opam could be made to install files in unintended locations if it installed a specially crafted package.. ========================================================================== Ubuntu Security Notice USN-8256-1 May 07, 2026 opam vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: opam could be made to install files in unintended locations if it installed a specially crafted package. Software Description: - opam: package manager for OCaml Details: Andrew Nesbitt discovered that opam did not properly validate file destination paths in package install files. An attacker could use this issue to bypass sandbox protections and write files to arbitrary locations, possibly leading to arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS opam 2.5.0-1ubuntu0.1~esm1 Available with Ubuntu Pro opam-installer 2.5.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 25.10 opam 2.3.0-1+deb13u1build0.25.10.1 opam-installer 2.3.0-1+deb13u1build0.25.10.1 Ubuntu 24.04 LTS opam 2.1.5-1ubuntu0.1~esm2 Available with Ubuntu Pro opam-installer 2.1.5-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS opam 2.1.2-1+deb12u1build0.22.04.1 opam-installer 2.1.2-1+deb12u1build0.22.04.1 Ubuntu 20.04 LTS opam 2.0.5-1ubuntu1+esm1 Available with Ubuntu Pro opam-installer 2.0.5-1ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8256-1 CVE-2026-41082 Package Information: https://launchpad.net/ubuntu/+source/opam/2.3.0-1+deb13u1build0.25.10.1 https://launchpad.net/ubuntu/+source/opam/2.1.2-1+deb12u1build0.22.04.1 . opam in Ubuntu has a significant flaw that may allow unintended file installations leading to potential code execution risks.. opam security issue, Ubuntu 26.04 LTS, package manager vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e2fe8f0165 2020-08-13 01:38:09.348906 --------------------------------------------------------------------------------Name : ark Product : Fedora 32 Version : 20.04.3 Release : 3.fc32 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt --------------------------------------------------------------------------------ChangeLog: * Fri Jul 31 2020 Rex Dieter - 20.04.3-3 - backport security fix for CVE-2020-16116 * Mon Jul 27 2020 Fedora Release Engineering - 20.04.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Rex Dieter - 20.04.3-1 - 20.04.3 * Fri Jun 12 2020 Rex Dieter - 20.04.2-1 - 20.04.2 * Wed May 27 2020 Rex Dieter - 20.04.1-1 - 20.04.1 * Sat Mar 7 2020 Rex Dieter - 19.12.3-1 - 19.12.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1862464 - CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory https://bugzilla.redhat.com/show_bug.cgi?id=1862464 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-e2fe8f0165' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.