[USN-8590-1] Exim vulnerabilities
[USN-8477-3] tar regression
[USN-8585-1] Kerberos vulnerabilities
[USN-8584-1] GStreamer Good Plugins vulnerabilities
[USN-8587-1] HTML-Parser vulnerability
[USN-8586-1] libgphoto2 vulnerabilities
[USN-8583-1] GIFLIB vulnerabilities
[USN-8589-1] Apache HTTP Server vulnerabilities
[USN-8588-1] Gawk vulnerabilities
[USN-8581-1] libarchive vulnerabilities
[USN-8591-1] AIOHTTP vulnerabilities
[USN-8590-1] Exim vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8590-1
July 22, 2026
exim4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Exim.
Software Description:
- exim4: Exim is a mail transport agent
Details:
It was discovered that Exim incorrectly handled certain command line
options. A local attacker could possibly use this issue to access files
outside of the spool area.
It was discovered that Exim incorrectly handled string expansion in
.local files. A local attacker could possibly use this issue to escalate
privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
exim4 4.99.1-1ubuntu1.4
Ubuntu 24.04 LTS
exim4 4.97-4ubuntu4.7
Ubuntu 22.04 LTS
exim4 4.95-4ubuntu2.11
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8590-1
https://launchpad.net/bugs/2161106
Package Information:
https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.4
https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.7
https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.11
[USN-8477-3] tar regression
==========================================================================
Ubuntu Security Notice USN-8477-3
July 22, 2026
tar regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
USN-8477-1 introduced a regression in tar
Software Description:
- tar: GNU tar archive utility
Details:
USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could
cause tar to fail to extract old archives that recorded a nonzero size for
directory entries, resulting in a regression.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that tar incorrectly handled certain crafted archive files.
An attacker could possibly use this to inject hidden files with
attacker-controlled content, bypassing pre-extraction inspection mechanisms.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
tar 1.35+dfsg-4ubuntu0.4
Ubuntu 24.04 LTS
tar 1.35+dfsg-3ubuntu0.4
Ubuntu 22.04 LTS
tar 1.34+dfsg-1ubuntu0.1.22.04.6
Ubuntu 20.04 LTS
tar 1.30+dfsg-7ubuntu0.20.04.4+esm3
Available with Ubuntu Pro
Ubuntu 18.04 LTS
tar 1.29b-2ubuntu0.4+esm4
Available with Ubuntu Pro
Ubuntu 16.04 LTS
tar 1.28-2.1ubuntu0.2+esm6
Available with Ubuntu Pro
Ubuntu 14.04 LTS
tar 1.27.1-1ubuntu0.1+esm7
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8477-3
https://ubuntu.com/security/notices/USN-8477-2
https://ubuntu.com/security/notices/USN-8477-1
CVE-2026-5704, https://launchpad.net/bugs/2161311
Package Information:
https://launchpad.net/ubuntu/+source/tar/1.35+dfsg-4ubuntu0.4
https://launchpad.net/ubuntu/+source/tar/1.35+dfsg-3ubuntu0.4
https://launchpad.net/ubuntu/+source/tar/1.34+dfsg-1ubuntu0.1.22.04.6
[USN-8585-1] Kerberos vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8585-1
July 22, 2026
krb5 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Kerberos.
Software Description:
- krb5: MIT Kerberos Network Authentication Protocol
Details:
It was discovered that Kerberos had an integer underflow vulnerability
in the berval2tl_data() function. An attacker could possibly use this issue
to cause Kerberos to crash, resulting in a denial of service.
