1.323.0
Notably, this release addresses:
USN-8543-1 Wget vulnerabilities:
- CVE-2026-58470: GNU Wget through 1.25.0, fixed in commit 43d3ba...
- CVE-2024-38428: url.c in GNU Wget through 1.24.5 mishandles sem...
- CVE-2026-58472: GNU Wget through 1.25.0, fixed in commit dd692d...
- CVE-2026-58469: GNU Wget through 1.25.0, fixed in commit 37a40f...
- CVE-2026-58471: GNU Wget through 1.25.0, fixed in commit c2640f...
USN-8541-1 Vim vulnerabilities:
- CVE-2026-59857: Vim is an open source, command line text editor...
- CVE-2026-59858: Vim is an open source, command line text editor...
- CVE-2026-59856: Vim is an open source, command line text editor...
USN-8533-1 OpenSSH vulnerabilities:
- CVE-2026-60001: sshd in OpenSSH before 10.4 does not always hon...
- CVE-2026-60002: ssh in OpenSSH before 10.4 can have a use-after...
- CVE-2026-59998: sshd in OpenSSH before 10.4 has an undocumented...
- CVE-2026-59997: internal-sftp in sshd in OpenSSH before 10.4 re...
- CVE-2026-59999: In sshd in OpenSSH before 10.4, DisableForwardi...
- CVE-2026-59995: sftp in OpenSSH before 10.4 does not properly c...
- CVE-2026-59996: scp in OpenSSH before 10.4 may place a file in ...
- CVE-2026-60000: sshd in OpenSSH before 10.4 allows remote attac...
USN-8531-1 libexif vulnerabilities:
- CVE-2026-40385: In libexif through 0.6.25, an unsigned 32bit in...
- CVE-2026-40386: In libexif through 0.6.25, an integer underflow...
- CVE-2026-32775: libexif through 0.6.25 has a flaw in decoding M...
USN-8512-1 Gzip vulnerabilities:
- CVE-2026-41992: GNU gzip contains a global buffer overflow vuln...
- CVE-2026-41991: GNU gzip contains a vulnerability in the gzexe ...
USN-8510-1 tar vulnerability:
-
CVE-2025-45582: GNU Tar through 1.35 allows file overwrite via ...
USN-8495-1 nghttp2 vulnerability:
- CVE-2026-58055: nghttp2's nghttpx proxy through 1.69.0 forwards...
USN-8493-1 Linux kernel vulnerabilities:
- CVE-2025-68214: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43414: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31682: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43304: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43501: In the Linux kernel, the following vulnerabilit...
- CVE-2025-71220: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23190: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23256: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31659: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31402: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43186: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43341: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23180: In the Linux kernel, the following vulnerabilit...
- CVE-2026-45988: In the Linux kernel, the following vulnerabilit...
- CVE-2025-71222: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23182: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23206: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23257: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31657: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23428: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43117: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23193: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46043: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31669: In the Linux kernel, the following vulnerabilit...
- CVE-2025-37822: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43406: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43071: In the Linux kernel, the following vulnerabilit...
- CVE-2025-71089: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31685: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43037: In the Linux kernel, the following vulnerabilit...
- CVE-2022-48816: In the Linux kernel, the following vulnerabilit...
- CVE-2025-37778: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31607: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31637: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43038: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46135: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23262: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46195: In the Linux kernel, the following vulnerabilit...
- CVE-2025-38201: In the Linux kernel, the following vulnerabilit...
- CVE-2023-53673: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23272: In the Linux kernel, the following vulnerabilit...
- CVE-2025-71224: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23216: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43407: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23258: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23455: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43114: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43493: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46243: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23278: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23450: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23176: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23198: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43011: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46119: In the Linux kernel, the following vulnerabilit...
- CVE-2025-37924: In the Linux kernel, the following vulnerabilit...
- CVE-2025-40082: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31649: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31478: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43383: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31668: In the Linux kernel, the following vulnerabilit...
- CVE-2025-68263: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23202: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31418: In the Linux kernel, the following vulnerabilit...
USN-8487-1 curl vulnerabilities:
- CVE-2026-8286: A vulnerability exists where a new transfer tha...
- CVE-2026-9080: Calling
curl_easy_pause()within the event-ba... - CVE-2026-8458: libcurl might in some circumstances reuse the w...
- CVE-2026-9545: In this scenario, libcurl first uses a proper H...
- CVE-2026-8927: When reusing a libcurl handle for sequential tr...
- CVE-2026-8924: A flaw in curl’s cookie parsing logic allows a ...
- CVE-2026-9079: libcurl had a flaw that when instructed to clea...
- CVE-2026-9547: When a libcurl-based application performs trans...
