========================================================================== Ubuntu Security Notice USN-8404-1 June 08, 2026 transmission vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Transmission could allow unintended actions if a user visited a malicious website. Software Description: - transmission: lightweight BitTorrent client Details: It was discovered that Transmission had a clickjacking weakness in the browser-facing WebUI and RPC response paths. An attacker could possibly use this issue to trick users into performing unintended actions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS transmission 4.1.1+dfsg-1ubuntu1.1 transmission-daemon 4.1.1+dfsg-1ubuntu1.1 Ubuntu 25.10 transmission 4.1.0~beta2+dfsg-3ubuntu1.1 transmission-daemon 4.1.0~beta2+dfsg-3ubuntu1.1 Ubuntu 24.04 LTS transmission 4.0.5-1ubuntu0.1 transmission-daemon 4.0.5-1ubuntu0.1 Ubuntu 22.04 LTS transmission 3.00-2ubuntu2.2 transmission-daemon 3.00-2ubuntu2.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8404-1 CVE-2026-38978 Package Information: https://launchpad.net/ubuntu/+source/transmission/4.1.1+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.1.0~beta2+dfsg-3ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.0.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/transmission/3.00-2ubuntu2.2
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Transmission could allow unintended actions if a user visited a malicious website. Software Description: - transmission: lightweight BitTorrent client Details: It was discovered that Transmission had a clickjacking weakness in the browser-facing WebUI and RPC response paths. An attacker could possibly use this issue to trick users into performing unintended actions.
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS transmission 4.1.1+dfsg-1ubuntu1.1 transmission-daemon 4.1.1+dfsg-1ubuntu1.1 Ubuntu 25.10 transmission 4.1.0~beta2+dfsg-3ubuntu1.1 transmission-daemon 4.1.0~beta2+dfsg-3ubuntu1.1 Ubuntu 24.04 LTS transmission 4.0.5-1ubuntu0.1 transmission-daemon 4.0.5-1ubuntu0.1 Ubuntu 22.04 LTS transmission 3.00-2ubuntu2.2 transmission-daemon 3.00-2ubuntu2.2 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8404-1
CVE-2026-38978
https://launchpad.net/ubuntu/+source/transmission/4.1.1+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.1.0~beta2+dfsg-3ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.0.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/transmission/3.00-2ubuntu2.2
Get the latest Linux and open source security news straight to your inbox.