Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Debian | 1128130 | lomiri-thumbnailer: FTBFS with boost 1.90 | lomiri-thumbnailer |
| Launchpad | 2142325 | lomiri-thumbnailers FTBFS in resolute | lomiri-thumbnailer |
| Launchpad | 2154290 | SRU: New upstream version 7.2.4 | rccl |
| CVE | CVE-2026-84784 | QUIC: Unbounded RETIRE_CONNECTION_ID Backlog | openssl openssl |
| CVE | CVE-2026-84782 | DTLS Retransmits Handshake Messages From a Stale Buffer Offset | openssl openssl openssl openssl openssl openssl |
| CVE | CVE-2026-77696 | Timing Side-Channel in SM2 Signature Generation | openssl openssl openssl openssl openssl openssl |
| CVE | CVE-2026-75806 | Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS | openssl openssl openssl openssl openssl openssl |
| CVE | CVE-2026-75805 | NULL Pointer Dereference in CMP Client Revocation Response Handling | openssl openssl openssl openssl openssl openssl |
| CVE | CVE-2026-75804 | QUIC Connection-Level Flow Control is Not Enforced for Streams | openssl openssl |
| CVE | CVE-2026-72897 | Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake | openssl openssl |
| CVE | CVE-2026-54875 | Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V | openssl openssl |
| CVE | CVE-2026-54872 | Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves | openssl openssl openssl openssl openssl openssl |
| CVE | CVE-2026-35191 | QUIC Unvalidated Amplification Credit may be Over Accounted | openssl openssl |
| CVE | CVE-2026-35189 | Excessive Memory Allocation in Relative CRLDP Processing | openssl openssl openssl openssl openssl openssl |
| CVE | CVE-2026-84449 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in | libheif libheif libheif libheif |
| CVE | CVE-2026-84448 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in li | libheif libheif libheif libheif libheif libheif libheif libheif |
| CVE | CVE-2026-84447 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decod | libheif libheif libheif libheif |
| CVE | CVE-2026-84446 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sam | libheif libheif libheif libheif |
| CVE | CVE-2026-84384 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can caus | libheif libheif libheif libheif libheif libheif libheif libheif |
| CVE | CVE-2026-33630 | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The sa | c-ares c-ares c-ares c-ares |
About
-
Send Feedback to @ubuntu_updates