- CVE-2026-8926: When asking curl to use a
.netrcfile to find... - CVE-2026-8925: The curl logic that works with SASL authenticat...
USN-8480-1 SQLite vulnerabilities:
- CVE-2026-11824: SQLite before 3.53.2 contains a heap-based buff...
- CVE-2026-11822: SQLite before 3.53.2 contains memory corruption...
USN-8477-1 tar vulnerability:
- CVE-2026-5704: A flaw was found in tar. A remote attacker coul...
USN-8468-1 ImageMagick vulnerabilities:
- CVE-2026-28691: ImageMagick is free and open-source software us...
- CVE-2026-27798: ImageMagick is free and open-source software us...
- CVE-2026-28692: ImageMagick is free and open-source software us...
- CVE-2026-27799: ImageMagick is free and open-source software us...
- CVE-2026-28693: ImageMagick is free and open-source software us...
- CVE-2026-28690: ImageMagick is free and open-source software us...
USN-8469-1 FFmpeg vulnerabilities:
- CVE-2026-40962: FFmpeg before 8.1 has an integer overflow and r...
- CVE-2025-12343: A flaw was found in FFmpeg’s TensorFlow backend...
USN-8454-1 libheif vulnerabilities:
- CVE-2026-32740: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-3950: A vulnerability was identified in strukturag li...
- CVE-2026-41071: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-32739: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-32814: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-32741: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-32738: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-32882: libheif is a HEIF and AVIF file format decoder ...
- CVE-2026-41069: libheif is a HEIF and AVIF file format decoder ...
USN-8451-1 Vim vulnerabilities:
- CVE-2026-47167: Vim is an open source, command line text editor...
- CVE-2026-52859: Vim is an open source, command line text editor...
- CVE-2026-47162: Vim is an open source, command line text editor...
- CVE-2026-52858: Vim is an open source, command line text editor...
- CVE-2026-52860: Vim is an open source, command line text editor...
USN-8415-1 Vim vulnerabilities:
- CVE-2026-46483: Vim is an open source, command line text editor...
- CVE-2026-43961: [Unknown description]
USN-8414-1 OpenSSL vulnerabilities:
-
CVE-2026-45447: Issue summary: A specially crafted PKCS#7 or S/...
-
CVE-2026-34182: Issue Summary: Cryptographic Message Services (...
-
CVE-2026-42764: Issue summary: Receiving a QUIC initial packet ...
-
CVE-2026-45446: Issue summary: The implementations of AES-SIV (...
-
CVE-2026-42766: Issue summary: A specially crafted password-enc...
-
CVE-2026-34180: Issue summary: Parsing a crafted DER-encoded AS...
-
CVE-2026-7383: Issue summary: A signed integer overflow when s...
-
CVE-2026-34183: Issue summary: Remote peer may exhaust heap mem...
-
CVE-2026-9076: Issue summary: When CMS password-based decrypti...
-
CVE-2026-42770: Issue summary: When EVP_PKEY_derive_set_peer() ...
-
CVE-2026-34181: Issue Summary: The PKCS#12 file processing fail...
-
CVE-2026-42769: Issue Summary: An error in the callback used to...
-
CVE-2026-42768: Issue summary: The CMS_decrypt and PKCS7_decryp...
-
CVE-2026-45445: Issue summary: When an application drives an AE...
-
CVE-2026-42767: Issue summary: An attacker-controlled CMP (Cert...
USN-8388-1 Linux kernel vulnerabilities:
- CVE-2026-43284: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43503: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46300: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43500: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43494: In the Linux kernel, the following vulnerabilit...
- CVE-2026-46333: In the Linux kernel, the following vulnerabilit...
USN-8362-1 XZ Utils vulnerability:
- CVE-2026-34743: XZ Utils provide a general-purpose data-compres...
USN-8319-1 Libgcrypt vulnerabilities:
- CVE-2026-41989: Libgcrypt before 1.12.2 sometimes allows a heap...
- CVE-2026-41990: Libgcrypt before 1.12.2 mishandles Dilithium si...
USN-8304-1 Vim vulnerabilities:
- CVE-2026-42307: Vim is an open source, command line text editor...
- CVE-2026-44656: Vim is an open source, command line text editor...
- CVE-2026-45130: Vim is an open source, command line text editor...
USN-8294-1 PostgreSQL vulnerabilities:
- CVE-2026-6475: Symlink following in PostgreSQL pg_basebackup p...
- CVE-2026-6637: Stack buffer overflow in PostgreSQL module "ref...
- CVE-2026-6575: Buffer over-read in PostgreSQL function pg_rest...
- CVE-2026-6478: Covert timing channel in comparison of MD5-hash...
- CVE-2026-6473: Integer wraparound in multiple PostgreSQL serve...
