<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Tue, 16 Jun 2026 19:56:25 +0000</lastBuildDate><item><title>USN-8437-1: rabbitmq-c vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8437-1</link><description>It was discovered that rabbitmq-c exposed credentials in command-line
arguments under certain circumstances. A local attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2023-35789)

It was discovered that rabbitmq-c incorrectly handled AMQP frame lengths
under certain circumstances, which could lead to an out-of-bounds read. A
remote attacker could possibly use this issue to cause rabbitmq-c to crash,
resulting in a denial of service. (CVE-2026-44235)

It was discovered that rabbitmq-c incorrectly handled AMQP login handshakes
under certain circumstances, which could lead to a heap buffer overflow. A
remote attacker could possibly use this issue to cause rabbitmq-c to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2026-44236)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8437-1</guid><pubDate>Tue, 16 Jun 2026 14:48:17 +0000</pubDate></item><item><title>USN-8433-1: OpenStack Keystone vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8433-1</link><description>It was discovered that OpenStack Keystone allowed restricted application
credentials to create EC2 credentials. An authenticated attacker with only
a reader role could possibly use this issue to bypass the role restrictions
imposed on the application credential. (CVE-2026-33551)

It was discovered that the OpenStack Keystone LDAP identity backend did
not correctly convert the user enabled attribute to a boolean value.
An attacker could possibly use this issue to authenticate as a user disabled
in LDAP. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2026-40683)

It was discovered that OpenStack Keystone's application credential
authentication plugin did not verify that the user supplied in an
authentication request matched the credential owner. An authenticated
attacker could possibly impersonate another user and gain access to their
tokens and credentials. (CVE-2026-42998)

It was discovered that OpenStack Keystone's RBAC policy enforcer
unconditionally merged the raw JSON request body into the policy enforcement
dictionary, overwriting trusted target data. An authenticated attacker could
possibly use this issue to inject arbitrary policy attributes to bypass RBAC
checks. (CVE-2026-42999)

It was discovered that OpenStack Keystone allowed an attacker with the member
role to escalate privileges to admin by chaining application credential
impersonation with Keystone trusts. An attacker could possibly use this
issue to create a persistent trust delegating the victim's admin role to
themselves. (CVE-2026-43000)

It was discovered that OpenStack Keystone did not validate that the project_id
for an EC2 credential matched the project of the authenticating application
credential. An attacker with valid credentials for one project could possibly
use this issue to create EC2 credentials targeting a different project.
(CVE-2026-43001)

It was discovered that OpenStack Keystone's federated token rescoping mechanism
did not propagate the original token's expiry to the newly issued token. A
remote attacker could possibly use this issue to maintain access indefinitely by
repeatedly rescoping tokens before expiry. (CVE-2026-44394)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8433-1</guid><pubDate>Tue, 16 Jun 2026 13:45:21 +0000</pubDate></item><item><title>USN-8432-1: FreeRDP vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8432-1</link><description>It was discovered that FreeRDP incorrectly handled memory under certain
circumstances, which could lead to an out-of-bounds heap write. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-45700)

In addition, this update fixes a regression introduced in USN-8105-1.
The update introduces a complete fix for CVE-2026-22858, CVE-2026-23732
and CVE-2026-25952 in Ubuntu 24.04 LTS and Ubuntu 25.10.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8432-1</guid><pubDate>Tue, 16 Jun 2026 08:41:44 +0000</pubDate></item><item><title>USN-8349-3: rsync regression</title><link>https://ubuntu.com/security/notices/USN-8349-3</link><description>USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 Calum Hutton discovered that rsync contained a heap-based out-of-bounds
 read when handling file transfers. A remote attacker with read access
 to an rsync server could possibly use this issue to cause a denial of
 service. (CVE-2025-10158)

 Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
 rsync daemons configured without chroot protection were exposed to a
 race condition on parent path components. A local attacker with write
 access to a module could possibly use this issue to overwrite files,
 obtain sensitive information, or escalate privileges.
 (CVE-2026-29518)

 It was discovered that rsync did not properly validate a length value
 while sorting extended attributes. An attacker could possibly use this
 issue to cause a denial of service. (CVE-2026-41035)

 It was discovered that rsync performed reverse-DNS lookups after
 chrooting in some daemon configurations. A remote attacker could
 possibly use this issue to bypass hostname-based access controls and
 access network services. (CVE-2026-43617)

 Omar Elsayed discovered that rsync did not properly check for integer
 overflows while decoding compressed tokens. A remote attacker could
 possibly use this issue to obtain sensitive information.
 (CVE-2026-43618)

 Andrew Tridgell discovered that rsync did not fully fix a symlink race
 condition in path-based system calls for daemons configured without
 chroot protection. A local attacker could possibly use this issue to
 overwrite files, obtain sensitive information, or escalate privileges.
 (CVE-2026-43619)

 Pratham Gupta discovered that rsync did not properly validate an index
 while processing file lists. A remote attacker could possibly use this
 issue to cause rsync to crash, resulting in a denial of service.
 (CVE-2026-43620)

