Ubuntu alert USN-8408-1 (php-twig)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8408-1] Twig vulnerability | |
| Date: | Mon, 08 Jun 2026 20:56:05 +0000 | |
| Message-ID: | <E1wWh0v-0005an-GK@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8408-1 June 08, 2026 php-twig vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Twig could be made to run programs if it received specially crafted network traffic from an authenticated user. Software Description: - php-twig: Flexible, fast, and secure template engine for PHP Details: It was discovered that Twig did not properly validate PHP callables when using a source policy. An authenticated user could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS php-twig 3.23.0-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8408-1 CVE-2026-24425
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmonLEoACgkQcpJm3tlz hgGG+A/9Hds9tKC0EJBOeeGW8hv1iSOyfhwaZwJFLdXnwsjS1WtEipB2sVvxeEvf 8z350fT39O/GgWAsd7PgBlc3zNCpA004mhsyOofmnUSUUSLkTSZvBKAaArdUtiip 7e1WZyGcW28d+bh0Clyzm5m7yDupBOm4UGcRwPHTpgZ/2GFkO3rKm8mx+A1jvMxw nsq4JaiDkh1TanqisThKxokoUHPTbyJUiDcGV4JsjztvavjLSrEBTvcutByn/lMZ sYREf22ZXoU4shqcWygBrsb41WvVxWzBvGy2UYbfP/DLD/pzaOqBzLzOK2vYixbK sOVbLF8Mn0wCqjiavtwa606tvjg16JkVNLZ60R5n9jP8HBzSD7BhU442xhfZjwqk 2/34WSNIvyyv8Mv1RKqzOTFRSiE2uEmdJUZlYgx/u8vX4bepfsd/OfrkFw3N+S/k UbjU2ne3fgtrPKstgaRJ+AWKf7IP8NLbl6kaTdHVGAcD3rtBERb0UJRYp+WToEPA OnqRuCtXVJuBjA6LWfcF/GhsVsmhuP4AS+y3xXavM2dGrE8Wj54td75AQ9LIU0tt 3b7Eofcfrc6Ot1dtXrhbde47YRdf1O+oYwzEjbHZe/ge8iDE8+frqDREOwGAkHmG hF51PrwsUXYUi6lHsMTA78krDTH+6y2oTRsM74Oen2yJIYiESEo= =4W5x -----END PGP SIGNATURE-----
