Ubuntu alert USN-8465-1 (mina2)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8465-1] Apache MINA vulnerabilities | |
| Date: | Thu, 25 Jun 2026 14:30:38 +0000 | |
| Message-ID: | <E1wcl6E-0000Zt-AL@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8465-1 June 23, 2026 mina2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Apache MINA could be made to run programs if it received specially crafted network traffic. Software Description: - mina2: Apache MINA is a network application framework which helps users develop high performance and high scalability network applications easily Details: It was discovered that Apache MINA lacked an acceptMatchers allowlist mechanism to restrict which classes could be deserialized. An attacker could use this to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-52046) It was discovered that Apache MINA's deserialization filter could be bypassed via multiple code paths. An attacker could use this to execute arbitrary code by sending a specially crafted serialized object over the network. (CVE-2026-42778, CVE-2026-42779, CVE-2026-47065) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libmina2-java 2.2.1-4ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS libmina2-java 2.2.1-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libmina2-java 2.1.5-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8465-1 CVE-2024-52046, CVE-2026-42778, CVE-2026-42779, CVE-2026-47065
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo9JBcACgkQcpJm3tlz hgHb2BAAqKNIoeFBIcSqI1jBq3cNaTNrwHJdRs6q1FfTsc5j+LrRE7k01Qmsucs0 XGgHTvojeCjjOUiEoqKSHBWW9fXF3rssoMCDZSKJb+9WGrr0S81CRPCgf8F+hHcO rpXvzGCkEvtY76u/0yGRFm/84NrfDq17rKNIxV5ff6lblvRHLxshVVmiODipW1TA T2MxroOY3pV0LcQXkweuDPBF9ZULYw0LY0eiYEH4yUmscCxxrkvD9aEBx52xPBIx Yq8+d/SNI+rYMFLqY7bWdi0xHidnCRWiePpbVMuEuM+vT5DlAR0fxvjiUu0N2Aya IS0kybhfJBNa5rfCze6XhImPCtxFCUsfNNvhYw+NeNAKCOmaR5NrXdfQhRWo29uR 1qouhtgGhpF78x8u1xqDgUOzIPHjE3XtKxFE2a4mfNZY20kQdKL6lPjQ9v9ocJFv RR+ODVETykZfQ2gYTzf9LQJlgUFAFur4wkFirg4VdFUusFD0zwxPY6Xf3OuiNVk6 tZ5yq/jQlNMTrWC0FDjQRAFdIb9gx0IVzdIMbpNzGqhQS+Dy+GSrfGQMxzIttNJH qq4Ikl3icTEsBiR/uFShZIDCNgpvmUuU9RYDdbhh30bg3U44+H9pg8WB9a62N+X8 8+rbfgckk5A/9wy7TBqC96UQMCb1U/4l1SDIrUJNurQRPJhpxhs= =OkqI -----END PGP SIGNATURE-----
