UbuntuUpdates.org

Package "nano"

Name: nano

Description:

small, friendly text editor inspired by Pico

Latest version: 8.4-1ubuntu0.1
Release: questing (25.10)
Level: security
Repository: main
Homepage: https://www.nano-editor.org/

Links


Download "nano"


Other versions of "nano" in Questing

Repository Area Version
base main 8.4-1
base universe 8.4-1
security universe 8.4-1ubuntu0.1
updates main 8.4-1ubuntu0.1
updates universe 8.4-1ubuntu0.1

Changelog

Version: 8.4-1ubuntu0.1 2026-06-04 23:08:05 UTC

  nano (8.4-1ubuntu0.1) questing-security; urgency=medium

  * SECURITY UPDATE: Incorrect permission assignment.
    - debian/patches/CVE-2026-6842.patch: Create ~/.local with correct
      permissions in src/history.c.
    - CVE-2026-6842
  * SECURITY UPDATE: Denial of service in redecorate_after_switch
    - debian/patches/CVE-2026-6843.patch: Escape error message to avoid
      content being interpreted as format specifiers in src/files.c
    - CVE-2026-6843

 -- Kyle Kernick <email address hidden> Wed, 03 Jun 2026 16:50:05 -0600

CVE-2026-6842 A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead
CVE-2026-6843 A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a nam



About   -   Send Feedback to @ubuntu_updates