Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-94057 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft | exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 |
| CVE | CVE-2026-94056 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me | exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 |
| CVE | CVE-2026-94055 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | exim4 exim4 exim4 exim4 |
| CVE | CVE-2026-94054 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 exim4 |
| Launchpad | 2168564 | freerdp3 3.32.0 security update tracking bug | freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 |
| Launchpad | 2142757 | libvirt 10.0.0-2ubuntu8.x - rpc: leak of GSource in use for interrupting main loop | libvirt libvirt libvirt libvirt |
| CVE | CVE-2026-77159 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi | libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt |
| CVE | CVE-2026-18917 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla | libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt libvirt-hwe libvirt libvirt-hwe libvirt libvirt libvirt libvirt libvirt |
| CVE | CVE-2026-63623 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was | libvirt-hwe libvirt-hwe libvirt-hwe libvirt-hwe |
| CVE | CVE-2026-63622 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera | libvirt-hwe libvirt-hwe libvirt-hwe libvirt-hwe |
| CVE | CVE-2026-61477 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT recor | libvirt-hwe libvirt-hwe libvirt-hwe libvirt-hwe |
| Launchpad | 2156727 | [SRU] upgrade from 24.04/25.10 leaves the user at a TTY | ubuntu-release-upgrader ubuntu-release-upgrader |
| CVE | CVE-2026-48526 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric | pyjwt pyjwt pyjwt pyjwt pyjwt pyjwt |
| CVE | CVE-2026-48525 | PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64 | pyjwt pyjwt pyjwt pyjwt |
| CVE | CVE-2026-48524 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint f | pyjwt pyjwt pyjwt pyjwt |
| CVE | CVE-2026-48523 | PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or j | pyjwt pyjwt |
| CVE | CVE-2026-48522 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which u | pyjwt pyjwt pyjwt pyjwt pyjwt pyjwt |
| CVE | CVE-2026-78161 | A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP | libwebsockets libwebsockets |
| CVE | CVE-2026-10650 | A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ | libwebsockets libwebsockets |
| CVE | CVE-2026-6893 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Hos | dracut dracut dracut dracut |
About
-
Send Feedback to @ubuntu_updates