Ubuntu 6975 Published by

Ubuntu has issued several security notices for vulnerabilities found in different packages, including python-pip and libsoup. The python-pip update fixes several security issues that could allow an attacker to perform denial of service or arbitrary code execution on Ubuntu 20.04 LTS, 18.04 LTS, and 16.04 LTS systems. The libsoup update addresses two vulnerabilities found in the HTTP client/server library for GNOME, which affects Ubuntu 25.10, 24.04 LTS, and 22.04 LTS systems. Meanwhile, a regression issue was discovered in FreeRDP on multiple Ubuntu versions, and an updated version has been released to fix this problem.

[USN-8010-1] pip vulnerabilities
[USN-8020-1] libsoup vulnerabilities
[USN-8004-2] FreeRDP regression




[USN-8010-1] pip vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8010-1
February 04, 2026

python-pip vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in pip.

Software Description:
- python-pip: Python package installer

Details:

Several security issues were discovered in the libraries bundled in pip. An
attacker could possibly use these issues to perform a variety of attacks,
such as denial of service or arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
python-pip-whl 20.0.2-5ubuntu1.11+esm4
Available with Ubuntu Pro
python3-pip 20.0.2-5ubuntu1.11+esm4
Available with Ubuntu Pro

Ubuntu 18.04 LTS
python-pip 9.0.1-2.3~ubuntu1.18.04.8+esm8
Available with Ubuntu Pro
python-pip-whl 9.0.1-2.3~ubuntu1.18.04.8+esm8
Available with Ubuntu Pro
python3-pip 9.0.1-2.3~ubuntu1.18.04.8+esm8
Available with Ubuntu Pro

Ubuntu 16.04 LTS
python-pip 8.1.1-2ubuntu0.6+esm12
Available with Ubuntu Pro
python-pip-whl 8.1.1-2ubuntu0.6+esm12
Available with Ubuntu Pro
python3-pip 8.1.1-2ubuntu0.6+esm12
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8010-1
CVE-2025-47273, CVE-2025-66418, CVE-2026-21441



[USN-8020-1] libsoup vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8020-1
February 08, 2026

libsoup3 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in libsoup.

Software Description:
- libsoup3: HTTP client/server library for GNOME

Details:

It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)

It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
gir1.2-soup-3.0 3.6.5-4ubuntu0.2
libsoup-3.0-0 3.6.5-4ubuntu0.2
libsoup-3.0-common 3.6.5-4ubuntu0.2
libsoup-3.0-dev 3.6.5-4ubuntu0.2
libsoup-3.0-doc 3.6.5-4ubuntu0.2
libsoup-3.0-tests 3.6.5-4ubuntu0.2

Ubuntu 24.04 LTS
gir1.2-soup-3.0 3.4.4-5ubuntu0.7
libsoup-3.0-0 3.4.4-5ubuntu0.7
libsoup-3.0-common 3.4.4-5ubuntu0.7
libsoup-3.0-dev 3.4.4-5ubuntu0.7
libsoup-3.0-doc 3.4.4-5ubuntu0.7
libsoup-3.0-tests 3.4.4-5ubuntu0.7

Ubuntu 22.04 LTS
gir1.2-soup-3.0 3.0.7-0ubuntu1+esm7
Available with Ubuntu Pro
libsoup-3.0-0 3.0.7-0ubuntu1+esm7
Available with Ubuntu Pro
libsoup-3.0-common 3.0.7-0ubuntu1+esm7
Available with Ubuntu Pro
libsoup-3.0-dev 3.0.7-0ubuntu1+esm7
Available with Ubuntu Pro
libsoup-3.0-doc 3.0.7-0ubuntu1+esm7
Available with Ubuntu Pro
libsoup-3.0-tests 3.0.7-0ubuntu1+esm7
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8020-1
CVE-2026-1467, CVE-2026-1536, CVE-2026-1539

Package Information:
https://launchpad.net/ubuntu/+source/libsoup3/3.6.5-4ubuntu0.2
https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.7



[USN-8004-2] FreeRDP regression


==========================================================================
Ubuntu Security Notice USN-8004-2
February 08, 2026

freerdp2 regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

USN-8004-1 introduced a regression in FreeRDP

Software Description:
- freerdp2: RDP client for Windows Terminal Services

Details:

USN-8004-1 fixed vulnerabilities in FreeRDP. The update for
CVE-2026-23533 introduced a regression. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Kim Dong Han discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
libfreerdp2-2t64 2.11.5+dfsg1-1ubuntu0.1~esm4
Available with Ubuntu Pro

Ubuntu 22.04 LTS
libfreerdp2-2 2.6.1+dfsg1-3ubuntu2.9

Ubuntu 20.04 LTS
libfreerdp2-2 2.6.1+dfsg1-0ubuntu0.20.04.2+esm2
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libfreerdp2-2 2.2.0+dfsg1-0ubuntu0.18.04.4+esm4
Available with Ubuntu Pro

After a standard system update you need to restart your session to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8004-2
https://ubuntu.com/security/notices/USN-8004-1
CVE-2026-23533, https://bugs.launchpad.net/bugs/2139694

Package Information:
https://launchpad.net/ubuntu/+source/freerdp2/2.6.1+dfsg1-3ubuntu2.9