UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2094834 [SRU] Bump eeprom to support memory timings update in 16GB Pi 5 rpi-eeprom
Launchpad 2142762 [SRU] Demote libde265 to Suggests libheif libheif
Launchpad 2133220 add ID_NET_MANAGED_BY property support to jammy systemd systemd
Launchpad 2133159 systemd-networkd does not respect ID_NET_MANAGED_BY in all cases systemd systemd
Launchpad 2128161 [SRU][FFe] pi-kernel VC4-KMS not working with CM5 rpi-eeprom rpi-eeprom
Launchpad 2141296 [00427578] Restarting systemd timer triggers service start off-schedule systemd systemd systemd systemd
Launchpad 2124206 apparmor socketpair regression test needs fixing apparmor apparmor
Launchpad 2142792 The busybox and nautilus profiles in 24.04 should be removed apparmor apparmor
Launchpad 2143863 [SRU] AppArmor bugfixes for Noble apparmor apparmor
CVE CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass bind9 bind9
CVE CVE-2026-3119 Authenticated query containing a TKEY record may cause named to terminate unexpectedly bind9 bind9
CVE CVE-2026-3104 Memory leak in code preparing DNSSEC proofs of non-existence bind9 bind9
CVE CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9
Launchpad 2141721 CVE-2025-32023: Redis allows out of bounds writes in hyperloglog commands leading to RCE redis redis
CVE CVE-2026-29111 systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. systemd systemd systemd systemd systemd systemd
CVE CVE-2026-25075 strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote att strongswan strongswan strongswan strongswan strongswan strongswan
CVE CVE-2026-28296 A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file pat gvfs gvfs gvfs gvfs gvfs gvfs
CVE CVE-2026-28295 A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its gvfs gvfs gvfs gvfs gvfs gvfs
CVE CVE-2026-27459 pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set pyopenssl pyopenssl pyopenssl pyopenssl
CVE CVE-2026-27448 pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set pyopenssl pyopenssl pyopenssl pyopenssl pyopenssl pyopenssl



About   -   Send Feedback to @ubuntu_updates