Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2025-59375 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. | expat expat expat expat |
| CVE | CVE-2026-39919 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows att | ghostscript ghostscript ghostscript ghostscript ghostscript ghostscript |
| CVE | CVE-2026-90698 | A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file | memcached memcached memcached memcached memcached memcached |
| CVE | CVE-2026-56405 | libexpat before 2.8.2 has an integer overflow in getAttributeId. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56404 | libexpat before 2.8.2 has an integer overflow in addBinding. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56412 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-50219 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset fr | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56403 | libexpat before 2.8.2 has an integer overflow in storeAtts. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-41080 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. | expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-45186 | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML | expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-32778 | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-32777 | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-32776 | libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-78135 | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandle | strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan |
| CVE | CVE-2026-78134 | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner E | strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan |
| CVE | CVE-2026-78133 | libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling. | strongswan strongswan strongswan strongswan |
| CVE | CVE-2026-78132 | strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax. | strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan |
| CVE | CVE-2026-78131 | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser. | strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan |
| CVE | CVE-2026-78130 | strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser. | strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan strongswan |
About
-
Send Feedback to @ubuntu_updates