Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2164757 | Release the CUDA-13-2 packages on Resolute | cuda-cudart-13-2 |
| Launchpad | 2155648 | SRU: New upstream version 7.2.4 | hipcub |
| Launchpad | 2154553 | SRU: New upstream version 7.2.4 | rocsparse |
| CVE | CVE-2026-80186 | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| CVE | CVE-2026-80185 | BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SD | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| CVE | CVE-2026-75032 | A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| CVE | CVE-2026-19774 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| Launchpad | 2154493 | SRU: New upstream version 7.2.4 | hiprand |
| CVE | CVE-2026-88373 | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length | libde265 libde265 libde265 libde265 |
| CVE | CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86143 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a l | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86142 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86139 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86138 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-76781 | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| Launchpad | 2168785 | Systemd based collection fails to get WSL version | ubuntu-insights |
| Launchpad | 2169719 | sdot on arm64 adds the caller's v0 register to the result (Neoverse N1, AmpereOne, Apple silicon, ThunderX2/3) | openblas |
| Launchpad | 2101888 | fsck.xfs can drop into a rescue shell when fsck.mode=force is set | xfsprogs |
| Launchpad | 2168936 | pcs output with broken lines - why? | pcs pcs |
| Launchpad | 2169164 | tmux server SIGSEGV in control_write() when a control-mode client is still connecting (fixed upstream in 3.7) | tmux tmux tmux |
About
-
Send Feedback to @ubuntu_updates