{"id":"USN-8555-2","summary":"ubuntu-advantage-tools regression","details":"USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu\n14.04 LTS only, it was discovered that some machines were unable to\nenable esm-infra-legacy due to a preemptive apt-helper check. This\nupdate fixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer\n token in command-line arguments when validating APT credentials. A local\n attacker could possibly use this issue to obtain sensitive information\n and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494)\n\n Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly\n validate data received from the contract server when writing APT source\n files. An attacker could possibly use this issue to inject arbitrary APT\n configuration and execute arbitrary code. (CVE-2026-11386)\n\n Mateusz Gierblinski discovered that Ubuntu Advantage Tools did not\n properly handle symbolic links when collecting diagnostic logs. A local\n attacker could possibly use this issue to obtain sensitive information\n from files owned by the administrator. This issue only affected Ubuntu\n 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,\n Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-12391)","modified":"2026-09-01T21:00:04.442082477Z","published":"2026-09-01T15:32:36Z","references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8555-2"},{"type":"REPORT","url":"https://launchpad.net/bugs/2165073"}],"affected":[{"package":{"name":"ubuntu-advantage-tools","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/ubuntu-advantage-tools?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.7ubuntu0.2"}]}],"versions":["2","10ubuntu0.14.04.2","10ubuntu0.14.04.3","10ubuntu0.14.04.4","19.6~ubuntu14.04.3","19.6~ubuntu14.04.4","19.7"],"ecosystem_specific":{"binaries":[{"binary_name":"ubuntu-advantage-tools","binary_version":"19.7ubuntu0.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8555-2.json"}}],"schema_version":"1.9.0"}