UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2166107 Transition the 450 graphics driver packages to 470 nvidia-graphics-drivers-450-server fabric-manager-450 libnvidia-nscq-450
Launchpad 2155202 Severe hardware functionality regressions caused by forced major version updates for NVIDIA drivers (originally: Latest Update Breaks Systems Using N nvidia-graphics-drivers-470 nvidia-graphics-drivers-470
Launchpad 2166032 Transition the 565 graphics driver packages to 580 fabric-manager-565 nvidia-imex-565 libnvidia-nscq-565 nvidia-graphics-drivers-565-server nvidia-graphics-drivers-565-server fabric-manager-565 nvidia-imex-565 libnvidia-nscq-565
Launchpad 2166991 New upstream release 595.99.02 UDA nvidia-graphics-drivers-595 nvidia-graphics-drivers-595
Launchpad 2167526 Transition the 610 graphics driver packages to 615 nvidia-graphics-drivers-610 nvidia-graphics-drivers-610 nvidia-graphics-drivers-610
Launchpad 2167002 New upstream release 615.71.09 UDA/ERD nvidia-graphics-drivers-615-server nvidia-graphics-drivers-615 fabric-manager-615 nvidia-imex-615 libnvidia-nscq-615 nvidia-graphics-drivers-615-server nvidia-graphics-drivers-615 fabric-manager-615 nvidia-imex-615 libnvidia-nscq-615 nvidia-graphics-drivers-615-server nvidia-graphics-drivers-615 fabric-manager-615 nvidia-imex-615 libnvidia-nscq-615
CVE CVE-2026-73194 DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. libdbi-perl libdbi-perl libdbi-perl libdbi-perl libdbi-perl
CVE CVE-2026-73193 DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by pr libdbi-perl libdbi-perl libdbi-perl libdbi-perl libdbi-perl
CVE CVE-2026-63388 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when buffer libevent libevent libevent libevent libevent libevent
CVE CVE-2026-63387 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_ libevent libevent libevent libevent libevent libevent
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4
CVE CVE-2026-94055 Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. exim4 exim4 exim4 exim4
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4
Launchpad 2168564 freerdp3 3.32.0 security update tracking bug freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3
Launchpad 2142757 libvirt 10.0.0-2ubuntu8.x - rpc: leak of GSource in use for interrupting main loop libvirt libvirt libvirt libvirt
CVE CVE-2026-77159 A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt
CVE CVE-2026-18917 A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt
CVE CVE-2026-63623 A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was libvirt-hwe libvirt-hwe libvirt-hwe libvirt-hwe
CVE CVE-2026-63622 A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera libvirt-hwe libvirt-hwe libvirt-hwe libvirt-hwe



About   -   Send Feedback to @ubuntu_updates