libXpm vulnerability
Published: Thu, 23 Jul 2026 14:41
Summary
libXpm could be made to crash if it opened a specially crafted file.
Details
Naoki Wakamatsu discovered that libXpm did not properly validate file boundaries when processing XPM image files. An attacker could possibly use this issue to cause libXpm to crash, resulting in a denial of service.
Recommended actions per Ubuntu release
StackPatch playbook auto-generated per release codename and per affected package.
Ubuntu jammy
libxpm→1:3.5.12-1ubuntu0.22.04.3apt_upgradeStandard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm
Most apt upgrades restart their service automatically. needrestart lists anything else.
libxpm-dev→1:3.5.12-1ubuntu0.22.04.3apt_upgradeStandard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
libxpm4→1:3.5.12-1ubuntu0.22.04.3apt_upgradeStandard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm4
Most apt upgrades restart their service automatically. needrestart lists anything else.
xpmutils→1:3.5.12-1ubuntu0.22.04.3apt_upgradeStandard apt upgrade. Install 1:3.5.12-1ubuntu0.22.04.3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y xpmutils
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu noble
libxpm→1:3.5.17-1ubuntu0.24.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm
Most apt upgrades restart their service automatically. needrestart lists anything else.
libxpm-dev→1:3.5.17-1ubuntu0.24.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
libxpm4→1:3.5.17-1ubuntu0.24.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm4
Most apt upgrades restart their service automatically. needrestart lists anything else.
xpmutils→1:3.5.17-1ubuntu0.24.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.24.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y xpmutils
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu resolute
libxpm→1:3.5.17-1ubuntu0.26.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm
Most apt upgrades restart their service automatically. needrestart lists anything else.
libxpm-dev→1:3.5.17-1ubuntu0.26.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
libxpm4→1:3.5.17-1ubuntu0.26.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libxpm4
Most apt upgrades restart their service automatically. needrestart lists anything else.
xpmutils→1:3.5.17-1ubuntu0.26.04.1apt_upgradeStandard apt upgrade. Install 1:3.5.17-1ubuntu0.26.04.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y xpmutils
Most apt upgrades restart their service automatically. needrestart lists anything else.
Are YOU affected by USN-8600-1?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8600-1 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.