USN-8600-1

Source
https://ubuntu.com/security/notices/USN-8600-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8600-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8600-1
Upstream
Related
Published
2026-07-23T14:41:05Z
Modified
2026-07-24T01:35:03.100635581Z
Summary
libxpm vulnerability
Details

Naoki Wakamatsu discovered that libXpm did not properly validate file boundaries when processing XPM image files. An attacker could possibly use this issue to cause libXpm to crash, resulting in a denial of service.

References

Affected packages

Ubuntu:22.04:LTS / libxpm

Package

Name
libxpm
Purl
pkg:deb/ubuntu/libxpm?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.5.12-1ubuntu0.22.04.3

Affected versions

1:3.*
1:3.5.12-1
1:3.5.12-1build1
1:3.5.12-1build2
1:3.5.12-1ubuntu0.22.04.1
1:3.5.12-1ubuntu0.22.04.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libxpm4",
            "binary_version": "1:3.5.12-1ubuntu0.22.04.3"
        },
        {
            "binary_name": "xpmutils",
            "binary_version": "1:3.5.12-1ubuntu0.22.04.3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8600-1.json"
cves_map
{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2026-4367"
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}

Ubuntu:24.04:LTS / libxpm

Package

Name
libxpm
Purl
pkg:deb/ubuntu/libxpm?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.5.17-1ubuntu0.24.04.1

Affected versions

1:3.*
1:3.5.12-1.1ubuntu1
1:3.5.17-1
1:3.5.17-1build1
1:3.5.17-1build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libxpm4",
            "binary_version": "1:3.5.17-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "xpmutils",
            "binary_version": "1:3.5.17-1ubuntu0.24.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8600-1.json"
cves_map
{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2026-4367"
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}

Ubuntu:26.04:LTS / libxpm

Package

Name
libxpm
Purl
pkg:deb/ubuntu/libxpm?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.5.17-1ubuntu0.26.04.1

Affected versions

1:3.*
1:3.5.17-1build2
1:3.5.17-1build3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libxpm4",
            "binary_version": "1:3.5.17-1ubuntu0.26.04.1"
        },
        {
            "binary_name": "xpmutils",
            "binary_version": "1:3.5.17-1ubuntu0.26.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8600-1.json"
cves_map
{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2026-4367"
        }
    ],
    "ecosystem": "Ubuntu:26.04:LTS"
}