<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Thu, 01 Oct 2026 22:06:47 +0000</lastBuildDate><item><title>USN-8863-1: GStreamer Good Plugins vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8863-1</link><description>Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled
certain FLAC audio streams. An attacker could possibly use this issue to
obtain sensitive information. (CVE-2026-17072)

Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed
certain AVI files. An attacker could possibly use this issue to cause a
denial of service or obtain sensitive information. (CVE-2026-73433)

Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse
certain AVI files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-73434)

Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled
certain closed caption data. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88914)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8863-1</guid><pubDate>Thu, 01 Oct 2026 16:46:33 +0000</pubDate></item><item><title>USN-8862-1: libXpm vulnerability</title><link>https://ubuntu.com/security/notices/USN-8862-1</link><description>It was discovered that libXpm did not correctly handle XPM images with
zero-dimension values. A local attacker could possibly use this issue to
cause libXpm to use excessive resources, leading to a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8862-1</guid><pubDate>Thu, 01 Oct 2026 12:51:01 +0000</pubDate></item><item><title>USN-8861-1: OpenSSL vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8861-1</link><description>It was discovered that OpenSSL had an inefficient algorithm in its QUIC
stream reassembly implementation. A remote attacker could possibly use this
issue to cause OpenSSL to use excessive CPU resources, leading to a denial
of service. (CVE-2026-42772)

It was discovered that OpenSSL did not properly limit memory allocated for
QUIC packet buffers. A remote attacker could possibly use this issue to
cause OpenSSL to use excessive memory resources, leading to a denial of
service. (CVE-2026-54873)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8861-1</guid><pubDate>Thu, 01 Oct 2026 12:02:00 +0000</pubDate></item><item><title>USN-8860-1: OpenStack Designate vulnerability</title><link>https://ubuntu.com/security/notices/USN-8860-1</link><description>It was discovered that OpenStack Designate did not properly validate
overlapping zones under certain circumstances. An authenticated user could
possibly use this issue to redirect DNS traffic to attacker-controlled
systems or cause a denial of service.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8860-1</guid><pubDate>Thu, 01 Oct 2026 11:17:31 +0000</pubDate></item><item><title>USN-8857-1: KCoreAddons vulnerability</title><link>https://ubuntu.com/security/notices/USN-8857-1</link><description>It was discovered that KCoreAddons incorrectly handled shell argument
quoting in KShell::quoteArgs. The parsing did not adequately handle shell
metacharacters, which could lead to a shell escape. An attacker could
possibly use this issue to execute arbitrary commands in applications that
relied on this method to handle user input.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8857-1</guid><pubDate>Thu, 01 Oct 2026 10:48:57 +0000</pubDate></item><item><title>USN-8858-1: Authen::SASL vulnerability</title><link>https://ubuntu.com/security/notices/USN-8858-1</link><description>It was discovered that Authen::SASL, a Perl authentication library, did
not properly validate login attempts. An attacker could possibly use
this issue to gain unauthorized access.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8858-1</guid><pubDate>Wed, 30 Sep 2026 16:40:43 +0000</pubDate></item><item><title>USN-8859-1: ImageMagick vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8859-1</link><description>It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service or
obtain sensitive information. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-56367)

It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2026-93586)

It was discovered that ImageMagick did not correctly handle certain images.
A local attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93587, CVE-2026-93588)

It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93589)

It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-93590)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8859-1</guid><pubDate>Wed, 30 Sep 2026 16:39:48 +0000</pubDate></item><item><title>USN-8855-1: GStreamer Bad Plugins vulnerability</title><link>https://ubuntu.com/security/notices/USN-8855-1</link><description>It was discovered that GStreamer Bad Plugins incorrectly validated the size
of multi-channel audio blocks. An attacker could possibly use this  issue
with a specially crafted WAV file to cause the program to crash, resulting
in a denial of service, or possibly execute arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8855-1</guid><pubDate>Wed, 30 Sep 2026 16:05:01 +0000</pubDate></item><item><title>USN-8856-1: Kdenlive, MLT vulnerability</title><link>https://ubuntu.com/security/notices/USN-8856-1</link><description>It was discovered that Kdenlive allowed dangerous proxy parameters when
processing attacker-controlled project files. An attacker could use this to
execute arbitrary commands via the MLT framework's ante/post consumer
properties.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8856-1</guid><pubDate>Wed, 30 Sep 2026 15:59:30 +0000</pubDate></item><item><title>USN-8845-1: GVfs vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8845-1</link><description>Keith Linneman discovered that GVfs did not properly validate data
received from SFTP servers. An attacker could possibly use this issue to
cause a heap buffer overflow, resulting in arbitrary code execution or a
denial of service. (CVE-2026-84268)

It was discovered that GVfs incorrectly handled file ownership when
creating private D-Bus sockets in the admin backend. A local attacker
could possibly use this issue to change the ownership of arbitrary
system files, resulting in privilege escalation to root. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88924)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8845-1</guid><pubDate>Wed, 30 Sep 2026 15:54:56 +0000</pubDate></item></channel></rss>