UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-19685 NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incom network-manager network-manager
CVE CVE-2026-55995 A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 5 open-isns open-isns open-isns open-isns open-isns open-isns
CVE CVE-2026-59893 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/le sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse
CVE CVE-2026-71491 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-o sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse
CVE CVE-2026-54284 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse
Launchpad 2167309 [Noble] Enable signing for Xilinx kernels and Ubuntu Core FIT images linux-xilinx
CVE CVE-2026-82474 Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run speci sudo sudo sudo sudo sudo sudo sudo sudo
CVE CVE-2026-66034 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbit libssh2 libssh2
Launchpad 2007394 [MIR][jammy] oem-stella-maria-meta oem-stella-maria-meta
Launchpad 1999966 [MIR][jammy] oem-stella-slowpoke-rpl-meta oem-stella-slowpoke-rpl-meta
CVE CVE-2026-18297 GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0
CVE CVE-2026-18299 GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-18298 GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-18296 GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-18295 GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-1829 The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via th gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-16118 A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0
CVE CVE-2026-15588 A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0
CVE CVE-2026-58016 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0
CVE CVE-2026-58015 A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0 glib2.0



About   -   Send Feedback to @ubuntu_updates