<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Sun, 27 Sep 2026 18:21:02 +0000</lastBuildDate><item><title>USN-8729-5: Linux kernel (AWS FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8729-5</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM32 architecture;
  - ARM64 architecture;
  - PowerPC architecture;
  - Compute Acceleration Framework;
  - Drivers core;
  - Bluetooth drivers;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - EFI core;
  - GPU drivers;
  - Hardware monitoring drivers;
  - InfiniBand drivers;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - SCSI subsystem;
  - SPI subsystem;
  - Network file systems library;
  - NTFS3 file system;
  - SMB network file system;
  - File systems infrastructure;
  - Software nodes and device properties;
  - Bluetooth subsystem;
  - Netfilter;
  - Tracing infrastructure;
  - io_uring subsystem;
  - IRQ subsystem;
  - KProbes tracing;
  - Memory management;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - Networking core;
  - IPv4 networking;
  - IPv6 networking;
  - Multipath TCP;
  - Phonet protocol;
  - SMC sockets;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - Key management;
  - Linux Security Modules (LSM) Framework;
  - ALSA framework;
  - AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055,
CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096,
CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103,
CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126,
CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134,
CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138,
CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180,
CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64518)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8729-5</guid><pubDate>Fri, 25 Sep 2026 11:35:38 +0000</pubDate></item><item><title>USN-8819-2: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8819-2</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8819-2</guid><pubDate>Fri, 25 Sep 2026 11:35:37 +0000</pubDate></item><item><title>USN-8818-2: Linux kernel (IBM) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8818-2</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8818-2</guid><pubDate>Fri, 25 Sep 2026 11:35:37 +0000</pubDate></item><item><title>USN-8730-6: Linux kernel (Intel IoTG) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8730-6</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - IPv6 networking;
  - Netfilter;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8730-6</guid><pubDate>Fri, 25 Sep 2026 11:35:37 +0000</pubDate></item><item><title>USN-8824-1: libpcap vulnerability</title><link>https://ubuntu.com/security/notices/USN-8824-1</link><description>It was discovered that libpcap did not properly validate BPF instructions
in some situation. An attacker could possibly use this issue to perform out
of bound memory operations.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8824-1</guid><pubDate>Fri, 25 Sep 2026 08:50:02 +0000</pubDate></item><item><title>USN-8820-1: curl vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8820-1</link><description>Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)

Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)

Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
possibly use this issue to cause curl to crash, resulting in a denial of
service, or execute arbitrary code. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-80229)

Stanislav Fort discovered that curl did not properly enforce public key
pinning when certificate verification was disabled in certain
circumstances. A remote attacker could possibly use this issue to bypass
pinning checks and cause curl to accept connections that should have been
rejected. (CVE-2026-80230)

Stanislav Fort discovered that curl incorrectly handled the Secure
attribute of cookies in certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-80255)

Stanislav Fort discovered that curl did not properly enforce Public
Suffix List boundaries when handling cookies in certain circumstances. A
remote attacker could possibly use this issue to cause cookies to be sent
to unrelated domains, resulting in sensitive information being exposed.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-82209)

Ady Elouej discovered that curl did not clear proxy authentication state
between requests when reusing a handle with environment-variable proxy
configuration. A remote attacker could possibly use this issue to obtain
sensitive credentials. This issue was previously fixed in USN-8487-1, but
that fix was incomplete for Ubuntu 16.04 LTS. (CVE-2026-8927)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8820-1</guid><pubDate>Thu, 24 Sep 2026 20:13:19 +0000</pubDate></item><item><title>USN-8821-1: OpenStack Swift vulnerability</title><link>https://ubuntu.com/security/notices/USN-8821-1</link><description>It was discovered that OpenStack Swift incorrectly handled truncated
aws-chunked PUT request bodies in its s3api middleware. An authenticated
attacker could possibly use this issue to cause OpenStack Swift to use
excessive resources, leading to a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8821-1</guid><pubDate>Thu, 24 Sep 2026 19:18:41 +0000</pubDate></item><item><title>USN-8819-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8819-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8819-1</guid><pubDate>Thu, 24 Sep 2026 15:02:57 +0000</pubDate></item><item><title>USN-8818-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8818-1</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8818-1</guid><pubDate>Thu, 24 Sep 2026 15:02:22 +0000</pubDate></item><item><title>USN-8817-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8817-1</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - HSR network protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8817-1</guid><pubDate>Thu, 24 Sep 2026 15:01:17 +0000</pubDate></item></channel></rss>