week ago
FEDORA-2026-7e38f57cef Packages in this update:
  • xorg-x11-server-21.1.23-1.fc44
Update description:

Update to xserver 21.1.23, security fixes for: ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

xorg-x11-server-Xwayland-24.1.12-1.fc44

1 week ago
FEDORA-2026-f98eff99c4 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.12-1.fc44
Update description:

Update to xwayland 24.1.12, security fixes for ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

USN-8209-2: Little CMS vulnerability

1 week ago
USN-8209-1 fixed vulnerabilities in Little CMS. This update contains the fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Little CMS incorrectly handled certain malformed ICC profiles. An attacker could use this issue to cause Little CMS to crash, resulting in a denial of service, or possibly execute arbitrary code.