UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2166430 dnsmasq 2.91-0ubuntu0.24.04.1 update broke ProxyDHCP mode dnsmasq dnsmasq dnsmasq dnsmasq dnsmasq dnsmasq
Launchpad 2168508 doca-ofed-26.01 fails to build on Kernel 7.0.0-39 doca-ofed-26.01-dkms
Launchpad 2168511 doca-ofed-3.4-dkms fails to build in Kernel 7.0.0-39 doca-ofed-3.4-dkms
CVE CVE-2026-0799 In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15 libpcap libpcap libpcap libpcap libpcap libpcap
Launchpad 2166733 New upstream core24.60 release linux-main-modules-vmware linux-main-generate-vmware linux-main-signed-vmware
CVE CVE-2026-49017 In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The S swift swift
CVE CVE-2026-8286 A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS curl curl
CVE CVE-2026-6429 When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the f curl curl curl curl
CVE CVE-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different curl curl curl curl curl curl
CVE CVE-2026-11856 Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a diff curl curl
CVE CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic curl curl curl curl curl curl
CVE CVE-2026-9080 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts curl curl
CVE CVE-2026-82209 When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domai curl curl curl curl curl curl
CVE CVE-2026-80255 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes cur curl curl
CVE CVE-2026-80230 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL curl curl curl curl curl curl
CVE CVE-2026-80229 When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider con curl curl
CVE CVE-2026-18924 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-af curl curl curl curl curl curl
CVE CVE-2026-13608 A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptogra curl curl curl curl
Launchpad 2167779 Reverted security upload 8.20.0-2ubuntu4, broken checksrc and CVE-2026-8927 backport curl curl curl curl curl curl
Launchpad 2167969 Upstream update to CVE-2026-9080 fix missing in Resolute curl curl



About   -   Send Feedback to @ubuntu_updates