UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2165127 [BPO] libreoffice 26.2.5 for jammy/noble libreoffice libreoffice libreoffice libreoffice
Launchpad 2146641 C200 Plan and Patches linux-azure-nvidia
Launchpad 2167253 [CVM][Backport] hv_netvsc: Advertise the SR-IOV capability for CoCo VMs linux-azure-nvidia
Launchpad 2166709 [SRU] libreoffice 26.2.6 for resolute libreoffice libreoffice
Launchpad 2167621 bubblewrap 0.11.1-1ubuntu0.2 breaks Flatpak applications with bind mount / symlink resolution errors bubblewrap bubblewrap bubblewrap bubblewrap bubblewrap bubblewrap
CVE CVE-2026-1801 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so libsoup2.4 libsoup3 libsoup3 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup2.4 libsoup2.4 libsoup2.4
CVE CVE-2026-87766 A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via bubblewrap bubblewrap bubblewrap bubblewrap bubblewrap bubblewrap
Launchpad 2159565 [SRU] Fix port-naming formatting regression in ALSA sequencer bridge pipewire pipewire
CVE CVE-2026-56389 GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration var bison bison bison bison bison bison
Launchpad 2150053 [SRU] Ensure brcmfmac firmware present in dracut initrd ubuntu-raspi-settings
CVE CVE-2026-18649 A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
Launchpad 2167436 CPU throttled to 400MHz on Dell AIO QB24250 thermald
Launchpad 2158525 mysql root account locked out after upgrade to 26.04 ubuntu-release-upgrader ubuntu-release-upgrader
CVE CVE-2026-85522 A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file sr valkey valkey
CVE CVE-2026-63639 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream valkey valkey
CVE CVE-2026-56684 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin valkey valkey
Launchpad 2158643 [SRU] lxc: incorrect free() of cap_to_text() result in ambient caps setup causes intermittent startup failure lxc lxc
Launchpad 2069523 click 0.5.2-2ubuntu4 fails to install on Ubuntu 24.04 LTS click
Launchpad 2163501 [SRU] Mesa 25.2.8 disabled legacy `bind_wayland_display` code path mesa mesa
CVE CVE-2026-69249 python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, whe python-cryptography python-cryptography



About   -   Send Feedback to @ubuntu_updates