Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
AccountsService could be made to run programs as an administrator if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8580-2 July 21, 2026 accountsservice vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: AccountsService could be made to run programs as an administrator if it opened a specially crafted file. Software Description: - accountsservice: query and manipulate user account information Details: USN-8580-1 fixed vulnerabilities in AccountsService. This update provides the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS accountsservice 0.6.55-0ubuntu12~20.04.7+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS accountsservice 0.6.45-1ubuntu1.3+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS accountsservice 0.6.40-2ubuntu11.6+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS accountsservice 0.6.35-0ubuntu7.3+esm4 Available with Ubuntu Pro After a standard systemupdate you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8580-2 https://ubuntu.com/security/notices/USN-8580-1 CVE-2026-61897, CVE-2026-61898 . AccountsService update for Ubuntu addresses critical security flaws that allow local attackers to execute commands as admins.. AccountsService updates, Ubuntu security fix, local execution flaw. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a potential buffer overflow in xz-utils, a popular data-compression utility and library. CVE-2026-34743 If the lzma_index_decoder function was used to decode an index that contained no records, the resulting lzma_index was left in a. Debian LTS Advisory DLA-4690-1
Several security issues were fixed in ImageMagick.. ========================================================================== Ubuntu Security Notice USN-8558-1 July 20, 2026 imagemagick vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in ImageMagick. Software Description: - imagemagick: Image manipulation programs and library Details: It was discovered that ImageMagick did not limit mutual references between MVG files. An attacker could possibly use this issue to cause a stack overflow, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-68950) It was discovered that the ImageMagick MSL coder destroyed a cloned image twice when an MSL script failed. An attacker could possibly use this issue to cause a use-after-free, resulting in a denial of service, or arbitrary code execution. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-28688) It was discovered that the ImageMagick VIFF image encoder did not properly validate the packet count, leading to an integer overflow on 32-bit systems. An attacker could possibly use this issue to cause an out-of- bounds heap write, resulting in a denial of service. (CVE-2026-33900) It was discovered that ImageMagick did not properly handle the column offset when sampling an image. An attacker could possibly use this issue to cause ImageMagick to read out of bounds, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-33905) Updateinstructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS imagemagick-7-common 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro imagemagick-7.q16 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro imagemagick-7.q16hdri 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libimage-magick-q16-perl 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagick++-7.q16-5 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagick++-7.q16-dev 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagick++-7.q16hdri-5 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagick++-7.q16hdri-dev 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7-arch-config 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7.q16-10 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7.q16-10-extra 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7.q16-dev 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7.q16hdri-10 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7.q16hdri-10-extra 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickcore-7.q16hdri-dev 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickwand-7-headers 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickwand-7.q16-10 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickwand-7.q16-dev 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickwand-7.q16hdri-10 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libmagickwand-7.q16hdri-dev 8:7.1.2.18+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS imagemagick-6-common 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro imagemagick-6.q16 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagick++-6.q16-9t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagick++-6.q16hdri-9t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickcore-6.q16-7-extra 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickcore-6.q16-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-7-extra 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickwand-6-headers 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickwand-6.q16-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickwand-6.q16hdri-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 Available with Ubuntu Pro Ubuntu 22.04 LTS imagemagick-6-common 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro imagemagick-6.q16 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with UbuntuPro libmagick++-6.q16-8 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagick++-6.q16hdri-8 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6-arch-config 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6.q16-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6.q16-6-extra 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6.q16hdri-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6.q16hdri-6-extra 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickwand-6.q16-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickwand-6.q16hdri-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12 Available with UbuntuPro Ubuntu 20.04 LTS imagemagick-6-common 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro imagemagick-6.q16 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagick++-6.q16-8 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagick++-6.q16hdri-8 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickcore-6.q16-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickcore-6.q16-6-extra 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickcore-6.q16hdri-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickcore-6.q16hdri-6-extra 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickwand-6.q16-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickwand-6.q16hdri-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12 Available with Ubuntu Pro Ubuntu 18.04 LTS imagemagick-6-common 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro imagemagick-6.q16 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagick++-6.q16-7 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagick++-6.q16hdri-7 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickcore-6.q16-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickcore-6.q16-3-extra 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with UbuntuPro libmagickcore-6.q16hdri-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickcore-6.q16hdri-3-extra 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickwand-6.q16-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickwand-6.q16hdri-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm14 Available with Ubuntu Pro Ubuntu 16.04 LTS imagemagick-6.q16 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro imagemagick-common 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagickwand-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.8.9.9-7ubuntu5.16+esm22 Available with Ubuntu Pro Ubuntu 14.04 LTS imagemagick 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro imagemagick-common 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagick++-dev 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagick++5 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagickcore-dev 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagickcore5 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagickcore5-extra 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagickwand-dev 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro libmagickwand5 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro perlmagick 8:6.7.7.10-6ubuntu3.13+esm23 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8558-1 CVE-2025-68950, CVE-2026-28688, CVE-2026-33900, CVE-2026-33905 . Multiple security issues have been fixed in ImageMagick packages for Ubuntu LTS releases, including critical flaws that can lead to denial of service.. ImageMagick Security, Ubuntu Update, System Security Issues, Critical Flaws. