Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Ubuntu Security

USN-8360-1: sslh vulnerability

  • What: sslh vulnerability allows local attackers to overwrite files
  • Impact: Ubuntu systems using sslh may be at risk
Read Full Article →

Ubuntu Security Notices USN-8360-1 USN-8360-1: sslh vulnerability Publication date 1 June 2026 Overview sslh could be made to overwrite files. Releases 26.04 LTS 25.10 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages sslh - Applicative protocol multiplexer Details It was discovered that sslh did not properly handle symbolic links when writing its PID file. A local attacker could possibly use this issue to overwrite arbitrary files. It was discovered that sslh did not properly handle symbolic links when writing its PID file. A local attacker could possibly use this issue to overwrite arbitrary files. Update instructions After a standard system update you need to restart sslh to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute sslh – 2.1.4-1ubuntu0.26.04.1 25.10 questing sslh – 2.1.4-1ubuntu0.25.10.1 24.04 LTS noble sslh – 1.22c-1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 22.04 LTS jammy sslh – 1.20-1+deb11u1build0.22.04.1 20.04 LTS focal sslh – 1.20-1+deb11u1build0.20.04.1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 18.04 LTS bionic sslh – 1.18-1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 16.04 LTS xenial sslh – 1.17-2ubuntu0.1~esm1 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2025-52936 CVE-2025-52936

Share this article