Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2156085 | [SRU] Update rocwmma to 7.2.4 in Resolute | rocwmma |
| Launchpad | 2155138 | SRU: New upstream version 7.2.4 | rocsolver |
| Launchpad | 2155653 | SRU: New upstream version 7.2.4 | hipblaslt |
| Launchpad | 2156252 | SRU: New upstream version 7.2.4 | hipsparse |
| Launchpad | 2155392 | SRU: New upstream version 7.2.4 | rocfft |
| Launchpad | 2158673 | qemu: virtio-net host-to-guest RX stalls under sustained traffic | qemu qemu qemu qemu |
| Launchpad | 2154711 | SRU: New upstream version 7.2.4 | rocthrust |
| Launchpad | 2156307 | drive-mirror/blockdev-mirror/active blockcommit silently lose guest writes during job startup | qemu-hwe qemu qemu-hwe qemu qemu qemu |
| Launchpad | 2160034 | [Ubuntu 26.04] qemu s390x: interface hardening fixes | qemu-hwe qemu qemu-hwe qemu |
| Launchpad | 2164757 | Release the CUDA-13-2 packages on Resolute | cuda-cudart-13-2 libcusparse-13-2 |
| Launchpad | 2155648 | SRU: New upstream version 7.2.4 | hipcub |
| Launchpad | 2154553 | SRU: New upstream version 7.2.4 | rocsparse |
| CVE | CVE-2026-80186 | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| CVE | CVE-2026-80185 | BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SD | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| CVE | CVE-2026-75032 | A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| CVE | CVE-2026-19774 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary | bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez |
| Launchpad | 2154493 | SRU: New upstream version 7.2.4 | hiprand |
| CVE | CVE-2026-88373 | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length | libde265 libde265 libde265 libde265 |
| CVE | CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
| CVE | CVE-2026-86143 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a l | libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 |
About
-
Send Feedback to @ubuntu_updates