- CVE-2026-6477: Use of inherently dangerous function PQfn(..., ...
- CVE-2026-6638: SQL injection in PostgreSQL logical replication...
- CVE-2026-6472: Missing authorization in PostgreSQL CREATE TYPE...
- CVE-2026-6476: SQL injection in PostgreSQL pg_createsubscriber...
- CVE-2026-6474: Externally-controlled format string in PostgreS...
- CVE-2026-6479: Uncontrolled recursion in PostgreSQL SSL and GS...
USN-8293-1 Bind vulnerabilities:
- CVE-2026-5950: An unbounded resend loop vulnerability exists i...
- CVE-2026-5947: Undefined behavior may result due to a race con...
- CVE-2026-3593: A use-after-free vulnerability exists within th...
- CVE-2026-5946: Multiple flaws have been identified in
named... - CVE-2026-3592: BIND resolvers are vulnerable to an amplified r...
- CVE-2026-3039: BIND servers that are configured to use TKEY-ba...
USN-8292-1 libarchive vulnerabilities:
- CVE-2026-4426: A flaw was found in libarchive. An Undefined Be...
- CVE-2026-4424: A flaw was found in libarchive. This heap out-o...
- CVE-2026-5121: A flaw was found in libarchive. On 32-bit syste...
USN-8284-1 GnuTLS vulnerabilities:
- CVE-2026-42015: A flaw was found in gnutls. An off-by-one error...
- CVE-2026-42011: A flaw was found in gnutls. This vulnerability ...
- CVE-2026-5260: A flaw was found in libgnutls. A remote attacke...
- CVE-2026-42010: A flaw was found in gnutls. Servers configured ...
- CVE-2026-3833: A flaw was found in gnutls. This vulnerability ...
- CVE-2026-42013: A flaw was found in gnutls. When validating cer...
- CVE-2026-33846: A heap buffer overflow vulnerability exists in ...
- CVE-2026-42014: A flaw was found in GnuTLS. The `gnutls_pkcs11_...
- CVE-2026-5419: A flaw was found in gnutls. The PKCS#7 padding ...
- CVE-2026-42009: A flaw was found in gnutls. A remote attacker c...
- CVE-2026-42012: A flaw was found in gnutls. A remote attacker c...
- CVE-2026-3832: A flaw was found in gnutls. A remote attacker c...
- CVE-2026-33845: A flaw in GnuTLS DTLS handshake parsing allows ...
USN-8283-1 rsync vulnerabilities:
- CVE-2026-43620: Rsync version 3.4.2 and prior contain a receive...
- CVE-2026-43618: Rsync version 3.4.2 and prior contain an intege...
- CVE-2026-43617: Rsync version 3.4.2 and prior contain an author...
- CVE-2026-45232: Rsync versions before 3.4.3 contain an off-by-o...
- CVE-2026-43619: Rsync version 3.4.2 and prior contain symlink r...
- CVE-2026-29518: Rsync versions before 3.4.3 contain a time-of-c...
- CVE-2026-41035: In rsync 3.0.1 through 3.4.1, receive_xattr rel...
- CVE-2025-10158: A malicious client acting as the receiver of an...
USN-8282-1 Unbound vulnerabilities:
- CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including v...
- CVE-2026-42944: NLnet Labs Unbound 1.14.0 up to and including v...
- CVE-2026-40622: NLnet Labs Unbound 1.16.2 up to and including v...
- CVE-2026-42923: NLnet Labs Unbound up to and including version ...
- CVE-2026-44608: NLnet Labs Unbound 1.14.0 up to and including v...
- CVE-2026-41292: NLnet Labs Unbound up to and including version ...
- CVE-2026-42960: NLnet Labs Unbound up to and including version ...
- CVE-2026-42959: NLnet Labs Unbound up to and including version ...
- CVE-2026-32792: NLnet Labs Unbound 1.6.2 up to and including ve...
- CVE-2026-44390: NLnet Labs Unbound up to and including version ...
- CVE-2026-42534: NLnet Labs Unbound up to and including version ...
USN-8279-1 Linux kernel vulnerabilities:
- CVE-2026-43077: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23351: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31431: In the Linux kernel, the following vulnerabilit...
- CVE-2024-35862: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31533: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23274: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31504: In the Linux kernel, the following vulnerabilit...
- CVE-2026-31419: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43078: In the Linux kernel, the following vulnerabilit...
- CVE-2024-50060: In the Linux kernel, the following vulnerabilit...
- CVE-2026-43033: In the Linux kernel, the following vulnerabilit...
USN-8263-1 ImageMagick vulnerabilities:
- CVE-2026-25898: ImageMagick is free and open-source software us...
- CVE-2026-25798: ImageMagick is free and open-source software us...
