Release
Ubuntu 26.04
Ubuntu · 2 targets · 2 artifacts
Release Facts
- Version
- 26.04
- Date
- Architectures
- amd64
- Editions
- -
- Variants
- desktop, live-server
- Protocols
- https, magnet
Quality
- Targets
- 2
- Artifacts
- 2
- Checksums
- 2/2
- Average confidence
- 1.00
- CVEs
- 11
Artifacts
| Artifact | Media | Size | Protocols | Checksums | Quality |
|---|---|---|---|---|---|
| ubuntu-26.04-desktop-amd64.iso | iso | 6.1 GB | https, magnet | 1 | 1.00 |
| ubuntu-26.04-live-server-amd64.iso | iso | 2.7 GB | https, magnet | 1 | 1.00 |
Related CVEs
- CVE-2017-9525
MEDIUM · In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
- CVE-2019-9512
HIGH · Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
- CVE-2026-47326
MEDIUM · Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.
- CVE-2026-47327
LOW · Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.
- CVE-2026-47328
MEDIUM · Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.
- CVE-2026-47329
LOW · Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.
- CVE-2026-47330
LOW · Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.
- CVE-2026-47331
HIGH · Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.
- CVE-2026-47332
MEDIUM · Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.
- CVE-2026-47333
HIGH · Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.
- CVE-2026-47334
MEDIUM · Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.