Ubuntu 7170 Published by

Ubuntu published security notices covering four separate vulnerabilities across its long-term support releases. Ruby-sinatra requires an update to block remote denial of service attacks caused by malformed header parsing. Desktop environments need patches for a libinput privilege escalation flaw, while older Python installations must address resource exhaustion and HTML parser crashes. The OpenSSL update resolves the HollowByte memory allocation bug that enables network-based denial of service attacks, though Ubuntu 22.04 and newer users must reboot their machines to apply the changes.

[USN-8624-1] Sinatra vulnerability
[USN-8602-1] libinput vulnerability
[USN-8614-1] Python vulnerabilities
[USN-8625-1] OpenSSL vulnerability




[USN-8624-1] Sinatra vulnerability


==========================================================================
Ubuntu Security Notice USN-8624-1
July 29, 2026

ruby-sinatra vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Sinatra could be made to crash if it received specially crafted network
traffic.

Software Description:
- ruby-sinatra: Ruby web-development dressed in a DSL

Details:

It was discovered that Sinatra did not properly handle header parsing,
causing ETag generation to hang when given specific input. A remote
attacker could possibly use this issue to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
ruby-sinatra 2.0.8.1-2+deb11u1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
ruby-sinatra 2.0.8.1-1ubuntu0.1~esm3
Available with Ubuntu Pro

Ubuntu 18.04 LTS
ruby-sinatra 1.4.8-1ubuntu0.1~esm3
Available with Ubuntu Pro

Ubuntu 16.04 LTS
ruby-sinatra 1.4.7-3ubuntu0.1~esm3
Available with Ubuntu Pro

After a standard system update you need to restart any applications that
use ruby-sinatra to make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8624-1
CVE-2025-61921



[USN-8602-1] libinput vulnerability


==========================================================================
Ubuntu Security Notice USN-8602-1
July 23, 2026

libinput vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

libinput could be made to run programs as an administrator.

Software Description:
- libinput: Input device management and event handling library

Details:

It was discovered that libinput did not properly escape device
properties. A local attacker could possibly use this issue to inject
arbitrary udev properties and execute arbitrary code as root.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
libinput-bin 1.20.0-1ubuntu0.4
libinput-dev 1.20.0-1ubuntu0.4
libinput10 1.20.0-1ubuntu0.4

Ubuntu 20.04 LTS
libinput-bin 1.15.5-1ubuntu0.3+esm1
Available with Ubuntu Pro
libinput-dev 1.15.5-1ubuntu0.3+esm1
Available with Ubuntu Pro
libinput10 1.15.5-1ubuntu0.3+esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8602-1
CVE-2026-50292

Package Information:
https://launchpad.net/ubuntu/+source/libinput/1.20.0-1ubuntu0.4



[USN-8614-1] Python vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8614-1
July 27, 2026

python2.7, python3.5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Python.

Software Description:
- python2.7: An interactive high-level object-oriented language
- python3.5: An interactive high-level object-oriented language

Details:

It was discovered that Python incorrectly handled expanding environment
variables in os.path.expandvars() when the input was user-controlled. An
attacker could possibly use this issue to cause Python to consume
resources, leading to a denial of service. (CVE-2025-6075)

It was discovered that Python incorrectly handled certain malformed
HTML-like markup in the HTMLParser module, raising an uncaught exception.
A remote attacker could possibly use this issue to cause applications that
parse untrusted input to crash, resulting in a denial of service.
(CVE-2025-69534)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
libpython2.7-minimal 2.7.12-1ubuntu0~16.04.18+esm21
Available with Ubuntu Pro
libpython2.7-stdlib 2.7.12-1ubuntu0~16.04.18+esm21
Available with Ubuntu Pro
libpython3.5-stdlib 3.5.2-2ubuntu0~16.04.13+esm24
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8614-1
CVE-2025-6075, CVE-2025-69534



[USN-8625-1] OpenSSL vulnerability


==========================================================================
Ubuntu Security Notice USN-8625-1
July 30, 2026

openssl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

OpenSSL could be made to crash if it received specially crafted network
traffic.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

It was discovered that OpenSSL incorrectly allocated memory buffers in the
SSL/TLS state machine when receiving handshake data. A remote attacker
could possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue is known as the "HollowByte"
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libssl3t64 3.5.5-1ubuntu3.3
openssl 3.5.5-1ubuntu3.3

Ubuntu 24.04 LTS
libssl3t64 3.0.13-0ubuntu3.12
openssl 3.0.13-0ubuntu3.12

Ubuntu 22.04 LTS
libssl3 3.0.2-0ubuntu1.26
openssl 3.0.2-0ubuntu1.26

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8625-1
https://launchpad.net/bugs/2161371

Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.3
https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.12
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.26