========================================================================== Ubuntu Security Notice USN-8611-1 July 27, 2026
glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in GNU C Library. Software Description: - glibc: GNU C Library Details: It was discovered that the GNU C Library iconv function incorrectly handled certain IBM character sets. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-4046) It was discovered that the GNU C Library DNS functions incorrectly handled certain DNS server responses when using gethostbyaddr or gethostbyaddr_r. An attacker in a privileged network position could possibly use this issue to cause an application to violate DNS specification or obtain incorrect hostname information. This issue only affected Ubuntu 24.04 LTS. (CVE-2026-4437, CVE-2026-4438) It was discovered that the GNU C Library deprecated debugging functions incorrectly enforced caller-supplied buffer lengths. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-5435) It was discovered that the GNU C Library scanf family of functions contained a heap buffer overflow when processing certain format specifiers. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-5450) It was discovered that the GNU C Library ungetwc function incorrectly handled certain character encodings. An attacker could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2026-5928) It was discovered that the GNU C Library deprecated debugging functions incorrectly validated DNS response record data. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-6238) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libc6 2.43-2ubuntu2.3 Ubuntu 24.04 LTS libc6 2.39-0ubuntu8.8 Ubuntu 22.04 LTS libc6 2.35-0ubuntu3.14 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8611-1 CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238 Package Information: https://launchpad.net/ubuntu/+source/glibc/2.43-2ubuntu2.3 https://launchpad.net/ubuntu/+source/glibc/2.39-0ubuntu8.8 https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.14
signature.asc
Description: OpenPGP digital signature
