StackPatch is liveSee product

Back to CVE digest
Ubuntu USN · USN-8600-1

libXpm vulnerability

Published: Thu, 23 Jul 2026 14:41

CVE-2026-4367

Summary

libXpm could be made to crash if it opened a specially crafted file.

Details

Naoki Wakamatsu discovered that libXpm did not properly validate file boundaries when processing XPM image files. An attacker could possibly use this issue to cause libXpm to crash, resulting in a denial of service.

Recommended actions per Ubuntu release

StackPatch playbook auto-generated per release codename and per affected package.

Ubuntu jammy

  • libxpm1:3.5.12-1ubuntu0.22.04.3apt_upgrade

    Standard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libxpm-dev1:3.5.12-1ubuntu0.22.04.3apt_upgrade

    Standard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libxpm41:3.5.12-1ubuntu0.22.04.3apt_upgrade

    Standard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm4

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • xpmutils1:3.5.12-1ubuntu0.22.04.3apt_upgrade

    Standard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y xpmutils

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Ubuntu noble

  • libxpm1:3.5.17-1ubuntu0.24.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libxpm-dev1:3.5.17-1ubuntu0.24.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libxpm41:3.5.17-1ubuntu0.24.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm4

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • xpmutils1:3.5.17-1ubuntu0.24.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y xpmutils

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Ubuntu resolute

  • libxpm1:3.5.17-1ubuntu0.26.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libxpm-dev1:3.5.17-1ubuntu0.26.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libxpm41:3.5.17-1ubuntu0.26.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libxpm4

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • xpmutils1:3.5.17-1ubuntu0.26.04.1apt_upgrade

    Standard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y xpmutils

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Are YOU affected by USN-8600-1?

5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8600-1 (and any other live CVE) applies. Anonymous, no signup.

curl https://mindsparkstack.com/scan.sh | bash
Want this automated for your servers?

StackPatch runs this match against YOUR installed packages every hour

Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.