[USN-8612-1] Roc Toolkit vulnerability
[USN-8611-1] GNU C Library vulnerabilities
[USN-8613-1] FreeIPMI vulnerabilities
[USN-8612-1] Roc Toolkit vulnerability
==========================================================================
Ubuntu Security Notice USN-8612-1
July 27, 2026
roc-toolkit vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
Summary:
Roc Toolkit could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- roc-toolkit: real-time audio streaming over the network
Details:
It was discovered that Roc Toolkit incorrectly handled WAV files with a
malformed "smpl" chunk. An attacker could use this issue to cause Roc
Toolkit to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libroc0.4 0.4.0+dfsg-5ubuntu3.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8612-1
CVE-2026-29022
Package Information:
https://launchpad.net/ubuntu/+source/roc-toolkit/0.4.0+dfsg-5ubuntu3.1
[USN-8611-1] GNU C Library vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8611-1
July 27, 2026
glibc vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in GNU C Library.
Software Description:
- glibc: GNU C Library
Details:
It was discovered that the GNU C Library iconv function incorrectly handled
certain IBM character sets. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-4046)
It was discovered that the GNU C Library DNS functions incorrectly handled
certain DNS server responses when using gethostbyaddr or gethostbyaddr_r.
An attacker in a privileged network position could possibly use this issue
to cause an application to violate DNS specification or obtain incorrect
hostname information. This issue only affected Ubuntu 24.04 LTS.
(CVE-2026-4437, CVE-2026-4438)
It was discovered that the GNU C Library deprecated debugging functions
incorrectly enforced caller-supplied buffer lengths. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-5435)
It was discovered that the GNU C Library scanf family of functions
contained a heap buffer overflow when processing certain format specifiers.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-5450)
It was discovered that the GNU C Library ungetwc function incorrectly
handled certain character encodings. An attacker could possibly use this
issue to obtain sensitive information or cause a denial of service.
(CVE-2026-5928)
It was discovered that the GNU C Library deprecated debugging functions
incorrectly validated DNS response record data. An attacker could possibly
use this issue to cause a denial of service or obtain sensitive
information. (CVE-2026-6238)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libc6 2.43-2ubuntu2.3
Ubuntu 24.04 LTS
libc6 2.39-0ubuntu8.8
Ubuntu 22.04 LTS
libc6 2.35-0ubuntu3.14
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8611-1
CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5435,
CVE-2026-5450, CVE-2026-5928, CVE-2026-6238
Package Information:
https://launchpad.net/ubuntu/+source/glibc/2.43-2ubuntu2.3
https://launchpad.net/ubuntu/+source/glibc/2.39-0ubuntu8.8
https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.14
[USN-8613-1] FreeIPMI vulnerabilities
==========================================================================
Ubuntu Security Notice USN-8613-1
July 27, 2026
FreeIPMI vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in FreeIPMI.
Software Description:
- freeipmi: in-band and out-of-band Intelligent Platform Management Interface
Details:
Zhihan Zheng discovered that FreeIPMI had several buffer overflow
vulnerabilities in ipmi-oem response message handling. A local attacker
with control a malicious IPMI device or simulator could possibly cause
FreeIPMI to crash, resulting in a denial of service. (CVE-2026-33554,
CVE-2026-50031)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
freeipmi-tools 1.6.16-1ubuntu0.1
Ubuntu 24.04 LTS
freeipmi-tools 1.6.13-3ubuntu0.1
Ubuntu 22.04 LTS
freeipmi-tools 1.6.9-2ubuntu0.22.04.3
Ubuntu 20.04 LTS
freeipmi-tools 1.6.4-3ubuntu1.1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
freeipmi-tools 1.4.11-1.1ubuntu4.1+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
freeipmi-tools 1.4.11-1.1ubuntu4.1~0.16.04.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04 LTS
freeipmi-tools 1.1.5-3ubuntu3.3+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8613-1
CVE-2026-33554, CVE-2026-50031
Package Information:
https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1
https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1
https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3