|
|
Log in / Subscribe / Register

Ubuntu alert USN-8238-2 (editorconfig-core)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8238-2] EditorConfig vulnerability
Date:  Tue, 02 Jun 2026 16:53:33 +0000
Message-ID:  <E1wUSMv-0002aZ-8h@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8238-2 June 02, 2026 editorconfig-core vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: EditorConfig could be made to crash if it opened a specially crafted file. Software Description: - editorconfig-core: coding style indenter across editors Details: USN-8238-1 fixed a vulnerability in EditorConfig. This update contains the corresponding fix for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. Original advisory details: It was discovered that EditorConfig incorrectly handled specially crafted configuration files. A local attacker could possibly use this issue to cause EditorConfig to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS editorconfig 0.12.5-2ubuntu0.1~esm3 Available with Ubuntu Pro editorconfig-doc 0.12.5-2ubuntu0.1~esm3 Available with Ubuntu Pro libeditorconfig-dev 0.12.5-2ubuntu0.1~esm3 Available with Ubuntu Pro libeditorconfig0 0.12.5-2ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS editorconfig 0.12.1-1.1+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro editorconfig-doc 0.12.1-1.1+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro libeditorconfig-dev 0.12.1-1.1+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro libeditorconfig0 0.12.1-1.1+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS editorconfig 0.12.1-1.1ubuntu0.18.04.1~esm3 Available with Ubuntu Pro editorconfig-doc 0.12.1-1.1ubuntu0.18.04.1~esm3 Available with Ubuntu Pro libeditorconfig-dev 0.12.1-1.1ubuntu0.18.04.1~esm3 Available with Ubuntu Pro libeditorconfig0 0.12.1-1.1ubuntu0.18.04.1~esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS editorconfig 0.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro editorconfig-doc 0.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro libeditorconfig-dev 0.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro libeditorconfig0 0.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8238-2 https://ubuntu.com/security/notices/USN-8238-1 CVE-2026-40489


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmofChoACgkQcpJm3tlz hgFHMA//VRMED68ruzi55yZkOH18YIM9JLhPsFYpDmibqFmkXkQ8TTno5tDhtbPV PxqwIfuYna+wFRmtlb7lqMABupviU+G9X2XKH0qoz75h+bq2jt2l1s0Vm1YumQYZ tSvZyD3BjZGfJjxqccDX03cpLf18lzGaGin94DHXaftq6nELyp/RHcyADsNk4AoW Ywm+aiEgHpFLKJmo437bG+YogY8RVItbi+Hs0AeJ57VOh0xenNFhdHRNlBoBP03Q lx/c7HhCq5NVHEq6oymla1XToRX+Ma/cR4nabscTjeO9NZHi1EyLQawfjON/3/lP ne7gaQpU8AGoCKHiI7LE0DnAylnWvf95PnXS3jPui3aMyugzvogZuLV3cij9oGz6 sgPsYbwHOQjymcD2MUthqPpZrkyfpMflkfTus6F7jPwiZ9mcvcgnVW89DMIGwBWv U5jc1n741sXdsV1Jea6Z/9I3QA2vXS95SFG4dCPiPajXJd+U74kLvZCWg9LDH/qz pWMQIm+PRsUZdM7RWevX4BFyRjaviJiJwiUpLsZczbmrF1qmCMnDjIK9utBz8zgy u94DBoQytI49bkzdBhe9nbcA6Jyldv3AxxL7q9D0Q8SmexxQ0679oWmPQpI5Z7WE Mr9YqPZZZlDF2UVGJ1OJAV+JpKlcuIrdMiX0b+v71Uuukjwbc0Q= =58Uh -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds