Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2163406 | [SRU] Update ubuntu-advantage-tools to v38 (AppArmor fixes, CVEs, cloud license updates) - Bionic, Focal, Jammy, Noble, Resolute | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| Launchpad | 2163564 | Lock screen keyboard layout reverts while the password is being typed | gnome-shell gnome-shell |
| Debian | 1064744 | glib-networking: System trust contains zero trusted certificates | msgraph msgraph |
| Launchpad | 2064147 | Unable to browse My Files using OneDrive integration | msgraph msgraph |
| Launchpad | 2155142 | python3-heat-dashboard misses template generator static assets | heat-dashboard |
| Launchpad | 2155247 | [SRU] magnum-api-wsgi missing from Ubuntu package | magnum |
| Launchpad | 2155145 | python3-magnum-ui invalid scss variable fails config step | magnum-ui |
| Launchpad | 2163089 | rdmsr and wrmsr segfault when invoked with -a without the msr module loaded | msr-tools |
| CVE | CVE-2026-57433 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a sign | perl perl |
| CVE | CVE-2026-57432 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an | perl perl |
| CVE | CVE-2026-13221 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when | perl perl |
| CVE | CVE-2026-12087 | Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument | perl perl |
| Launchpad | 2163136 | [SRU] QHD panel doesn't support 60Hz refresh rate but Ubuntu OS can see 60Hz on display setting | mutter mutter |
| CVE | CVE-2026-69806 | Exposure of sensitive information to an unauthorized actor in .NET all ... | dotnet10 dotnet10 dotnet10 dotnet10 |
| CVE | CVE-2026-58649 | Origin validation error in .NET allows an unauthorized attacker to dis ... | dotnet10 dotnet8 dotnet10 dotnet8 dotnet8 dotnet10 dotnet8 dotnet10 |
| CVE | CVE-2026-8932 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. li | curl curl |
| CVE | CVE-2026-73073 | Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr | vim vim vim vim |
| CVE | CVE-2026-6791 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use | glibc glibc glibc glibc glibc glibc glibc glibc |
| CVE | CVE-2026-6368 | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv me | glibc glibc glibc glibc glibc glibc glibc glibc |
| CVE | CVE-2026-19542 | Out-of-bounds stack array access in tdelete | glibc glibc glibc glibc glibc glibc glibc glibc |
About
-
Send Feedback to @ubuntu_updates