<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_ubuntu</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:36:21 +0000</lastBuildDate>
    <item>
      <title>USN-8864-1 — linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8864-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-kvm, Ubuntu:Pro:FIPS:16.04:LTS: linux-fips&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-kvm, Ubuntu:Pro:FIPS:16.04:LTS: linux-fips&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8864-1</guid>
      <pubDate>Fri, 02 Oct 2026 07:04:46 +0000</pubDate>
    </item>
    <item>
      <title>USN-8816-4 — linux-gke vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8816-4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: linux-gke&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - DRBD Distributed Replicated Block Device drivers;
  - InfiniBand drivers;
  - IOMMU subsystem;
  - Multiple devices driver;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NVME drivers;
  - TCM subsystem;
  - Virtio Host (VHOST) subsystem;
  - Xen hypervisor drivers;
  - AFS file system;
  - File systems infrastructure;
  - Network file systems library;
  - Network file system (NFS) client;
  - NTFS3 file system;
  - OCFS2 file system;
  - OrangeFS file system;
  - SMB network file system;
  - IPv4 networking;
  - Sun RPC protocol;
  - IPv6 networking;
  - IP tunnels definitions;
  - Netfilter;
  - TCP network protocol;
  - Locking primitives;
  - 9P file system network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - Networking core;
  - IFE protocol;
  - RxRPC session sockets;
  - Network traffic control;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
  - XFRM subsystem;
(CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541,
CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476,
CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033,
CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065,
CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085,
CVE…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: linux-gke&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - DRBD Distributed Replicated Block Device drivers;
  - InfiniBand drivers;
  - IOMMU subsystem;
  - Multiple devices driver;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NVME drivers;
  - TCM subsystem;
  - Virtio Host (VHOST) subsystem;
  - Xen hypervisor drivers;
  - AFS file system;
  - File systems infrastructure;
  - Network file systems library;
  - Network file system (NFS) client;
  - NTFS3 file system;
  - OCFS2 file system;
  - OrangeFS file system;
  - SMB network file system;
  - IPv4 networking;
  - Sun RPC protocol;
  - IPv6 networking;
  - IP tunnels definitions;
  - Netfilter;
  - TCP network protocol;
  - Locking primitives;
  - 9P file system network protocol;
  - B.A.T.M.A.N. meshing protocol;
  - Networking core;
  - IFE protocol;
  - RxRPC session sockets;
  - Network traffic control;
  - SCTP protocol;
  - SMC sockets;
  - TIPC protocol;
  - XFRM subsystem;
(CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541,
CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476,
CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033,
CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065,
CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085,
CVE…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8816-4</guid>
      <pubDate>Fri, 02 Oct 2026 06:30:38 +0000</pubDate>
    </item>
    <item>
      <title>USN-8818-6 — linux-fips vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8818-6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS-updates:22.04:LTS: linux-fips&lt;/p&gt;
&lt;p&gt;It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS-updates:22.04:LTS: linux-fips&lt;/p&gt;
&lt;p&gt;It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8818-6</guid>
      <pubDate>Fri, 02 Oct 2026 06:30:36 +0000</pubDate>
    </item>
    <item>
      <title>USN-8851-2 — linux-raspi-5.4 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8851-2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: linux-raspi-5.4&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: linux-raspi-5.4&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8851-2</guid>
      <pubDate>Fri, 02 Oct 2026 06:30:35 +0000</pubDate>
    </item>
    <item>
      <title>USN-8863-1 — gst-plugins-good1.0 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8863-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:18.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:20.04:LTS: gst-plugins-good1.0, Ubuntu:22.04:LTS: gst-plugins-good1.0, Ubuntu:24.04:LTS: gst-plugins-good1.0, Ubuntu:26.04:LTS: gst-plugins-good1.0&lt;/p&gt;
&lt;p&gt;Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled
certain FLAC audio streams. An attacker could possibly use this issue to
obtain sensitive information. (CVE-2026-17072)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed
certain AVI files. An attacker could possibly use this issue to cause a
denial of service or obtain sensitive information. (CVE-2026-73433)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse
certain AVI files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-73434)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled
certain closed caption data. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88914)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:18.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:20.04:LTS: gst-plugins-good1.0, Ubuntu:22.04:LTS: gst-plugins-good1.0, Ubuntu:24.04:LTS: gst-plugins-good1.0, Ubuntu:26.04:LTS: gst-plugins-good1.0&lt;/p&gt;
&lt;p&gt;Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled
certain FLAC audio streams. An attacker could possibly use this issue to
obtain sensitive information. (CVE-2026-17072)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed
certain AVI files. An attacker could possibly use this issue to cause a
denial of service or obtain sensitive information. (CVE-2026-73433)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse
certain AVI files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-73434)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled
