<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Tue, 09 Jun 2026 13:10:06 +0000</lastBuildDate><item><title>USN-8044-2: alsa-lib vulnerability</title><link>https://ubuntu.com/security/notices/USN-8044-2</link><description>USN-8044-1 fixed a vulnerability in alsa-lib. This update provides the
corresponding fix for alsa-lib on Ubuntu 20.04 LTS.

Original advisory details:

 It was discovered that alsa-lib incorrectly handled the topology mixer
 control decoder. A local attacker could use a specially crafted topology
 file to cause alsa-lib to crash, resulting in a denial of service, or
 possibly execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8044-2</guid><pubDate>Tue, 09 Jun 2026 09:23:55 +0000</pubDate></item><item><title>USN-8410-1: shell-quote vulnerability</title><link>https://ubuntu.com/security/notices/USN-8410-1</link><description>Akshat Sinha discovered that shell-quote improperly validated object-token
inputs. An attacker could possibly use this issue to cause shell-quote to
crash, resulting in a denial of service, or execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8410-1</guid><pubDate>Tue, 09 Jun 2026 08:38:23 +0000</pubDate></item><item><title>USN-8408-1: Twig vulnerability</title><link>https://ubuntu.com/security/notices/USN-8408-1</link><description>It was discovered that Twig did not properly validate PHP callables when
using a source policy. An authenticated user could possibly use this issue
to execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8408-1</guid><pubDate>Mon, 08 Jun 2026 19:36:58 +0000</pubDate></item><item><title>USN-8407-1: strongSwan vulnerability</title><link>https://ubuntu.com/security/notices/USN-8407-1</link><description>Elliott Childre discovered that strongSwan incorrectly handled the cloning
of certain identities. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8407-1</guid><pubDate>Mon, 08 Jun 2026 17:28:38 +0000</pubDate></item><item><title>USN-8349-2: rsync regression</title><link>https://ubuntu.com/security/notices/USN-8349-2</link><description>USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.

Original advisory details:

 Calum Hutton discovered that rsync contained a heap-based out-of-bounds
 read when handling file transfers. A remote attacker with read access
 to an rsync server could possibly use this issue to cause a denial of
 service. (CVE-2025-10158)

 Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
 rsync daemons configured without chroot protection were exposed to a
 race condition on parent path components. A local attacker with write
 access to a module could possibly use this issue to overwrite files,
 obtain sensitive information, or escalate privileges.
 (CVE-2026-29518)

 It was discovered that rsync did not properly validate a length value
 while sorting extended attributes. An attacker could possibly use this
 issue to cause a denial of service. (CVE-2026-41035)

 It was discovered that rsync performed reverse-DNS lookups after
 chrooting in some daemon configurations. A remote attacker could
 possibly use this issue to bypass hostname-based access controls and
 access network services. (CVE-2026-43617)

 Omar Elsayed discovered that rsync did not properly check for integer
 overflows while decoding compressed tokens. A remote attacker could
 possibly use this issue to obtain sensitive information.
 (CVE-2026-43618)

 Andrew Tridgell discovered that rsync did not fully fix a symlink race
 condition in path-based system calls for daemons configured without
 chroot protection. A local attacker could possibly use this issue to
 overwrite files, obtain sensitive information, or escalate privileges.
 (CVE-2026-43619)

 Pratham Gupta discovered that rsync did not properly validate an index
 while processing file lists. A remote attacker could possibly use this
 issue to cause rsync to crash, resulting in a denial of service.
 (CVE-2026-43620)

 Michal Ruprich discovered that rsync contained an off-by-one error
 while handling HTTP proxy responses. An attacker able to intercept network
 communications or a malicious proxy server could possibly use this issue to
 cause a denial of service. (CVE-2026-45232)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8349-2</guid><pubDate>Mon, 08 Jun 2026 16:41:09 +0000</pubDate></item><item><title>USN-8406-1: Net::CIDR::Lite vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8406-1</link><description>Dave Rolsky discovered that Net::CIDR::Lite did not properly handle
extraneous zero characters at the beginning of an IP address string. A
remote attacker could possibly use this issue to bypass access controls
that are based on IP addresses. This issue only affected Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2021-47154)

It was discovered that Net::CIDR::Lite did not properly validate the IPv6
group count when handling uncompressed IPv6 addresses. A remote attacker
could possibly use this issue to bypass access controls. (CVE-2026-40198)

