Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-56003 | A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf | libxfont libxfont libxfont |
| CVE | CVE-2026-56002 | A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to exec | libxfont libxfont libxfont |
| CVE | CVE-2026-56001 | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the | libxfont libxfont libxfont |
| Launchpad | 2161162 | 1:10.2p1-2ubuntu3.4 built without crypt() | openssh build-essential openssh build-essential |
| Launchpad | 2147129 | [SRU] dbx updates fail to notify snapd on default image | fwupd fwupd |
| Launchpad | 2153804 | SRU: New upstream version 7.2.4 | rocm-cmake |
| Launchpad | 2159601 | SRU: pkg-rocm-tools: enable gfx950 (AMD Instinct MI350 / CDNA4) build target for resolute | pkg-rocm-tools |
| Launchpad | 2156423 | Fix grub-initrd-fallback.service order | grub2 grub2 |
| Launchpad | 2161092 | tzdata 2026c release | tzdata tzdata tzdata tzdata tzdata |
| CVE | CVE-2026-12391 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| CVE | CVE-2026-11386 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| CVE | CVE-2026-9494 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| Launchpad | 2160650 | tar after USN-8477-1 cannot extract previously valid files | tar tar tar tar tar tar tar tar tar tar tar tar |
| Launchpad | 2155110 | Autopkgtest failure on amd64v3 | ghostty |
| Launchpad | 2148769 | [SRU] ghostty does not start: Illegal instruction | ghostty |
| Launchpad | 2158737 | autopkgtest fails in Noble because of missing scsi_debug kernel module | gvfs |
| Launchpad | 2159018 | [SRU] gnome-control-center 50.3 | gnome-control-center |
| Launchpad | 2062980 | nautilus progress bar on ubuntu dock icon does not update | nautilus |
| Launchpad | 2156984 | UAF in Nautilus Unity quicklist bookmark handler | nautilus |
| Launchpad | 2146869 | .ova file displays huge icon in list view | nautilus |
About
-
Send Feedback to @ubuntu_updates