<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 16 Sep 2026 22:23:08 +0000</lastBuildDate><item><title>USN-8776-1: python-cryptography vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8776-1</link><description>It was discovered that python-cryptography incorrectly accepted objects
with immutable buffers when performing certain cipher operations. This
would result in corrupted output, contrary to expectations. This issue only
affected Ubuntu 18.04 LTS. (CVE-2023-23931)

It was discovered that python-cryptography reported the outcome of
decrypting PKCS#7 enveloped data in distinguishable ways, and with
observable timing differences. A remote attacker could possibly use this
issue to recover the key used to encrypt the message contents, and obtain
sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-69247)

Jack Lloyd discovered that python-cryptography incorrectly handled wildcard
DNS names when enforcing the name constraints of a certificate authority. A
remote attacker could possibly use this issue to have an invalid
certificate chain accepted, and use names outside of the permitted ones.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)

Samuel Judson discovered that python-cryptography incorrectly handled
certificate chains that contained duplicate certificates. A remote attacker
could possibly use this issue to cause python-cryptography to use excessive
resources, leading to a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-69249)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8776-1</guid><pubDate>Wed, 16 Sep 2026 20:12:52 +0000</pubDate></item><item><title>USN-8774-1: libheif vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8774-1</link><description>Ali Firas discovered that libheif incorrectly handled certain images. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-62291)

Dmitrijs Trizna discovered that libheif incorrectly handled certain image
sequences. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-62377)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8774-1</guid><pubDate>Wed, 16 Sep 2026 16:36:02 +0000</pubDate></item><item><title>USN-8736-2: Perl vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8736-2</link><description>USN-8736-1 fixed vulnerabilities in Perl. This update provides the
corresponding fix for Perl on Ubuntu 24.04 LTS.

Original advisory details:

It was discovered that Perl incorrectly handled certain large inputs during
regular expression matching. An attacker could possibly use this issue to
trigger out-of-bounds heap reads or writes, resulting in a denial of
service or arbitrary code execution. (CVE-2026-15534)

It was discovered that Perl incorrectly handled certain regular expression
containing alternative matching branches. An attacker could  possibly use
this issue to cause incorrect regular expression matches, resulting in
security restrictions being bypassed. (CVE-2026-19487)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8736-2</guid><pubDate>Wed, 16 Sep 2026 14:37:44 +0000</pubDate></item><item><title>USN-8773-1: GNU Guix vulnerability</title><link>https://ubuntu.com/security/notices/USN-8773-1</link><description>It was discovered that GNU Guix incorrectly made build outputs accessible
to local users before their file metadata was finalized. A local attacker
could possibly use this issue to gain elevated privileges.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8773-1</guid><pubDate>Wed, 16 Sep 2026 11:33:38 +0000</pubDate></item><item><title>USN-8772-1: AOM vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8772-1</link><description>It was discovered that AOM incorrectly handled the first-pass statistics
buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use
this issue to cause a heap buffer overflow, leading to a denial of service
or possibly execute arbitrary code. (CVE-2026-56208)

It was discovered that AOM incorrectly validated spatial and temporal
layer IDs in the SVC (Scalable Video Coding) encoder controls. An attacker
could possibly use this issue to write to an arbitrary memory address, read
out-of-bounds heap memory, or execute arbitrary code. (CVE-2026-56209,
CVE-2026-56210, CVE-2026-56211)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8772-1</guid><pubDate>Wed, 16 Sep 2026 09:29:07 +0000</pubDate></item><item><title>USN-8514-2: OpenSSH vulnerability</title><link>https://ubuntu.com/security/notices/USN-8514-2</link><description>USN-8514-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.

Original advisory details:

 It was discovered that OpenSSH incorrectly handled file permissions when
 downloading files as root using the legacy scp protocol without the
 preserve-mode option. An attacker could use this to install setuid or setgid
 files on a system, possibly leading to privilege escalation.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8514-2</guid><pubDate>Wed, 16 Sep 2026 08:46:47 +0000</pubDate></item><item><title>USN-8770-1: SimpleSAMLphp vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8770-1</link><description>It was discovered that SimpleSAMLphp incorrectly validated cryptographic
signatures in XML messages. An authenticated attacker could possibly use
this issue to impersonate users or gain elevated privileges. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)

It was discovered that SimpleSAMLphp incorrectly handled external entities
when parsing untrusted XML documents. A remote attacker could possibly use
this issue to obtain sensitive information. This issue did not affect
Ubuntu 24.04 LTS. (CVE-2024-52596)

It was discovered that SimpleSAMLphp incorrectly verified signatures in
SAML messages using the HTTP-Redirect binding. A remote attacker could
possibly use this issue to bypass authentication and impersonate users.
(CVE-2025-27773)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8770-1</guid><pubDate>Tue, 15 Sep 2026 16:16:00 +0000</pubDate></item><item><title>USN-8769-1: phpseclib vulnerability</title><link>https://ubuntu.com/security/notices/USN-8769-1</link><description>It was discovered that phpseclib did not perform padding validation in
constant time when using AES in CBC mode. A remote attacker could possibly
use this issue to conduct a padding oracle timing attack and obtain
sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8769-1</guid><pubDate>Tue, 15 Sep 2026 15:59:40 +0000</pubDate></item><item><title>USN-8768-1: Shibboleth vulnerability</title><link>https://ubuntu.com/security/notices/USN-8768-1</link><description>Florian Stuhlmann discovered that Shibboleth incorrectly escaped input
when using the ODBC storage plugin. A remote attacker could possibly use
this issue to perform SQL injection attacks and obtain sensitive
information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8768-1</guid><pubDate>Tue, 15 Sep 2026 15:43:58 +0000</pubDate></item><item><title>USN-8767-1: Snapcast vulnerability</title><link>https://ubuntu.com/security/notices/USN-8767-1</link><description>It was discovered that Snapcast incorrectly handled crafted JSON-RPC
requests. A remote attacker could possibly use this issue to execute
arbitrary code or obtain sensitive information.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8767-1</guid><pubDate>Tue, 15 Sep 2026 15:22:17 +0000</pubDate></item></channel></rss>