Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-88373 | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length | libde265 libde265 |
| CVE | CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86143 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a l | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86142 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86139 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | libxml2 libxml2 |
| CVE | CVE-2026-86138 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-76781 | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| Launchpad | 2168785 | Systemd based collection fails to get WSL version | ubuntu-insights |
| Launchpad | 2169719 | sdot on arm64 adds the caller's v0 register to the result (Neoverse N1, AmpereOne, Apple silicon, ThunderX2/3) | openblas |
| Launchpad | 2101888 | fsck.xfs can drop into a rescue shell when fsck.mode=force is set | xfsprogs |
| Launchpad | 2168936 | pcs output with broken lines - why? | pcs pcs |
| Launchpad | 2169164 | tmux server SIGSEGV in control_write() when a control-mode client is still connecting (fixed upstream in 3.7) | tmux tmux tmux |
| CVE | CVE-2026-53583 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i | libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 |
| Launchpad | 2167992 | SRU: Fix crash on rapid addition/removal of interfaces (Upstream #744) | lldpd lldpd |
| Launchpad | 2165836 | mate-notification-daemon segfaults in libgobject at session start (glib 2.88 regression) | mate-notification-daemon |
| CVE | CVE-2026-16517 | A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zi | libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive |
| Launchpad | 1998592 | [SRU] in specific situations, nano can eat characters | nano nano |
| Launchpad | 2165869 | glib2 GTask bug causes livelocks in Evolution (and others) | glib2.0 glib2.0 |
| Launchpad | 2144770 | plymouth reload sometimes switches to text mode | plymouth plymouth plymouth plymouth |
| Launchpad | 2168772 | [SRU] orca 50.3 | orca |
About
-
Send Feedback to @ubuntu_updates