ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 19 sources: “Ubuntu roundup (2026-09-16 to 2026-09-18): ten USNs fix 16 CVEs, including Rclone unauthenticated command execution and Arm kernel TLB race” — merged summary and timeline →

USN-8777-1: GNU Bison vulnerability

lowAdvisoryimportance 18
AI summary · glm-5.3-flash

Ubuntu issued USN-8777-1 fixing a GNU Bison flaw in HTML report generation that could allow attackers to execute arbitrary code.

Ubuntu Security Notice USN-8777-1 fixes a vulnerability in GNU Bison, which incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could potentially leverage this issue to execute arbitrary code. Patched packages are available for supported Ubuntu releases; no CVE id is listed in the notice and no active exploitation is mentioned.

  • GNU Bison mishandled grammar-defined configuration variables in HTML report generation.
  • Issue could enable arbitrary code execution.
  • Ubuntu released patched packages under USN-8777-1.
Full article

It was discovered that GNU Bison incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could possibly use this issue to execute arbitrary code.

This source does not provide full text. Read it at ubuntu.com.