(CVE-2026-11850)
It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism
parsing. A remote attacker could possibly use these issues to cause
Kerberos to crash, resulting in a denial of service. (CVE-2026-40355,
CVE-2026-40356)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
krb5-admin-server 1.22.1-2ubuntu4.1
krb5-kdc 1.22.1-2ubuntu4.1
libkrb5-3 1.22.1-2ubuntu4.1
Ubuntu 24.04 LTS
krb5-admin-server 1.20.1-6ubuntu2.7
krb5-kdc 1.20.1-6ubuntu2.7
libkrb5-3 1.20.1-6ubuntu2.7
Ubuntu 22.04 LTS
krb5-admin-server 1.19.2-2ubuntu0.8
krb5-kdc 1.19.2-2ubuntu0.8
libkrb5-3 1.19.2-2ubuntu0.8
After a standard system update you need to restart Kerberos to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8585-1
CVE-2026-11850, CVE-2026-40355, CVE-2026-40356
Package Information:
https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1
https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7
https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8
[USN-8584-1] GStreamer Good Plugins vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8584-1
July 22, 2026
gst-plugins-good1.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in GStreamer Good Plugins.
Software Description:
- gst-plugins-good1.0: GStreamer plugins
Details:
It was discovered that GStreamer Good Plugins incorrectly handled certain
Matroska files. An attacker could possibly use this issue to cause
GStreamer Good Plugins to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39043)
It was discovered that GStreamer Good Plugins incorrectly handled certain
WAV files. An attacker could possibly use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39044)
It was discovered that GStreamer Good Plugins incorrectly handled certain
WavPack audio files. An attacker could use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-53705)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
gstreamer1.0-plugins-good 1.28.2-2ubuntu0.1
Ubuntu 24.04 LTS
gstreamer1.0-plugins-good 1.24.2-1ubuntu1.5
libgstreamer-plugins-good1.0-0 1.24.2-1ubuntu1.5
Ubuntu 22.04 LTS
gstreamer1.0-plugins-good 1.20.3-0ubuntu1.7
libgstreamer-plugins-good1.0-0 1.20.3-0ubuntu1.7
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8584-1
CVE-2026-39043, CVE-2026-39044, CVE-2026-53705
Package Information:
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.28.2-2ubuntu0.1
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.5
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.7
[USN-8587-1] HTML-Parser vulnerability
==========================================================================
Ubuntu Security Notice USN-8587-1
July 22, 2026
libhtml-parser-perl vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
HTML-Parser could be made to expose sensitive information.
Software Description:
- libhtml-parser-perl: collection of modules that parse HTML text documents
Details:
It was discovered that HTML-Parser incorrectly handled entity references
when the input string was identical to an entity value in the lookup table.
An attacker could possibly use this issue to obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libhtml-parser-perl 3.83-1ubuntu0.1
Ubuntu 24.04 LTS
libhtml-parser-perl 3.81-1ubuntu0.1
Ubuntu 22.04 LTS
libhtml-parser-perl 3.76-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8587-1
CVE-2026-8829
Package Information:
https://launchpad.net/ubuntu/+source/libhtml-parser-perl/3.83-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libhtml-parser-perl/3.81-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libhtml-parser-perl/3.76-1ubuntu0.1
[USN-8586-1] libgphoto2 vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8586-1
July 22, 2026
libgphoto2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in libgphoto2.
Software Description:
- libgphoto2: gphoto2 digital camera library
Details:
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing EOS image format data. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40333)
It was discovered that libgphoto2 did not properly null-terminate buffers
when parsing Canon folder entries. An attacker with physical access could
possibly use this issue to obtain sensitive information. (CVE-2026-40334)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing device property values. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40335)
It was discovered that libgphoto2 had a memory leak when parsing Sony
device property descriptors. An attacker with physical access could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-40336)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing Sony device property enumeration data. An attacker
with physical access could possibly use this issue to obtain sensitive
information. (CVE-2026-40338)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing Sony device property form flags. An attacker with
physical access could possibly use this issue to obtain sensitive
information. (CVE-2026-40339)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing object information. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40340)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing EOS focus information. An attacker with physical
access could possibly use this issue to cause libgphoto2 to crash,
resulting in a denial of service. (CVE-2026-40341)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libgphoto2-6t64 2.5.33-1ubuntu1.1
Ubuntu 24.04 LTS
libgphoto2-6t64 2.5.31-2.1ubuntu1.1
Ubuntu 22.04 LTS
libgphoto2-6 2.5.27-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8586-1
CVE-2026-40333, CVE-2026-40334, CVE-2026-40335, CVE-2026-40336,
CVE-2026-40338, CVE-2026-40339, CVE-2026-40340, CVE-2026-40341
Package Information:
https://launchpad.net/ubuntu/+source/libgphoto2/2.5.33-1ubuntu1.1
https://launchpad.net/ubuntu/+source/libgphoto2/2.5.31-2.1ubuntu1.1
https://launchpad.net/ubuntu/+source/libgphoto2/2.5.27-1ubuntu0.1
[USN-8583-1] GIFLIB vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8583-1
July 22, 2026
giflib vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
GIFLIB could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- giflib: library for GIF images
Details:
It was discovered that GIFLIB incorrectly handled certain GIF image files.
