Security Advisory – 17 Feb 2026

Security fixes and advisories that landed overnight. 17 Feb 2026 13:00 GMT.

Top items

Ubuntu

USN-8044-1: alsa-lib vulnerability

Alsa-lib incorrectly handled the topology mixer control decoder. A local attacker could use a specially crafted topology file to crash alsa-lib, resulting in denial of service or possibly execute arbitrary code.

  • Published: 16 Feb 2026 14:01 GMT
  • CVEs: Not stated in the advisory excerpt
  • Notes: local attacker using a specially crafted topology file

USN-8043-1: GnuTLS vulnerabilities

GnuTLS incorrectly handled malicious certificates containing a large number of name constraints and subject alternative names, which could let a remote attacker cause resource consumption and denial of service (CVE-2025-14831). GnuTLS also incorrectly handled certain PKCS11 token labels, which a remote attacker could use to crash GnuTLS, causing denial of service or possibly execute arbitrary code (CVE-2025-9820).

  • Published: 16 Feb 2026 13:53 GMT
  • CVEs: CVE-2025-14831, CVE-2025-9820
  • Notes: malicious certificates with many name constraints and subject alternative names

Related posts

Privacy boundaries when AI touches government records

AI governance gets awkward fast when government records are involved, because the model is rarely the problem. The problem is the sloppy boundary around it, the sort I have seen quietly turn a...

Metadata schema choices for content libraries

Structured metadata only works when it matches how people actually retrieve content. I have seen neat schemas fail as soon as the library meets real records, and tarot makes the problem obvious. If...

Federation trade-offs in self-hosted social feeds

Federation looks tidy until you let it touch the edges, and then the odd cases arrive fast. I prefer self-hosted social feeds that stay explicit about what is local, what is remote, and what should...