USN-8709-1: ncurses vulnerability

Publication date

1 September 2026

Overview

ncurses could be made to crash if it opened a specially crafted file.


Packages

  • ncurses - shared libraries for terminal handling

Details

It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.

It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 LTS noble libncurses6 –  6.4+20240113-1ubuntu2.2
libtinfo6 –  6.4+20240113-1ubuntu2.2
ncurses-bin –  6.4+20240113-1ubuntu2.2
22.04 LTS jammy libncurses5 –  6.3-2ubuntu0.3
libncurses6 –  6.3-2ubuntu0.3
libtinfo5 –  6.3-2ubuntu0.3
libtinfo6 –  6.3-2ubuntu0.3
ncurses-bin –  6.3-2ubuntu0.3
20.04 LTS focal libncurses5 –  6.2-0ubuntu2.1+esm2  
libncurses6 –  6.2-0ubuntu2.1+esm2  
libtinfo5 –  6.2-0ubuntu2.1+esm2  
libtinfo6 –  6.2-0ubuntu2.1+esm2  
ncurses-bin –  6.2-0ubuntu2.1+esm2  
18.04 LTS bionic libncurses5 –  6.1-1ubuntu1.18.04.1+esm4  
libtinfo5 –  6.1-1ubuntu1.18.04.1+esm4  
ncurses-bin –  6.1-1ubuntu1.18.04.1+esm4  
16.04 LTS xenial libncurses5 –  6.0+20160213-1ubuntu1+esm7  
libtinfo5 –  6.0+20160213-1ubuntu1+esm7  
ncurses-bin –  6.0+20160213-1ubuntu1+esm7  
14.04 LTS trusty libncurses5 –  5.9+20140118-1ubuntu1+esm7  
libtinfo5 –  5.9+20140118-1ubuntu1+esm7  
ncurses-bin –  5.9+20140118-1ubuntu1+esm7  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›