Vulnerability in Evolution Data Server Allows File Deletion in Ubuntu Systems

Vulnerability in Evolution Data Server Allows File Deletion in Ubuntu Systems

First seen 1 Jun 2026, 21:22 UTC UbuntuLinuxsecurity 92% similarity 45.8

Article Content

Browse articles
ThreatCluster

A vulnerability has been identified in Evolution Data Server affecting Ubuntu 18.04 LTS and 20.04 LTS. The flaw allows an attacker to exploit the software's handling of local cache files, potentially leading to the deletion of arbitrary files. This issue was addressed in the recent USN-8055-2 update, which follows the earlier USN-8055-1 advisory. Users are advised to update their systems to the latest package versions to mitigate this risk. The specific versions impacted include evolution-data-server 3.36.5-0ubuntu1+esm1 for Ubuntu 20.04 LTS and 3.28.5-0ubuntu0.18.04.3+esm1 for Ubuntu 18.04 LTS. A session restart is required post-update to apply the changes. This vulnerability highlights the importance of regular system updates to maintain security.

Key Points: • Evolution Data Server vulnerability allows arbitrary file deletion on affected Ubuntu systems. • Impacted versions include Ubuntu 18.04 LTS and 20.04 LTS with specific package versions. • Users must update their systems and restart sessions to apply the necessary security changes.

ThreatCluster AI

Timeline

2026-06-01
USN-8055-2 update released
Ubuntu released an update to address a vulnerability in Evolution Data Server affecting versions 18.04 and 20.04 LTS.
Ubuntu
2026-06-01
Vulnerability discovered
It was found that Evolution Data Server mishandled local cache file deletions, allowing potential file removal by attackers.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story