It was discovered that Net::CIDR::Lite mishandled IPv4 mapped IPv6
addresses. A remote attacker could possibly use this issue to bypass access
controls that are based on IP addresses. (CVE-2026-40199)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8406-1</guid><pubDate>Mon, 08 Jun 2026 16:06:45 +0000</pubDate></item><item><title>USN-8405-1: CUPS vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8405-1</link><description>Ariel Silver discovered that CUPS incorrectly handled username comparisons
during authorization checks. A local attacker could possibly use this issue
to gain unauthorized access to restricted operations. (CVE-2026-27447)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
notify-recipient-uri values in the RSS notifier. A remote attacker could
possibly use this issue to overwrite lp-writable files and cause a denial
of service. (CVE-2026-34978)

Jacob Newman discovered that CUPS incorrectly handled filter option strings
when processing job attributes. An attacker could use this issue to cause
CUPS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2026-34979)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
page-border values in shared PostScript queues. A remote attacker could
possibly use this issue to execute arbitrary code. (CVE-2026-34980)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
localhost authentication to attacker-controlled IPP services. A local
attacker could possibly use this issue to overwrite arbitrary files
and execute arbitrary code. (CVE-2026-34990)

Tomer Fichman discovered that CUPS incorrectly handled negative
job-password-supported values. A local attacker could possibly use this
issue to cause CUPS to crash, resulting in a denial of service.
(CVE-2026-39314)

Tomer Fichman discovered that CUPS incorrectly handled temporary printer
deletion. An attacker could possibly use this issue to cause CUPS to crash,
resulting in a denial of service, or to execute arbitrary code.
(CVE-2026-39316)

Tomer Fichman discovered that CUPS incorrectly handled certain malformed
SNMP responses. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2026-41079)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8405-1</guid><pubDate>Mon, 08 Jun 2026 15:51:32 +0000</pubDate></item><item><title>USN-8404-1: Transmission vulnerability</title><link>https://ubuntu.com/security/notices/USN-8404-1</link><description>It was discovered that Transmission had a clickjacking weakness in the
browser-facing WebUI and RPC response paths. An attacker could possibly use
this issue to trick users into performing unintended actions.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8404-1</guid><pubDate>Mon, 08 Jun 2026 15:15:55 +0000</pubDate></item><item><title>USN-8403-1: Kea DHCP vulnerability</title><link>https://ubuntu.com/security/notices/USN-8403-1</link><description>Ali Norouzi discovered that Kea DHCP did not properly handle maliciously
crafted messages over configured API sockets and HA listeners. A remote
attacker could possibly use this issue to cause Kea DHCP to crash,
resulting in a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8403-1</guid><pubDate>Mon, 08 Jun 2026 14:28:06 +0000</pubDate></item><item><title>USN-8401-1: Netty vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8401-1</link><description>It was discovered that Netty's HTTP proxy handler did not properly
validate headers when constructing CONNECT requests. An
attacker could possibly use this issue to inject arbitrary HTTP
headers into CONNECT requests. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 26.04 LTS. (CVE-2026-42578)

It was discovered that Netty's DNS codec did not properly enforce
domain name constraints. An attacker could possibly use this issue to
bypass domain name validation, or cause Netty to consume resources,
leading to a denial of service. This issue only affected Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-42579)

It was discovered that Netty did not correctly handle HTTP/1.0
requests containing both a Transfer-Encoding and Content-Length
header. A remote attacker could possibly use this issue to perform
HTTP request smuggling attacks. (CVE-2026-42581)

Violeta Georgieva discovered that Netty incorrectly paired responses with
requests when handling informational HTTP responses. A remote attacker
could possibly use this issue to perform HTTP request smuggling attacks.
(CVE-2026-42584)

Violeta Georgieva discovered that Netty incorrectly parsed malformed
Transfer-Encoding headers. A remote attacker could possibly use this
issue to perform HTTP request smuggling attacks. (CVE-2026-42585)

It was discovered that Netty's Redis encoder did not validate CRLF
characters. An attacker could possibly use this issue to inject arbitrary
Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-42586)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8401-1</guid><pubDate>Mon, 08 Jun 2026 13:38:28 +0000</pubDate></item></channel></rss>