<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Wed, 30 Sep 2026 13:09:05 +0000</lastBuildDate><item><title>USN-8851-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8851-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8851-1</guid><pubDate>Wed, 30 Sep 2026 09:53:51 +0000</pubDate></item><item><title>USN-8850-1: Linux kernel (BlueField) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8850-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - OCFS2 file system;
  - IPv6 networking;
  - Netfilter;
  - SCTP protocol;
(CVE-2025-38724, CVE-2026-53043, CVE-2026-53131, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8850-1</guid><pubDate>Wed, 30 Sep 2026 08:10:36 +0000</pubDate></item><item><title>USN-8849-1: Linux kernel (NVIDIA Tegra) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8849-1</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355,
CVE-2026-53398, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888,
CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984,
CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007,
CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8849-1</guid><pubDate>Wed, 30 Sep 2026 08:04:30 +0000</pubDate></item><item><title>USN-8818-4: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8818-4</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - exFAT file system;
  - Network file system (NFS) client;
  - Network file system (NFS) server daemon;
  - B.A.T.M.A.N. meshing protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8818-4</guid><pubDate>Wed, 30 Sep 2026 08:00:27 +0000</pubDate></item><item><title>USN-8817-2: Linux kernel (AWS FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8817-2</link><description>It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - InfiniBand drivers;
  - Network drivers;
  - TCM subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - HSR network protocol;
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8817-2</guid><pubDate>Wed, 30 Sep 2026 08:00:26 +0000</pubDate></item><item><title>USN-8730-7: Linux kernel (FIPS) vulnerability</title><link>https://ubuntu.com/security/notices/USN-8730-7</link><description>A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
  - IPv6 networking;
  - Netfilter;
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8730-7</guid><pubDate>Wed, 30 Sep 2026 08:00:26 +0000</pubDate></item><item><title>USN-8819-4: Linux kernel (FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8819-4</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Network file system (NFS) server daemon;
  - IPv6 networking;
  - Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8819-4</guid><pubDate>Wed, 30 Sep 2026 08:00:26 +0000</pubDate></item><item><title>USN-8847-2: OpenSSL vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8847-2</link><description>USN-8847-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

Original advisory details:

 It was discovered that OpenSSL incorrectly handled certain certificate
 revocation list distribution point names. An attacker could possibly use
 this issue to cause OpenSSL to consume excessive memory, resulting in a
 denial of service. (CVE-2026-35189)

 It was discovered that OpenSSL incorrectly implemented scalar
 multiplication for non-NIST elliptic curves. An attacker could possibly use
 this issue to perform a timing side-channel attack and obtain
 sensitive information. This issue only affected Ubuntu 18.04 LTS and
 Ubuntu 20.04 LTS. (CVE-2026-54872)

 It was discovered that OpenSSL incorrectly implemented SM2 signature
 generation. An attacker could possibly use this issue to perform a
 timing side-channel attack and obtain sensitive information. This issue
 only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-77696)

 It was discovered that OpenSSL incorrectly handled DTLS retransmission
 of handshake messages. An attacker could possibly use this issue to
 cause incorrect handshake behavior or a denial of service.
 (CVE-2026-84782)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8847-2</guid><pubDate>Tue, 29 Sep 2026 23:28:05 +0000</pubDate></item><item><title>USN-8847-1: OpenSSL vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8847-1</link><description>It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)

It was discovered that OpenSSL incorrectly handled QUIC unvalidated
amplification credit accounting. An attacker could possibly use this
issue to cause a denial of service. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-35191)

It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly
use this issue to perform a timing side-channel attack and obtain
sensitive information. (CVE-2026-54872)

It was discovered that OpenSSL incorrectly implemented SM2 scalar
multiplication on ARM64 and RISC-V architectures. An attacker could
possibly use this issue to perform a timing side-channel attack and
obtain sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-54875)

It was discovered that OpenSSL incorrectly handled SSL context switching
during a TLS handshake. An attacker could possibly use this issue to
cause an out-of-bounds read, resulting in a denial of service or
obtaining sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-72897)

It was discovered that OpenSSL incorrectly enforced QUIC connection-
level flow control for streams. An attacker could possibly use this
issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-75804)

It was discovered that OpenSSL incorrectly handled a NULL pointer in
CMP client revocation response processing. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-75805)

It was discovered that OpenSSL incorrectly handled undersized DTLS 1.2
AEAD records before authentication. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-75806)

It was discovered that OpenSSL incorrectly implemented SM2 signature
generation. An attacker could possibly use this issue to perform a
timing side-channel attack and obtain sensitive information.
(CVE-2026-77696)

It was discovered that OpenSSL incorrectly handled DTLS retransmission
of handshake messages. An attacker could possibly use this issue to
cause incorrect handshake behavior or a denial of service.
(CVE-2026-84782)

It was discovered that OpenSSL incorrectly handled QUIC
RETIRE_CONNECTION_ID frames. An attacker could possibly use this issue
to cause OpenSSL to consume excessive memory, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84784)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8847-1</guid><pubDate>Tue, 29 Sep 2026 18:19:43 +0000</pubDate></item><item><title>USN-8846-1: libheif vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8846-1</link><description>Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
compressed metadata. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 26.04 LTS. (CVE-2026-84384)

Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
HEIF sequence data. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-84446)

Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
image references. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-84447)

It was discovered that libheif incorrectly handled certain region masks.
A local attacker could possibly use this issue to obtain sensitive
information or cause a denial of service. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84448)

It was discovered that libheif incorrectly handled certain images. A
remote attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-84449)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8846-1</guid><pubDate>Tue, 29 Sep 2026 16:18:50 +0000</pubDate></item></channel></rss>