<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>vulnfeed — Ubuntu</title>
    <link>https://vulnfeed.it</link>
    <description>Ubuntu security vulnerabilities — vulnfeed.it</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 04 Aug 2026 17:55:03 +0000</lastBuildDate>
    <atom:link href="https://vulnfeed.it/feed/ubuntu.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>[UNKNOWN] USN-8624-1: USN-8624-1: Sinatra vulnerability</title>
    <link>https://ubuntu.com/security/notices/USN-8624-1</link>
    <description>It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.</description>
    <pubDate>Wed, 29 Jul 2026 19:09:19 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8624-1</guid>
  </item>
  <item>
    <title>[HIGH] USN-8623-1: USN-8623-1: Linux kernel (NVIDIA) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8623-1</link>
    <description>Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)</description>
    <pubDate>Wed, 29 Jul 2026 13:53:58 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8623-1</guid>
  </item>
  <item>
    <title>[HIGH] USN-8622-1: USN-8622-1: Linux kernel (NVIDIA) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8622-1</link>
    <description>Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)</description>
    <pubDate>Wed, 29 Jul 2026 13:50:57 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8622-1</guid>
  </item>
  <item>
    <title>[MEDIUM] USN-8620-2: USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8620-2</link>
    <description>Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local at</description>
    <pubDate>Wed, 29 Jul 2026 07:46:56 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8620-2</guid>
  </item>
  <item>
    <title>[CRITICAL] USN-8615-2: USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8615-2</link>
    <description>It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics net</description>
    <pubDate>Wed, 29 Jul 2026 07:43:21 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8615-2</guid>
  </item>
  <item>
    <title>[UNKNOWN] USN-8561-2: USN-8561-2: FreeRDP regression</title>
    <link>https://ubuntu.com/security/notices/USN-8561-2</link>
    <description>USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.</description>
    <pubDate>Tue, 28 Jul 2026 18:08:13 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8561-2</guid>
  </item>
  <item>
    <title>[UNKNOWN] USN-8625-1: USN-8625-1: OpenSSL vulnerability</title>
    <link>https://ubuntu.com/security/notices/USN-8625-1</link>
    <description>It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial of service.</description>
    <pubDate>Thu, 30 Jul 2026 13:38:32 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8625-1</guid>
  </item>
  <item>
    <title>[MEDIUM] USN-8620-4: USN-8620-4: Linux kernel (Intel IoTG) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8620-4</link>
    <description>Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local at</description>
    <pubDate>Fri, 31 Jul 2026 15:00:56 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8620-4</guid>
  </item>
  <item>
    <title>[MEDIUM] USN-8620-3: USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8620-3</link>
    <description>Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local at</description>
    <pubDate>Fri, 31 Jul 2026 09:40:09 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8620-3</guid>
  </item>
  </channel>
</rss>