<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Ubuntu security notices</title><link>https://ubuntu.com/security/notices/rss.xml</link><description>Recent content on Ubuntu security notices</description><atom:link href="https://ubuntu.com/security/notices/rss.xml" rel="self"/><copyright>2026 Canonical Ltd. Ubuntu and Canonical are registered trademarks of Canonical Ltd.</copyright><docs>http://www.rssboard.org/rss-specification</docs><generator>Feedgen</generator><lastBuildDate>Sat, 04 Apr 2026 15:15:14 +0000</lastBuildDate><item><title>USN-8148-3: Linux kernel (Real-time) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8148-3</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - Netfilter;
  - Network traffic control;
(CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8148-3</guid><pubDate>Thu, 02 Apr 2026 20:58:01 +0000</pubDate></item><item><title>USN-8148-2: Linux kernel (FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8148-2</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - Netfilter;
  - Network traffic control;
(CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8148-2</guid><pubDate>Thu, 02 Apr 2026 20:45:55 +0000</pubDate></item><item><title>USN-8145-2: Linux kernel (FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8145-2</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - Cryptographic API;
  - UDF file system;
  - NFC subsystem;
  - Network traffic control;
(CVE-2024-46777, CVE-2025-21735, CVE-2025-37849, CVE-2026-23060,
CVE-2026-23074)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8145-2</guid><pubDate>Thu, 02 Apr 2026 20:37:36 +0000</pubDate></item><item><title>USN-8143-2: Linux kernel (FIPS) vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8143-2</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - GPU drivers;
  - BTRFS file system;
  - GFS2 file system;
  - UDF file system;
  - NFC subsystem;
  - Network traffic control;
(CVE-2021-47142, CVE-2021-47145, CVE-2021-47254, CVE-2024-46777,
CVE-2025-21735, CVE-2026-23060, CVE-2026-23074)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8143-2</guid><pubDate>Thu, 02 Apr 2026 20:30:36 +0000</pubDate></item><item><title>USN-8146-1: libjxl vulnerability</title><link>https://ubuntu.com/security/notices/USN-8146-1</link><description>Daniel Novomeský discovered that libjxl did not properly manage memory when
decoding certain files. An attacker could use this issue to cause
libjxl to crash, resulting in denial of service, or possibly execute
arbitrary code.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8146-1</guid><pubDate>Thu, 02 Apr 2026 19:09:19 +0000</pubDate></item><item><title>USN-8149-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8149-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - Netfilter;
  - Network traffic control;
(CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8149-1</guid><pubDate>Thu, 02 Apr 2026 18:31:30 +0000</pubDate></item><item><title>USN-8148-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8148-1</link><description>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - Cryptographic API;
  - Netfilter;
  - Network traffic control;
(CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8148-1</guid><pubDate>Thu, 02 Apr 2026 18:01:51 +0000</pubDate></item><item><title>USN-8145-1: Linux kernel vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8145-1</link><description>
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - Cryptographic API;
  - UDF file system;
  - NFC subsystem;
  - Network traffic control;
(CVE-2024-46777, CVE-2025-21735, CVE-2025-37849, CVE-2026-23060,
CVE-2026-23074)
</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8145-1</guid><pubDate>Thu, 02 Apr 2026 14:06:57 +0000</pubDate></item><item><title>USN-8144-1: Undertow vulnerability</title><link>https://ubuntu.com/security/notices/USN-8144-1</link><description>It was discovered that Undertow incorrectly validated the Host header in
incoming HTTP requests. A remote attacker could possibly use this issue
to gain unintended access to user sessions.</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8144-1</guid><pubDate>Thu, 02 Apr 2026 08:22:52 +0000</pubDate></item><item><title>USN-8140-1: Cairo vulnerabilities</title><link>https://ubuntu.com/security/notices/USN-8140-1</link><description>Alberto Garcia, Francisco Oca and Suleman Ali discovered that Cairo did
not properly manage memory. An attacker could possibly use this issue to
cause Cairo to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2017-9814)

It was discovered that Cairo incorrectly handled certain angle values when
drawing arcs. An attacker could possibly use this issue to cause Cairo to
crash, resulting in a denial of service. (CVE-2019-6461)

It was discovered that Cairo incorrectly handled certain calculations when
drawing arcs. An attacker could possibly use this issue to cause Cairo to
consume resources, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2019-6462)

Stephan Bergmann discovered that Cairo incorrectly managed memory during
image composition. An attacker could use this issue to cause Cairo to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-35492)</description><guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8140-1</guid><pubDate>Thu, 02 Apr 2026 07:27:21 +0000</pubDate></item></channel></rss>