<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 22 Jul 2026 23:15:10 +0000</lastBuildDate><item><title>USN-8590-1: Exim vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8590-1</link><description>It was discovered that Exim incorrectly handled certain command line
options. A local attacker could possibly use this issue to access files
outside of the spool area.

It was discovered that Exim incorrectly handled string expansion in
.local files. A local attacker could possibly use this issue to escalate
privileges.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8590-1</guid><pubDate>Wed, 22 Jul 2026 16:57:48 +0000</pubDate></item><item><title>USN-8589-1: Apache HTTP Server vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8589-1</link><description>It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-29167)

It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)

Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module
was vulnerable to a timing attack. A remote attacker could possibly use
this issue to bypass Digest authentication. (CVE-2026-33006)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8589-1</guid><pubDate>Wed, 22 Jul 2026 16:41:46 +0000</pubDate></item><item><title>USN-8588-1: Gawk vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8588-1</link><description>It was discovered that Gawk incorrectly handled memory when processing
input using the getline redirection. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-40467)

It was discovered that Gawk incorrectly handled certain integer
calculations when allocating memory. An attacker could possibly use
this issue to cause a denial of service or overwrite heap memory with
attacker-controlled data. (CVE-2026-40468)

It was discovered that Gawk incorrectly handled certain integer
calculations when performing substitutions. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-40469)

It was discovered that Gawk incorrectly handled memory when reading
directory entries. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-40553)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8588-1</guid><pubDate>Wed, 22 Jul 2026 16:29:49 +0000</pubDate></item><item><title>USN-8477-3: tar regression</title><link>https://ubuntu.com/security/notices/USN-8477-3</link><description>USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could
cause tar to fail to extract old archives that recorded a nonzero size for
directory entries, resulting in a regression.
This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that tar incorrectly handled certain crafted archive files.
 An attacker could possibly use this to inject hidden files with
 attacker-controlled content, bypassing pre-extraction inspection mechanisms.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8477-3</guid><pubDate>Wed, 22 Jul 2026 15:03:31 +0000</pubDate></item><item><title>USN-8587-1: HTML-Parser vulnerability</title><link>https://ubuntu.com/security/notices/USN-8587-1</link><description>It was discovered that HTML-Parser incorrectly handled entity references
when the input string was identical to an entity value in the lookup table.
An attacker could possibly use this issue to obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8587-1</guid><pubDate>Wed, 22 Jul 2026 13:18:12 +0000</pubDate></item><item><title>USN-8586-1: libgphoto2 vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8586-1</link><description>It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing EOS image format data. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40333)

It was discovered that libgphoto2 did not properly null-terminate buffers
when parsing Canon folder entries. An attacker with physical access could
possibly use this issue to obtain sensitive information. (CVE-2026-40334)

It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing device property values. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40335)

It was discovered that libgphoto2 had a memory leak when parsing Sony
device property descriptors. An attacker with physical access could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-40336)

It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing Sony device property enumeration data. An attacker
with physical access could possibly use this issue to obtain sensitive
information. (CVE-2026-40338)

It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing Sony device property form flags. An attacker with
physical access could possibly use this issue to obtain sensitive
information. (CVE-2026-40339)

It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing object information. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40340)

It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing EOS focus information. An attacker with physical
access could possibly use this issue to cause libgphoto2 to crash,
resulting in a denial of service. (CVE-2026-40341)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8586-1</guid><pubDate>Wed, 22 Jul 2026 13:11:45 +0000</pubDate></item><item><title>USN-8585-1: Kerberos vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8585-1</link><description>It was discovered that Kerberos had an integer underflow vulnerability
in the berval2tl_data() function. An attacker could possibly use this issue
to cause Kerberos to crash, resulting in a denial of service.
(CVE-2026-11850)

It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism
parsing. A remote attacker could possibly use these issues to cause
Kerberos to crash, resulting in a denial of service. (CVE-2026-40355,
CVE-2026-40356)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8585-1</guid><pubDate>Wed, 22 Jul 2026 13:04:35 +0000</pubDate></item><item><title>USN-8584-1: GStreamer Good Plugins vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8584-1</link><description>It was discovered that GStreamer Good Plugins incorrectly handled certain
Matroska files. An attacker could possibly use this issue to cause
GStreamer Good Plugins to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39043)

It was discovered that GStreamer Good Plugins incorrectly handled certain
WAV files. An attacker could possibly use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39044)

It was discovered that GStreamer Good Plugins incorrectly handled certain
WavPack audio files. An attacker could use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-53705)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8584-1</guid><pubDate>Wed, 22 Jul 2026 12:52:28 +0000</pubDate></item><item><title>USN-8583-1: GIFLIB vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8583-1</link><description>It was discovered that GIFLIB incorrectly handled certain GIF image files.
If a user or automated system were tricked into opening a specially crafted
GIF file, a remote attacker could use this issue to cause GIFLIB to crash,
resulting in a denial of service, or possibly execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8583-1</guid><pubDate>Wed, 22 Jul 2026 12:42:04 +0000</pubDate></item><item><title>USN-8580-2: AccountsService vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8580-2</link><description>USN-8580-1 fixed vulnerabilities in AccountsService. This update provides
the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.

Original advisory details:

 It was discovered that the Ubuntu-specific SetLanguage patch to
 AccountsService incorrectly handled dropping privileges. A local attacker
 could use this issue to execute arbitrary commands as an administrator.
 (CVE-2026-61897)

 It was discovered that the Ubuntu-specific SetLanguage helpers for
 AccountsService incorrectly handled parsing configuration files. A local
 attacker could use this issue to execute arbitrary commands.
 (CVE-2026-61898)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8580-2</guid><pubDate>Tue, 21 Jul 2026 19:23:41 +0000</pubDate></item></channel></rss>