Linuxsecurity Critical Authentication Bypass Vulnerability in Ubuntu's Booth Component
Article Content
- •Critical authentication bypass vulnerability in Ubuntu's Booth component.
- •Remote attackers can exploit the flaw to gain unintended access to network services.
- •Users must update to specific package versions and restart Booth to mitigate risks.
A serious authentication bypass vulnerability has been discovered in the Booth component of Ubuntu, affecting versions 18.04, 20.04, 22.04, and 24.04 LTS. The flaw arises from improper validation of message authentication codes, potentially allowing remote attackers to bypass authentication and gain unintended access to network services. CISA has confirmed the exploitation of this flaw, prompting urgent advisories for system updates. Users are advised to update their systems to the specified package versions to mitigate the risk. Affected users should restart Booth after applying the updates to ensure all changes take effect. Ubuntu Pro users have access to long-term security coverage for the affected packages. The vulnerability is cataloged under USN-8832-1, with specific package versions provided for each Ubuntu LTS release. Immediate action is recommended to prevent unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…