- What: Security update for Sympa in Ubuntu
- Impact: Fixes a path traversal vulnerability that could allow unauthorized access
Ubuntu Security Notices USN-8552-1 USN-8552-1: Sympa vulnerability Publication date 15 July 2026 Overview Sympa could allow unintended access to network services. Releases 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages sympa - mailing list management software Details It was discovered that Sympa did not properly validate input on the generic SSO login. A remote attacker could possibly use this issue to perform a path traversal attack and gain unintended access. It was discovered that Sympa did not properly validate input on the generic SSO login. A remote attacker could possibly use this issue to perform a path traversal attack and gain unintended access. Update instructions After a standard system update you need to restart sympa to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 24.04 LTS noble sympa – 6.2.70~dfsg-2+deb12u1build0.24.04.1 22.04 LTS jammy sympa – 6.2.66~dfsg-2ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 20.04 LTS focal sympa – 6.2.40~dfsg-4ubuntu0.20.04.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 18.04 LTS bionic sympa – 6.2.24~dfsg-1ubuntu0.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 16.04 LTS xenial sympa – 6.1.24~dfsg-1ubuntu0.1~esm1 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2024-55919 CVE-2024-55919