- CVE-2026-25799: ImageMagick is free and open-source software us...
- CVE-2026-25965: ImageMagick is free and open-source software us...
- CVE-2026-25797: ImageMagick is free and open-source software us...
- CVE-2026-24485: ImageMagick is free and open-source software us...
- CVE-2026-25796: ImageMagick is free and open-source software us...
- CVE-2026-25794: ImageMagick is free and open-source software us...
- CVE-2026-25637: ImageMagick is free and open-source software us...
- CVE-2026-25576: ImageMagick is free and open-source software us...
- CVE-2026-25795: ImageMagick is free and open-source software us...
- CVE-2026-24484: ImageMagick is free and open-source software us...
- CVE-2026-25897: ImageMagick is free and open-source software us...
- CVE-2026-24481: ImageMagick is free and open-source software us...
- CVE-2026-25638: ImageMagick is free and open-source software us...
USN-8259-1 OpenEXR vulnerabilities:
- CVE-2026-27622: OpenEXR provides the specification and referenc...
- CVE-2026-34380: OpenEXR provides the specification and referenc...
- CVE-2026-34588: OpenEXR provides the specification and referenc...
USN-8255-1 Linux kernel vulnerabilities:
- CVE-2023-2640: On Ubuntu kernels carrying both c914c0e27eb0 an...
- CVE-2026-23273: In the Linux kernel, the following vulnerabilit...
- CVE-2026-23112: In the Linux kernel, the following vulnerabilit...
- CVE-2023-32629: Local privilege escalation vulnerability in Ubu...
USN-8246-1 Vim vulnerabilities:
- CVE-2026-41411: Vim is an open source, command line text editor...
- CVE-2026-39881: Vim is an open source, command line text editor...
- CVE-2026-35177: Vim is an open source, command line text editor...
USN-8233-1 nghttp2 vulnerability:
- CVE-2026-27135: nghttp2 is an implementation of the Hypertext T...
USN-8229-1 sed vulnerability:
- CVE-2026-5958: When sed is invoked with both -i (in-place edit...
USN-8227-1 curl vulnerabilities:
- CVE-2026-4873: A vulnerability exists where a connection requi...
- CVE-2026-5773: libcurl might in some circumstances reuse the w...
- CVE-2026-5545: libcurl might in some circumstances reuse the w...
- CVE-2026-6429: When asked to both use a
.netrcfile for cred... - CVE-2026-6276: Using libcurl, when a custom
Host:header is ... - CVE-2026-6253: curl might erroneously pass on credentials for ...
- CVE-2026-7168: Successfully using libcurl to do a transfer ove...
USN-8226-1 kmod update:
- CVE-2026-31431: In the Linux kernel, the following vulnerabilit...
USN-8222-1 OpenSSH vulnerabilities:
- CVE-2026-35414: OpenSSH before 10.3 mishandles the authorized_k...
- CVE-2026-35387: OpenSSH before 10.3 can use unintended ECDSA al...
- CVE-2026-35386: In OpenSSH before 10.3, command execution can o...
- CVE-2026-35388: OpenSSH before 10.3 omits connection multiplexi...
- CVE-2026-35385: In OpenSSH before 10.3, a file downloaded by sc...
USN-8213-1 Vim vulnerabilities:
- CVE-2026-35177: Vim is an open source, command line text editor...
- CVE-2026-39881: Vim is an open source, command line text editor...
USN-8202-1 jq vulnerabilities:
- CVE-2026-32316: jq is a command-line JSON processor. An integer...
- CVE-2026-39956: jq is a command-line JSON processor. In commits...
- CVE-2026-40164: jq is a command-line JSON processor. Before com...
- CVE-2026-39979: jq is a command-line JSON processor. In commits...
- CVE-2026-33947: jq is a command-line JSON processor. In version...
- CVE-2026-33948: jq is a command-line JSON processor. Commits be...
USN-8171-1 Vim vulnerabilities:
- CVE-2026-34982: Vim is an open source, command line text editor...
- CVE-2026-32249: Vim is an open source, command line text editor...
- CVE-2026-33412: Vim is an open source, command line text editor...
USN-8119-1 systemd vulnerabilities:
- CVE-2026-29111: systemd, a system and service manager, (as PID ...
-ii linux-libc-dev:amd64 5.15.0-185.195 amd64 Linux Kernel Headers for development
+ii linux-libc-dev:amd64 5.15.0-186.196 amd64 Linux Kernel Headers for development
-ii tar 1.34+dfsg-1ubuntu0.1.22.04.4 amd64 GNU version of the tar archiving utility
+ii tar 1.34+dfsg-1ubuntu0.1.22.04.5 amd64 GNU version of the tar archiving utility