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in jbig2dec.. ========================================================================== Ubuntu Security Notice USN-8582-1 July 21, 2026 jbig2dec vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in jbig2dec. Software Description: - jbig2dec: JBIG2 decoder library Details: Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an out-of-bounds read vulnerability in its command-line tool. An attacker could possibly use this issue to cause jbig2dec to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-46361) It was discovered that jbig2dec had an integer overflow in the jbig2_arith_iaid_ctx_new() function. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-38076) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS jbig2dec 0.20-1ubuntu0.26.04.1 libjbig2dec0 0.20-1ubuntu0.26.04.1 Ubuntu 24.04 LTS jbig2dec 0.20-1ubuntu0.24.04.1 libjbig2dec0 0.20-1ubuntu0.24.04.1 Ubuntu 22.04 LTS jbig2dec 0.19-3ubuntu0.1 libjbig2dec0 0.19-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8582-1 CVE-2023-46361, CVE-2026-38076 Package Information: https://launchpad.net/ubuntu/+source/jbig2dec/0.20-1ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/jbig2dec/0.20-1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/jbig2dec/0.19-3ubuntu0.1 . Multiple security flaws in jbig2dec identified, leading to possible denial of service attacks in Ubuntu systems.. Ubuntu updates, jbig2dec flaws,Ubuntu security, denial of service, vulnerability updates. . Severity: Important. LinuxSecurity.com Team
AccountsService could be made to run programs as an administrator if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8580-1 July 21, 2026 accountsservice vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: AccountsService could be made to run programs as an administrator if it opened a specially crafted file. Software Description: - accountsservice: query and manipulate user account information Details: It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS accountsservice 23.13.9-8ubuntu5.2 libaccountsservice0 23.13.9-8ubuntu5.2 Ubuntu 24.04 LTS accountsservice 23.13.9-2ubuntu6.1 libaccountsservice0 23.13.9-2ubuntu6.1 Ubuntu 22.04 LTS accountsservice 22.07.5-2ubuntu1.6 libaccountsservice0 22.07.5-2ubuntu1.6 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8580-1 CVE-2026-61897, CVE-2026-61898 Package Information: https://launchpad.net/ubuntu/+source/accountsservice/23.13.9-8ubuntu5.2 https://launchpad.net/ubuntu/+source/accountsservice/23.13.9-2ubuntu6.1 https://launchpad.net/ubuntu/+source/accountsservice/22.07.5-2ubuntu1.6 . A critical issue in Ubuntu's AccountsService could allow local attackers to run commands as an administrator via crafted files. Immediate update is advised.. Ubuntu AccountsService Arbitrary Execution Local Attack. . Severity: Important. LinuxSecurity.com Team
OpenSSH could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8577-1 July 21, 2026 openssh vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: OpenSSH could allow unintended access to network services. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: USN-8222-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 16.04 LTS. Original advisory details: Vladimir Tokarev discovered that OpenSSH incorrectly handled certificates with the principal name containing a comma character when using user-trusted CA keys in authorized_keys and an authorized_keys principals="" option that lists more than one principal. This could result in inappropriate principal matching, contrary to expectations. (CVE-2026-35414) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS openssh-server 1:7.2p2-4ubuntu2.10+esm9 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8577-1 CVE-2026-35414 . OpenSSH on Ubuntu 16.04 LTS has a critical access flaw; update recommended for enhancing system security.. OpenSSH update, Ubuntu security alert, network services vulnerability. . Severity: Critical. LinuxSecurity.com Team
CUPS could be made to run programs as the lp user if it received specially crafted print job requests.. ========================================================================== Ubuntu Security Notice USN-8578-1 July 21, 2026 CUPS vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: CUPS could be made to run programs as the lp user if it received specially crafted print job requests. Software Description: - cups: Common UNIX Printing System(tm) Details: It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS cups 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-bsd 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-client 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-common 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-core-drivers 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-daemon 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro libcups2 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8578-1 CVE-2026-34980 . CUPS in Ubuntu could be exploited for remote code execution via crafted print jobrequests, update recommended immediately.. CUPS issue, Ubuntu 16.04, control character exploit, remote access threat, system update. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in snapd.. ========================================================================== Ubuntu Security Notice USN-8579-1 July 21, 2026 snapd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in snapd. Software Description: - snapd: Daemon and tooling that enable snap packages Details: James Henstridge discovered that snapd's default apparmor template did not restrict access to systemd-userdbd varlink interface. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2024-5300) Qualys discovered that snap-confine can be tricked to create attacker-controlled files at certain privileged locations. A local attacker could possibly use this issue to bypass intended restrictions and escalate privileges to root. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-8933) Zygmunt Krynicki discovered that snapd's default seccomp template did not restrict the creation of executables with the set-user-ID attribute. A local attacker could possibly use this issue to create and execute setuid binaries. (CVE-2026-15226) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS snapd 2.76+ubuntu26.04.3 Ubuntu 24.04 LTS snapd 2.76+ubuntu24.04.1 Ubuntu 22.04 LTS snapd 2.76+ubuntu22.04.1 Ubuntu 20.04 LTS snapd 2.67.1+20.04ubuntu1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS snapd 2.61.4ubuntu0.18.04.1+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS snapd 2.61.4ubuntu0.16.04.1+esm4 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8579-1 CVE-2024-5300, CVE-2026-15226, CVE-2026-8933 Package Information: https://launchpad.net/ubuntu/+source/snapd/2.76+ubuntu26.04.3 https://launchpad.net/ubuntu/+source/snapd/2.76+ubuntu24.04.1 https://launchpad.net/ubuntu/+source/snapd/2.76+ubuntu22.04.1 . Three critical fixes in snapd for Ubuntu tackle attacker exploits that may expose sensitive data or elevate privileges.. Local Attack, Vulnerability Fix, Snapd Daemon, Ubuntu Security, Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.