|
|
Log in / Subscribe / Register

Ubuntu alert USN-8229-2 (sed)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8229-2] sed vulnerability
Date:  Thu, 28 May 2026 21:17:55 +0000
Message-ID:  <E1wSi71-0004P6-Je@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8229-2 May 28, 2026 sed vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: sed could be made to overwrite files. Software Description: - sed: GNU stream editor for filtering/transforming text Details: USN-8229-1 fixed a vulnerability in sed. This update provides the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: MichaƂ Majchrowicz and Marcin Wyczechowski discovered that sed incorrectly handled symbolic links when performing in-place edits. A local attacker could possibly use this issue to overwrite arbitrary files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS sed 4.7-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS sed 4.4-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8229-2 https://ubuntu.com/security/notices/USN-8229-1 CVE-2026-5958


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoYpoQACgkQcpJm3tlz hgHSABAAn6N3vu/T+xaEb4xPwhnZIxxRDn16x4t9GXHJmf24l6mRwQsIprjq3jEu Bu5CynXTrWvYXvqWla8zcfIWAhHSLxYmVMN4eQoypjF5AX692kQ1qY2iP5caXkyu HBoaODWEhpxZR1BK3qwkoZqy571qY5U43RN54C/Et36prj4GkYtMx8QOrwAVdYFs pXp69thc+01S6W2qQ/Fbzl017ZYYJ0g+6BUCBIJxleGbJzU290NIlLfdzBQHAi8m vxGJD7aEfQ9EQ8T9Se4mDFpdivmuyqc3L6mK1GUlt14nWNnGhxvwi7tf96Kgh8q8 lOk/9W5eMfE7mnMjUaZcZTFP4CIGV/xtPnEr/3PPlikq9A1z0hONKshLkCWZ4ctI jwiJjIMUA8ZnJo40dfa5Ds+RbRqgIXjMQs2HNNgC00Loxf/Th/WnjekazKqmECDJ r9YDHP68qGu88Oh7ObW+53J5qT1XUPgd9dm6qxYzvFOggmBH+u9ReP5oUzt6dx3O NZQOVkexeyRMfYiDbwRZ7MOy2WUhY8e9fMeQB891MmWSnMXAuo+UcYvhLTb2yks1 tuokSzep0HVZCe+26qndOprZHTT4AhF0JGh//ujrbRK6oSl0dlfYLbAZx/PT9Sgj IdTzKFDO36IJsyeyYPdjQ+w+9ZWnSoVCVHGhjFNdhyAbxGOoJm0= =abkO -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds