Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-85522 | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file sr | valkey |
| CVE | CVE-2026-63639 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream | valkey |
| CVE | CVE-2026-56684 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin | valkey |
| Launchpad | 2158643 | [SRU] lxc: incorrect free() of cap_to_text() result in ambient caps setup causes intermittent startup failure | lxc lxc |
| Launchpad | 2069523 | click 0.5.2-2ubuntu4 fails to install on Ubuntu 24.04 LTS | click |
| Launchpad | 2163501 | [SRU] Mesa 25.2.8 disabled legacy `bind_wayland_display` code path | mesa mesa |
| CVE | CVE-2026-69249 | python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, whe | python-cryptography python-cryptography |
| CVE | CVE-2026-69248 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an inte | python-cryptography python-cryptography |
| CVE | CVE-2026-69247 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, | python-cryptography python-cryptography |
| CVE | CVE-2026-39113 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05c | sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 |
| Launchpad | 2167438 | [SRU] Neutron gazpacho stable releases | neutron neutron |
| Launchpad | 2150273 | [SRU] SSH fails on IPA-joined systems when logging in with an alternative UPN suffix | openssh openssh |
| Launchpad | 2127049 | wireplumber crashed with SIGABRT; \ | wireplumber wireplumber |
| CVE | CVE-2026-62377 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory( | libheif libheif libheif libheif |
| CVE | CVE-2026-62291 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 au | libheif libheif libheif libheif |
| Launchpad | 2160197 | open-vm-tools FTBFS with glib 2.88: g_free macro redefinition in glib_stubs.c | open-vm-tools open-vm-tools |
| Launchpad | 2166910 | open-vm-tools.service unnecessary ordering constraint blocks cloud-init on non-VMware platforms | open-vm-tools open-vm-tools open-vm-tools open-vm-tools |
| CVE | CVE-2026-56211 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder' | aom aom aom aom aom aom aom aom |
| CVE | CVE-2026-56210 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Vi | aom aom aom aom aom aom aom aom |
| CVE | CVE-2026-56209 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Vid | aom aom aom aom aom aom aom aom |
About
-
Send Feedback to @ubuntu_updates