 Michal Ruprich discovered that rsync contained an off-by-one error
 while handling HTTP proxy responses. An attacker able to intercept network
 communications or a malicious proxy server could possibly use this issue to
 cause a denial of service. (CVE-2026-45232)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8349-3</guid><pubDate>Tue, 16 Jun 2026 07:31:50 +0000</pubDate></item><item><title>USN-8431-1: Ruby vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8431-1</link><description>It was discovered that Ruby's Net::IMAP library did not properly verify
that Transport Layer Security (TLS) encryption was started after issuing a STARTTLS command. A remote
attacker could possibly use this issue to perform a machine-in-the-middle attack and silently
bypass TLS encryption. (CVE-2026-42246)

It was also discovered that Ruby's Net::IMAP library did not validate
string arguments passed to certain commands. A remote attacker could possibly use this issue to
inject arbitrary IMAP commands. (CVE-2026-42257)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8431-1</guid><pubDate>Mon, 15 Jun 2026 17:24:17 +0000</pubDate></item><item><title>USN-8430-1: ADSys vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8430-1</link><description>It was discovered that ADSys did not properly handle certain HTTP/2 frames.
A remote attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-27141)

It was discovered that ADSys did not properly handle certain HTTP/2
SETTINGS frames. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-33814)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8430-1</guid><pubDate>Mon, 15 Jun 2026 16:19:26 +0000</pubDate></item><item><title>USN-8428-1: tmux vulnerability</title><link>https://ubuntu.com/security/notices/USN-8428-1</link><description>It was discovered that tmux incorrectly handled image cleanup, leading to
a use-after-free vulnerability. A local attacker could possibly use this
issue to cause tmux to crash, resulting in a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8428-1</guid><pubDate>Mon, 15 Jun 2026 13:03:51 +0000</pubDate></item><item><title>USN-8398-3: nginx vulnerability</title><link>https://ubuntu.com/security/notices/USN-8398-3</link><description>USN-8398-1 fixed a vulnerability in nginx. The update caused a regression
and was temporarily reverted in USN-8398-2. This update introduces a
complete fix for CVE-2026-49975.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that nginx incorrectly handled certain cookie headers in
 the HTTP/2 implementation. A remote attacker could possibly use this issue
 to cause nginx to consume excessive resources, resulting in a denial of
 service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8398-3</guid><pubDate>Mon, 15 Jun 2026 12:44:22 +0000</pubDate></item><item><title>USN-8405-2: CUPS regression</title><link>https://ubuntu.com/security/notices/USN-8405-2</link><description>USN-8405-1 fixed vulnerabilities in CUPS. The update introduced a
regression that cause CUPS to crash when parsing certain large printer PPD
files. This update fixes the problem.

Original advisory details:

 Ariel Silver discovered that CUPS incorrectly handled username comparisons
 during authorization checks. A local attacker could possibly use this issue
 to gain unauthorized access to restricted operations. (CVE-2026-27447)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 notify-recipient-uri values in the RSS notifier. A remote attacker could
 possibly use this issue to overwrite lp-writable files and cause a denial
 of service. (CVE-2026-34978)

 Jacob Newman discovered that CUPS incorrectly handled filter option strings
 when processing job attributes. An attacker could use this issue to cause
 CUPS to crash, resulting in a denial of service, or possibly execute
 arbitrary code. (CVE-2026-34979)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 page-border values in shared PostScript queues. A remote attacker could
 possibly use this issue to execute arbitrary code. (CVE-2026-34980)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 localhost authentication to attacker-controlled IPP services. A local
 attacker could possibly use this issue to overwrite arbitrary files
 and execute arbitrary code. (CVE-2026-34990)

 Tomer Fichman discovered that CUPS incorrectly handled negative
 job-password-supported values. A local attacker could possibly use this
 issue to cause CUPS to crash, resulting in a denial of service.
 (CVE-2026-39314)

 Tomer Fichman discovered that CUPS incorrectly handled temporary printer
 deletion. An attacker could possibly use this issue to cause CUPS to crash,
 resulting in a denial of service, or to execute arbitrary code.
 (CVE-2026-39316)

 Tomer Fichman discovered that CUPS incorrectly handled certain malformed
 SNMP responses. An attacker could possibly use this issue to obtain
 sensitive information. (CVE-2026-41079)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8405-2</guid><pubDate>Mon, 15 Jun 2026 12:12:13 +0000</pubDate></item><item><title>USN-8427-1: Mesa vulnerability</title><link>https://ubuntu.com/security/notices/USN-8427-1</link><description>It was discovered that Mesa did not properly validate memory allocation
sizes in WebGPU under certain circumstances. An attacker could use this
issue to cause Mesa to crash, resulting in a denial of service, or possibly
execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8427-1</guid><pubDate>Mon, 15 Jun 2026 12:01:35 +0000</pubDate></item></channel></rss>