Skip to content
Ubuntu 14.04 USN-8555

Ubuntu 14.04 USN-8555

Linuxsecurity LinuxSecurity Advisories September 1, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×

USN-8555-1 introduced a regression in Ubuntu Advantage Tools. Software Description: - ubuntu-advantage-tools: Management tools for Ubuntu Pro Details: USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu 14.04 LTS only, it was discovered that some machines were unable to enable esm-infra-legacy due to a preemptive apt-helper check. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer token in command-line arguments when validating APT credentials. A local attacker could possibly use this issue to obtain sensitive information and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494) Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly validate data received from the contract server when writing APT source files. An attacker could possibly use this issue to inject arbitrary APT configuration and execute a... Read the Full Advisory

USN-8555-1 introduced a regression in Ubuntu Advantage Tools.

Software Description:

- ubuntu-advantage-tools: Management tools for Ubuntu Pro

USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu

14.04 LTS only, it was discovered that some machines were unable to

enable esm-infra-legacy due to a preemptive apt-helper check. This

update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer

token in command-line arguments when validating APT credentials. A local

attacker could possibly use this issue to obtain sensitive information

and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494)

Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly

validate data received from the contract server when writing APT source

files. An attacker could possibly use this issue to inject arbitrary APT

configuration and execute a...

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS ubuntu-advantage-tools 19.7ubuntu0.2 In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8555-2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

CVEs (1)

Platforms (1)