UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-88924 A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by call gvfs gvfs gvfs
CVE CVE-2026-84268 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a l gvfs gvfs gvfs
CVE CVE-2026-86219 Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_ libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl
CVE CVE-2026-19387 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient gst-plugins-bad1.0 gst-plugins-bad1.0
CVE CVE-2026-45184 Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used. mlt kdenlive
Launchpad 2168441 Kdenlive: Remote code execution via malicious project file mlt kdenlive
CVE CVE-2026-80183 In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under an keystone keystone keystone keystone keystone keystone
CVE CVE-2026-80184 In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) keystone keystone keystone keystone keystone keystone
CVE CVE-2026-80182 In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new keystone keystone keystone keystone keystone keystone
CVE CVE-2026-84732 Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted openvpn openvpn openvpn openvpn openvpn openvpn
CVE CVE-2025-63913 An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and co opensbi opensbi
Launchpad 2166678 Samba 4.19.5 in Ubuntu 24.04.4 LTS hits upstream Bug 15527 with mergerfs/FUSE, causing SMB2 CLOSE failure and smbd panic samba samba
Launchpad 2151863 Tooltip displays oversized when hovering over desktop application icons qt6-ukui-platformtheme
Launchpad 2160664 Edge gesture window overlaps the UKUI panel and prevents Show Desktop from working ukui-sidebar
Launchpad 2151290 [SRU] ukui-sidebar crashes (coredump) when triggering popup notifications ukui-sidebar
CVE CVE-2026-16742 systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user systemd systemd
CVE CVE-2026-15059 Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. systemd systemd
CVE CVE-2026-15060 When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unpriv systemd systemd
Launchpad 2167504 [SRU] systemd v259.9 to resolute systemd systemd
Debian 1128130 lomiri-thumbnailer: FTBFS with boost 1.90 lomiri-thumbnailer



About   -   Send Feedback to @ubuntu_updates