If a user or automated system were tricked into opening a specially crafted
GIF file, a remote attacker could use this issue to cause GIFLIB to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
giflib-tools 5.2.2-1ubuntu3.2
libgif7 5.2.2-1ubuntu3.2
Ubuntu 24.04 LTS
giflib-tools 5.2.2-1ubuntu1.2
libgif7 5.2.2-1ubuntu1.2
Ubuntu 22.04 LTS
giflib-tools 5.1.9-2ubuntu0.3
libgif7 5.1.9-2ubuntu0.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8583-1
CVE-2026-23868, CVE-2026-26740
Package Information:
https://launchpad.net/ubuntu/+source/giflib/5.2.2-1ubuntu3.2
https://launchpad.net/ubuntu/+source/giflib/5.2.2-1ubuntu1.2
https://launchpad.net/ubuntu/+source/giflib/5.1.9-2ubuntu0.3
[USN-8589-1] Apache HTTP Server vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8589-1
July 22, 2026
apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Apache HTTP Server.
Software Description:
- apache2: Apache HTTP server
Details:
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module
was vulnerable to a timing attack. A remote attacker could possibly use
this issue to bypass Digest authentication. (CVE-2026-33006)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
apache2 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-bin 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-dev 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-ssl-dev 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-suexec-custom 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-utils 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
libapache2-mod-md 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
Ubuntu 18.04 LTS
apache2 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-bin 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-dev 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-ssl-dev 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-suexec-custom 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-utils 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
Ubuntu 16.04 LTS
apache2 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-bin 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-dev 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-suexec-custom 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-utils 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
Ubuntu 14.04 LTS
apache2 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-bin 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-dev 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-event 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-itk 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-prefork 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-worker 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-suexec 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-suexec-custom 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-utils 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2.2-bin 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
libapache2-mod-macro 1:2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
libapache2-mod-proxy-html 1:2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
After a standard system update you need to restart apache2 to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8589-1
CVE-2026-29167, CVE-2026-29170, CVE-2026-33006
[USN-8588-1] Gawk vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8588-1
July 22, 2026
gawk vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Gawk.
Software Description:
- gawk: GNU implementation of AWK
Details:
It was discovered that Gawk incorrectly handled memory when processing
input using the getline redirection. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-40467)
It was discovered that Gawk incorrectly handled certain integer
calculations when allocating memory. An attacker could possibly use
this issue to cause a denial of service or overwrite heap memory with
attacker-controlled data. (CVE-2026-40468)
It was discovered that Gawk incorrectly handled certain integer
calculations when performing substitutions. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-40469)
It was discovered that Gawk incorrectly handled memory when reading
directory entries. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-40553)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
gawk 1:5.3.2-1ubuntu1.1
Ubuntu 24.04 LTS
gawk 1:5.2.1-2ubuntu0.1
Ubuntu 22.04 LTS
gawk 1:5.1.0-1ubuntu0.2
Ubuntu 20.04 LTS
gawk 1:5.0.1+dfsg-1ubuntu0.1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
gawk 1:4.1.4+dfsg-1ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
gawk 1:4.1.3+dfsg-0.1ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 14.04 LTS
gawk 1:4.0.1+dfsg-2.1ubuntu2+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8588-1
CVE-2026-40467, CVE-2026-40468, CVE-2026-40469, CVE-2026-40553
Package Information:
https://launchpad.net/ubuntu/+source/gawk/1:5.3.2-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gawk/1:5.2.1-2ubuntu0.1
https://launchpad.net/ubuntu/+source/gawk/1:5.1.0-1ubuntu0.2
[USN-8581-1] libarchive vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8581-1
July 21, 2026
libarchive vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libarchive.
