Ubuntu Security Notices

Developers issue an Ubuntu Security Notice when a security issue is fixed in an official Ubuntu package. You can find additional guidance for high-profile vulnerabilities in the Ubuntu Vulnerability Knowledge Base section.

To report a security vulnerability in an Ubuntu package, please contact the Security Team.

The Security Team also produces OVAL files for each Ubuntu release. These are an industry-standard machine-readable format dataset that contain details of all known security vulnerabilities and fixes relevant to the Ubuntu release, and can be used to determine whether a particular patch is appropriate. OVAL files can also be used to audit a system to check whether the latest security fixes have been applied.

Subscribe for updates  

Mailing list Atom RSS

Search USNs

USN ID, name, description or CVE ID contains


Filter by Ubuntu release

14 - 23 of 10743 results

2 June 2026

Several security issues were fixed in MySQL.

  • Ubuntu 26.04 LTS,
  • 25.10 ,
  • 24.04 LTS,
  • 22.04 LTS

2 June 2026

GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file.

  • Ubuntu 20.04 LTS,
  • 18.04 LTS

CVE ID

CVE-2026-2921


2 June 2026

XZ Utils could be made to crash or run programs as your login if it received specially crafted input.

  • Ubuntu 25.10 ,
  • 24.04 LTS,
  • 22.04 LTS,
  • 20.04 LTS,
  • 18.04 LTS,
  • 16.04 LTS,
  • 14.04 LTS

1 June 2026

The system could be compromised under certain conditions.

  • Ubuntu 14.04 LTS

1 June 2026

Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.

  • Ubuntu 20.04 LTS,
  • 18.04 LTS,
  • 16.04 LTS,
  • 14.04 LTS

1 June 2026

sslh could be made to overwrite files.

  • Ubuntu 26.04 LTS,
  • 25.10 ,
  • 24.04 LTS,
  • 22.04 LTS,
  • 20.04 LTS,
  • 18.04 LTS,
  • 16.04 LTS

1 June 2026

NNCP could allow unintended access to files.

  • Ubuntu 25.10 ,
  • 24.04 LTS,
  • 22.04 LTS

1 June 2026

haveged could be made to run programs as an administrator.

  • Ubuntu 26.04 LTS,
  • 25.10 ,
  • 24.04 LTS,
  • 22.04 LTS

1 June 2026

Evolution Data Server could be made to remove files.

  • Ubuntu 20.04 LTS,
  • 18.04 LTS

CVE ID

CVE-2026-2604


1 June 2026

Qt Declarative could be made to use excessive resources if it received specially crafted input.

  • Ubuntu 24.04 LTS,
  • 22.04 LTS,
  • 20.04 LTS


Resources


Further reading

  • Loading...

Get up to 15 years of security
maintenance for your new or established systems

Get up to 15 years of security maintenance for your entire Ubuntu Archive. Keep your systems stable with security backporting and avoid forced upgrades.