Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in Luanti.. ========================================================================== Ubuntu Security Notice USN-8366-1 June 02, 2026 luanti vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Several security issues were fixed in Luanti. Software Description: - luanti: free and open-source voxel game engine Details: It was discovered that Luanti, when using LuaJIT, did not properly enforce Lua sandbox restrictions. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-40959) It was discovered that Luanti did not properly restrict access to insecure environments. An attacker could possibly use this issue to obtain unintended access to the insecure environment or HTTP API. (CVE-2026-40960) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS luanti 5.10.0+dfsg-5+deb13u1build0.26.04.1 luanti-data 5.10.0+dfsg-5+deb13u1build0.26.04.1 luanti-server 5.10.0+dfsg-5+deb13u1build0.26.04.1 Ubuntu 25.10 luanti 5.10.0+dfsg-5+deb13u1build0.25.10.1 luanti-data 5.10.0+dfsg-5+deb13u1build0.25.10.1 luanti-server 5.10.0+dfsg-5+deb13u1build0.25.10.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8366-1 CVE-2026-40959, CVE-2026-40960 Package Information: https://launchpad.net/ubuntu/+source/luanti/5.10.0+dfsg-5+deb13u1build0.26.04.1 https://launchpad.net/ubuntu/+source/luanti/5.10.0+dfsg-5+deb13u1build0.25.10.1 . Several security issues in Luanti on Ubuntu fixed. Critical remote code execution vulnerability and HTTP API access improved.. Luanti Security Ubuntu Update. . Severity: Critical. LinuxSecurity.comTeam
Two security issues were discovered in Luanti, a multiplayer infinite-world block sandbox game, which could result in incomplete restrictions for installed mods or sandbox escape. For the stable distribution (trixie), these problems have been fixed in version 5.10.0+dfsg-5+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6217-1
An update that solves one vulnerability can now be installed.. # luanti-5.11.0-1.1 on GA media Announcement ID: openSUSE-SU-2025:14825-1 Rating: moderate Cross-References: * CVE-2022-35978 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the luanti-5.11.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * luanti 5.11.0-1.1 * luanti-data 5.11.0-1.1 * luanti-lang 5.11.0-1.1 * luantiserver 5.11.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2022-35978.html . The latest luanti-5.11.0-1.1 security update in openSUSE Tumbleweed fixes vulnerabilities of moderate severity, enhancing system protection and stability. luanti, openSUSE, software security, Tumbleweed update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.