Bugs addressed in recent updates
Origin | Bug number | Title | Packages |
---|---|---|---|
CVE | CVE-2024-26146 | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a p | ruby-rack ruby-rack |
CVE | CVE-2024-26141 | Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Respo | ruby-rack ruby-rack |
CVE | CVE-2023-3966 | A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invali | openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch |
CVE | CVE-2012-6655 | An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted p | accountsservice accountsservice accountsservice accountsservice |
CVE | CVE-2024-27913 | ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a ma | frr frr frr frr frr frr frr frr |
CVE | CVE-2024-25629 | c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc | c-ares c-ares c-ares c-ares c-ares c-ares |
CVE | CVE-2023-27103 | Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc. | libde265 libde265 libde265 libde265 |
CVE | CVE-2023-27102 | Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc. | libde265 libde265 libde265 libde265 |
CVE | CVE-2023-22742 | libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not per | libgit2 libgit2 libgit2 libgit2 |
CVE | CVE-2023-49468 | Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. | libde265 libde265 libde265 libde265 libde265 libde265 |
CVE | CVE-2023-49467 | Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at mo | libde265 libde265 libde265 libde265 libde265 libde265 |
CVE | CVE-2023-49465 | Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. | libde265 libde265 libde265 libde265 libde265 libde265 |
CVE | CVE-2023-47471 | Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header funct | libde265 libde265 libde265 libde265 libde265 libde265 |
CVE | CVE-2023-43887 | Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_paramet | libde265 libde265 libde265 libde265 libde265 libde265 |
CVE | CVE-2024-24577 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i | libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 |
CVE | CVE-2024-24575 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i | libgit2 libgit2 libgit2 libgit2 |
CVE | CVE-2024-0607 | A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a | linux linux linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp |
CVE | CVE-2023-23004 | In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error | linux linux linux linux-bluefield linux linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp |
CVE | CVE-2023-39198 | A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_o | linux |
Launchpad | 2051655 | Focal update: v5.4.266 upstream stable release | linux linux linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp |
About
-
Send Feedback to @ubuntu_updates