certain closed caption data. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88914)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8863-1</guid>
      <pubDate>Thu, 01 Oct 2026 16:46:33 +0000</pubDate>
    </item>
    <item>
      <title>USN-8862-1 — libxpm vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8862-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: libxpm, Ubuntu:24.04:LTS: libxpm, Ubuntu:26.04:LTS: libxpm&lt;/p&gt;
&lt;p&gt;It was discovered that libXpm did not correctly handle XPM images with
zero-dimension values. A local attacker could possibly use this issue to
cause libXpm to use excessive resources, leading to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: libxpm, Ubuntu:24.04:LTS: libxpm, Ubuntu:26.04:LTS: libxpm&lt;/p&gt;
&lt;p&gt;It was discovered that libXpm did not correctly handle XPM images with
zero-dimension values. A local attacker could possibly use this issue to
cause libXpm to use excessive resources, leading to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8862-1</guid>
      <pubDate>Thu, 01 Oct 2026 12:51:01 +0000</pubDate>
    </item>
    <item>
      <title>USN-8861-1 — openssl vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8861-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;It was discovered that OpenSSL had an inefficient algorithm in its QUIC
stream reassembly implementation. A remote attacker could possibly use this
issue to cause OpenSSL to use excessive CPU resources, leading to a denial
of service. (CVE-2026-42772)&lt;/p&gt;
&lt;p&gt;It was discovered that OpenSSL did not properly limit memory allocated for
QUIC packet buffers. A remote attacker could possibly use this issue to
cause OpenSSL to use excessive memory resources, leading to a denial of
service. (CVE-2026-54873)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;It was discovered that OpenSSL had an inefficient algorithm in its QUIC
stream reassembly implementation. A remote attacker could possibly use this
issue to cause OpenSSL to use excessive CPU resources, leading to a denial
of service. (CVE-2026-42772)&lt;/p&gt;
&lt;p&gt;It was discovered that OpenSSL did not properly limit memory allocated for
QUIC packet buffers. A remote attacker could possibly use this issue to
cause OpenSSL to use excessive memory resources, leading to a denial of
service. (CVE-2026-54873)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8861-1</guid>
      <pubDate>Thu, 01 Oct 2026 12:02:00 +0000</pubDate>
    </item>
    <item>
      <title>USN-8860-1 — designate vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8860-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: designate, Ubuntu:Pro:18.04:LTS: designate, Ubuntu:Pro:20.04:LTS: designate, Ubuntu:22.04:LTS: designate, Ubuntu:24.04:LTS: designate, Ubuntu:26.04:LTS: designate&lt;/p&gt;
&lt;p&gt;It was discovered that OpenStack Designate did not properly validate
overlapping zones under certain circumstances. An authenticated user could
possibly use this issue to redirect DNS traffic to attacker-controlled
systems or cause a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: designate, Ubuntu:Pro:18.04:LTS: designate, Ubuntu:Pro:20.04:LTS: designate, Ubuntu:22.04:LTS: designate, Ubuntu:24.04:LTS: designate, Ubuntu:26.04:LTS: designate&lt;/p&gt;
&lt;p&gt;It was discovered that OpenStack Designate did not properly validate
overlapping zones under certain circumstances. An authenticated user could
possibly use this issue to redirect DNS traffic to attacker-controlled
systems or cause a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8860-1</guid>
      <pubDate>Thu, 01 Oct 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>USN-8857-1 — kf6-kcoreaddons vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8857-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: kf6-kcoreaddons&lt;/p&gt;
&lt;p&gt;It was discovered that KCoreAddons incorrectly handled shell argument
quoting in KShell::quoteArgs. The parsing did not adequately handle shell
metacharacters, which could lead to a shell escape. An attacker could
possibly use this issue to execute arbitrary commands in applications that
relied on this method to handle user input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: kf6-kcoreaddons&lt;/p&gt;
&lt;p&gt;It was discovered that KCoreAddons incorrectly handled shell argument
quoting in KShell::quoteArgs. The parsing did not adequately handle shell
metacharacters, which could lead to a shell escape. An attacker could
possibly use this issue to execute arbitrary commands in applications that
relied on this method to handle user input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8857-1</guid>
      <pubDate>Thu, 01 Oct 2026 10:48:57 +0000</pubDate>
    </item>
    <item>
      <title>USN-8858-1 — libauthen-sasl-perl vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8858-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:16.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:18.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:20.04:LTS: libauthen-sasl-perl, Ubuntu:22.04:LTS: libauthen-sasl-perl, Ubuntu:24.04:LTS: libauthen-sasl-perl, Ubuntu:26.04:LTS: libauthen-sasl-perl&lt;/p&gt;
&lt;p&gt;It was discovered that Authen::SASL, a Perl authentication library, did
not properly validate login attempts. An attacker could possibly use
this issue to gain unauthorized access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:16.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:18.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:20.04:LTS: libauthen-sasl-perl, Ubuntu:22.04:LTS: libauthen-sasl-perl, Ubuntu:24.04:LTS: libauthen-sasl-perl, Ubuntu:26.04:LTS: libauthen-sasl-perl&lt;/p&gt;
&lt;p&gt;It was discovered that Authen::SASL, a Perl authentication library, did
not properly validate login attempts. An attacker could possibly use
this issue to gain unauthorized access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8858-1</guid>
      <pubDate>Wed, 30 Sep 2026 16:40:43 +0000</pubDate>
    </item>
  </channel>
</rss>
