Denial of Service Vulnerability in Ubuntu's less Command

Denial of Service Vulnerability in Ubuntu's less Command

First seen 6 Mar 2026, 08:11 UTC UbuntuLinuxsecurity 60.1

Article Content

Browse articles
ThreatCluster

A vulnerability in the 'less' command on Ubuntu 14.04 LTS allows attackers to crash the program or execute arbitrary commands through crafted input. This issue affects Ubuntu and its derivatives, posing a risk of denial of service and potential command execution. Users are advised to apply patches to mitigate this threat.

Timeline

2024-02-19
CVE-2022-48624 published
2026-03-05
Ubuntu published USN-8079-1 detailing the less vulnerability
2026-03-06
Linuxsecurity reported on the less vulnerability in Ubuntu 14.04 LTS