UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-56003 A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf libxfont libxfont libxfont
CVE CVE-2026-56002 A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec libxfont libxfont libxfont
CVE CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the libxfont libxfont libxfont
Launchpad 2161162 1:10.2p1-2ubuntu3.4 built without crypt() openssh build-essential openssh build-essential
Launchpad 2147129 [SRU] dbx updates fail to notify snapd on default image fwupd fwupd
Launchpad 2153804 SRU: New upstream version 7.2.4 rocm-cmake
Launchpad 2159601 SRU: pkg-rocm-tools: enable gfx950 (AMD Instinct MI350 / CDNA4) build target for resolute pkg-rocm-tools
Launchpad 2156423 Fix grub-initrd-fallback.service order grub2 grub2
Launchpad 2161092 tzdata 2026c release tzdata tzdata tzdata tzdata tzdata
CVE CVE-2026-12391 An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools
CVE CVE-2026-11386 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools
CVE CVE-2026-9494 An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools
Launchpad 2160650 tar after USN-8477-1 cannot extract previously valid files tar tar tar tar tar tar tar tar tar tar tar tar
Launchpad 2155110 Autopkgtest failure on amd64v3 ghostty
Launchpad 2148769 [SRU] ghostty does not start: Illegal instruction ghostty
Launchpad 2158737 autopkgtest fails in Noble because of missing scsi_debug kernel module gvfs
Launchpad 2159018 [SRU] gnome-control-center 50.3 gnome-control-center
Launchpad 2062980 nautilus progress bar on ubuntu dock icon does not update nautilus
Launchpad 2156984 UAF in Nautilus Unity quicklist bookmark handler nautilus
Launchpad 2146869 .ova file displays huge icon in list view nautilus



About   -   Send Feedback to @ubuntu_updates