THE ESSENTIALS
  • Check the applicable package channel as well as its version.

What changed

Canonical published USN-8752-1 with Konsole packages addressing CVE-2025-49091. The terminal emulator can mishandle certain URLs, potentially allowing attacker-supplied code to run with the user’s permissions. The notice covers Ubuntu 16.04, 18.04, 20.04, 22.04 and 24.04 LTS, making this a distribution update for an existing vulnerability.

Why it matters

For administrators, the delivery channel matters alongside the version number. Canonical marks the listed 18.04-through-24.04 packages as Ubuntu Pro fixes through ESM Apps. That qualification means a published fix should not automatically be treated as installed or available through every machine’s current update configuration.

What remains unproven

The advisory does not describe the precise triggering circumstances or report active exploitation. It says a standard system update generally applies the necessary changes, but provides no fleet-level deployment evidence.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. Canonical / Ubuntu Security Notices ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