Ubuntu alert USN-8386-1 (nano)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8386-1] Nano vulnerabilities | |
| Date: | Thu, 04 Jun 2026 23:18:19 +0000 | |
| Message-ID: | <E1wVHKN-0007ZF-Cn@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8386-1 June 04, 2026 nano vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Nano. Software Description: - nano: GNU nano editor Details: Michał Majchrowicz and Marcin Wyczechowski discovered that Nano created the ~/.local directory with incorrect permissions. In environments with permissive umask settings, a local attacker could possibly use this issue to inject a malicious launcher file, resulting in information disclosure or other unintended actions. (CVE-2026-6842) Michał Majchrowicz and Marcin Wyczechowski discovered that Nano incorrectly handled directory names when updating the status line. A local attacker could possibly use this issue to cause Nano to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6843) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS nano 8.7.1-1ubuntu0.1 nano-tiny 8.7.1-1ubuntu0.1 Ubuntu 25.10 nano 8.4-1ubuntu0.1 nano-tiny 8.4-1ubuntu0.1 Ubuntu 24.04 LTS nano 7.2-2ubuntu0.2 nano-tiny 7.2-2ubuntu0.2 Ubuntu 22.04 LTS nano 6.2-1ubuntu0.2 nano-tiny 6.2-1ubuntu0.2 Ubuntu 20.04 LTS nano 4.8-1ubuntu1.1+esm1 Available with Ubuntu Pro nano-tiny 4.8-1ubuntu1.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS nano 2.9.3-2ubuntu0.1~esm2 Available with Ubuntu Pro nano-tiny 2.9.3-2ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8386-1 CVE-2026-6842, CVE-2026-6843 Package Information: https://launchpad.net/ubuntu/+source/nano/8.7.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/nano/8.4-1ubuntu0.1 https://launchpad.net/ubuntu/+source/nano/7.2-2ubuntu0.2 https://launchpad.net/ubuntu/+source/nano/6.2-1ubuntu0.2
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoiBX4ACgkQcpJm3tlz hgHWQg/+LcpheZh+EG1edj9GkgeqtOLL3Qw+Nb/E5HzW0AjjOQQmrRA88tAKxFW8 3K8q6j7fpnfVKW/+UhyUXX/0rCdQnWWudMFGsYO3nqOrSXCqIfN9+hlcTmqzvxO1 4R+dP9EEVDGhy/YRL+zlKZ5XvdyVdjqZY+3bHcj6jtEoLEGKVm1nNZ1X9PI9ArUA heAr6Rn36uh9HBtQk3yYy42Rn0M1kn6MbHJSUeJQOjxDcCbWyDUqp+bAzuVNtvZ0 MILKxT3r9+abAPhLUZgQeIK5D2gURvmShsgluAp6fgLqnawmvjsdvJre/ry8Zncq nbxdbF/s6jDa6Qi6HJmH0du90+u7Fb7ITdwOD8J7fd/XhU8CcBvPAEVdEBqVwJ8x UjfJTKapAqsiZT3M/AvzJBL3D3y1iIElAX3bS9dNiE2luv6EOdsQ4k31xGTMw04Q ySlbY0hlRhgvQKY8cRjYddPNaw5bEBc7niq3daIHnb6P4FiokO9SgATExWFr2pKI P/UV9YOs2XJMlFq3eZT0P31CVhlim0TknxK91iUXFBveeAYNqmY0Fo5gle36pLwN /jSQoEzbErL9tJj58xZSKNYwq4VPe5rNYuISeM4Z7U2vG/9sKBarOY/VnG4tAa+1 pRPCxbJkGQmR4XNgfRPWtPOiCtJYhtGDWLwjACDsslgldd5pdRg= =iU/c -----END PGP SIGNATURE-----
