security advisory

Security Advisory – 24 Feb 2026

Security fixes and advisories. The feed was updated 24 Feb 2026 11:00 GMT.

Top items

Ubuntu

USN-8057-1: GIMP vulnerabilities

Multiple GIMP parsers could be triggered by maliciously-crafted files to cause out-of-bounds writes and indexing errors. An attacker could possibly use these issues to cause a denial of service or execute arbitrary code in affected Ubuntu releases.

  • Published: 23 Feb 2026 20:09 GMT
  • CVEs: CVE-2017-17785, CVE-2025-2761, CVE-2025-10922, CVE-2025-14425, CVE-2025-15059
  • Notes: maliciously-crafted files can cause out-of-bounds writes

USN-8051-2: libssh vulnerabilities

Multiple issues in libssh affected clients and SCP/SFTP handling, including crashes and path sanitisation errors. Remote or local attackers could cause denial of service, overwrite files outside the working directory or possibly execute arbitrary code.

  • Published: 23 Feb 2026 19:56 GMT
  • CVEs: CVE-2025-8277, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968
  • Notes: SCP client could overwrite files outside of the working directory

USN-8056-1: U-Boot vulnerabilities

U-Boot parsing and filesystem handling errors could be triggered by specially crafted DHCP responses and malformed squashfs or EXT4 images. An attacker could obtain sensitive memory contents, cause crashes resulting in denial of service, or possibly execute arbitrary code.

  • Published: 23 Feb 2026 13:04 GMT
  • CVEs: CVE-2024-42040, CVE-2024-57254, CVE-2024-57255, CVE-2024-57256, CVE-2024-57257, CVE-2024-57258
  • Notes: attacker on the local network could obtain sensitive memory contents

USN-8055-1: Evolution Data Server vulnerability

Evolution Data Server incorrectly handled removing local cache files which could be abused. An attacker could possibly use this issue to cause Evolution Data Server to remove arbitrary files.

  • Published: 23 Feb 2026 12:50 GMT
  • CVEs: Not stated in the advisory excerpt
  • Notes: could remove arbitrary files

USN-8054-1: DjVuLibre vulnerabilities

DjVuLibre could be forced to execute a division by zero and mishandle memory operations when processing crafted files. A remote attacker could cause applications to stop responding or crash, or possibly execute arbitrary code on affected older releases.

  • Published: 23 Feb 2026 12:38 GMT
  • CVEs: CVE-2021-46312, CVE-2025-53367
  • Notes: execute a division by zero
Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Prev
Securing your homelab with effective VLAN strategies
img securing your homelab with effective vlan strategies vlan configuration

Securing your homelab with effective VLAN strategies

Unlock the potential of your homelab with effective VLAN configuration

Next
Logging and auditing AI actions in your homelab
img logging and auditing ai actions in your homelab ai management

Logging and auditing AI actions in your homelab

Log every AI action, store structured JSON events, and protect the audit trail

You May Also Like