Software Description:
- libarchive: Library to read/write archive files
Details:
It was discovered that libarchive did not properly manage memory when
unpacking certain RAR5 archives, leading to a double free. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-14164)
It was discovered that libarchive did not properly validate certain tar
archives, leading to a buffer overflow. A remote attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028)
It was discovered that libarchive did not properly validate certain
malformed ACL entries. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-5745)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libarchive-dev 3.8.5-1ubuntu2.2
libarchive-tools 3.8.5-1ubuntu2.2
libarchive13t64 3.8.5-1ubuntu2.2
Ubuntu 24.04 LTS
libarchive-dev 3.7.2-2ubuntu0.8
libarchive-tools 3.7.2-2ubuntu0.8
libarchive13t64 3.7.2-2ubuntu0.8
Ubuntu 22.04 LTS
libarchive-dev 3.6.0-1ubuntu1.8
libarchive-tools 3.6.0-1ubuntu1.8
libarchive13 3.6.0-1ubuntu1.8
Ubuntu 20.04 LTS
libarchive-dev 3.4.0-2ubuntu1.5+esm3
Available with Ubuntu Pro
libarchive-tools 3.4.0-2ubuntu1.5+esm3
Available with Ubuntu Pro
libarchive13 3.4.0-2ubuntu1.5+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8581-1
CVE-2026-14164, CVE-2026-15028, CVE-2026-5745
Package Information:
https://launchpad.net/ubuntu/+source/libarchive/3.8.5-1ubuntu2.2
https://launchpad.net/ubuntu/+source/libarchive/3.7.2-2ubuntu0.8
https://launchpad.net/ubuntu/+source/libarchive/3.6.0-1ubuntu1.8
[USN-8591-1] AIOHTTP vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8591-1
July 22, 2026
python-aiohttp vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in AIOHTTP.
Software Description:
- python-aiohttp: Asynchronous HTTP client/server Python framework
Details:
Sean Gilligan discovered that AIOHTTP did not properly limit memory
usage when processing HTTP headers and trailers. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-22815)
It was discovered that AIOHTTP did not properly limit the size of its
DNS cache. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service.
(CVE-2026-34513)
Mingi Jung discovered that AIOHTTP did not properly sanitize the
content_type parameter. An attacker could possibly use this issue to
inject malicious HTTP headers, resulting in HTTP response splitting.
(CVE-2026-34514)
It was discovered that AIOHTTP did not properly limit memory usage when
processing multipart headers. An attacker could possibly use this issue
to consume excessive system resources, resulting in a denial of service.
(CVE-2026-34516)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
python3-aiohttp 3.13.3-3ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
python3-aiohttp 3.9.1-1ubuntu0.1+esm3
Available with Ubuntu Pro
Ubuntu 22.04 LTS
python3-aiohttp 3.8.1-4ubuntu0.2+esm3
Available with Ubuntu Pro
Ubuntu 20.04 LTS
python3-aiohttp 3.6.2-1ubuntu1+esm6
Available with Ubuntu Pro
Ubuntu 18.04 LTS
python3-aiohttp 3.0.1-1ubuntu0.1~esm7
Available with Ubuntu Pro
Ubuntu 16.04 LTS
python3-aiohttp 0.20.2-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8591-1
CVE-2026-22815, CVE-2026-34513, CVE-2026-34514, CVE-2026-34516