UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2165958 package postfix 3.10.6-4ubuntu2.1 failed to install/upgrade: old postfix package postinst maintainer script subprocess failed with exit status 1 postfix postfix
Launchpad 2068765 [MIR][jammy] oem-stella-banhou-meta oem-stella-banhou-meta
Launchpad 1997645 [MIR][jammy] oem-stella-mii-meta oem-stella-mii-meta
Launchpad 2115842 [MIR][noble] oem-somerville-inkay-meta oem-somerville-inkay-meta
Launchpad 2084015 gnome-shell has no response when plug-in unauthorized thunderbolt devices gnome-shell gnome-shell
Launchpad 2108011 Screen zoom with multiple displays results in screen corruption gnome-shell gnome-shell
Launchpad 2164856 sssd_be leaves an [ldap_child] \u003cdefunct\u003e zombie on every backend start sssd sssd
Launchpad 2169024 [SRU] test-upstream autopkgtest failing for OpenSSH upgrades crypto-policies
CVE CVE-2026-8404 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `C python-django python-django python-django python-django python-django python-django
CVE CVE-2026-15307 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as python-django python-django python-django python-django python-django python-django
CVE CVE-2026-88924 A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by call gvfs gvfs gvfs gvfs gvfs gvfs
CVE CVE-2026-84268 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a l gvfs gvfs gvfs gvfs gvfs gvfs
CVE CVE-2026-86219 Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_ libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl
CVE CVE-2026-19387 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient gst-plugins-bad1.0 gst-plugins-bad1.0 gst-plugins-bad1.0 gst-plugins-bad1.0
CVE CVE-2026-45184 Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used. mlt kdenlive mlt kdenlive
Launchpad 2168441 Kdenlive: Remote code execution via malicious project file mlt kdenlive mlt kdenlive
CVE CVE-2026-80183 In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under an keystone keystone keystone keystone keystone keystone
CVE CVE-2026-80184 In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) keystone keystone keystone keystone keystone keystone
CVE CVE-2026-80182 In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new keystone keystone keystone keystone keystone keystone
CVE CVE-2026-84732 Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted openvpn openvpn openvpn openvpn openvpn openvpn



About   -   Send Feedback to @ubuntu_updates