Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2167039 | pam_lastlog2.so not linked against libpam: \ | util-linux util-linux |
| Launchpad | 2154067 | [SRU] Python error when tagging with eyeD3 after upgrading to resolute raccoon | eyed3 |
| Launchpad | 2166611 | v4l2-relayd unusable with libcamerasrc/SoftISP: sandbox blocks dma-buf allocator, and YUY2 caps never negotiate (black frames) | v4l2-relayd |
| Launchpad | 2167831 | ceilometer agents fail to start on Python 3.14: PicklingError on _ConfigFileOpt lambda | ceilometer ceilometer |
| Launchpad | 2147499 | [SRU] open-iscsi initramfs: preserve static iBFT semantics while fixing netplan rendering for MAAS boot | open-iscsi open-iscsi open-iscsi open-iscsi open-iscsi open-iscsi |
| CVE | CVE-2026-5917 | libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerabi | libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 |
| Launchpad | 2164908 | SRU: Update to upstream 1.0.4 | ubuntu-cuda-packaging-tools |
| CVE | CVE-2026-19685 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incom | network-manager network-manager network-manager network-manager |
| CVE | CVE-2026-55995 | A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 5 | open-isns open-isns open-isns open-isns open-isns open-isns open-isns open-isns open-isns open-isns open-isns open-isns |
| CVE | CVE-2026-59893 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/le | sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse |
| CVE | CVE-2026-71491 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-o | sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse |
| CVE | CVE-2026-54284 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly | sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse sqlparse |
| Launchpad | 2167309 | [Noble] Enable signing for Xilinx kernels and Ubuntu Core FIT images | linux-xilinx |
| CVE | CVE-2026-82474 | Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run speci | sudo sudo sudo sudo sudo sudo sudo sudo |
| CVE | CVE-2026-66034 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbit | libssh2 libssh2 |
| Launchpad | 2007394 | [MIR][jammy] oem-stella-maria-meta | oem-stella-maria-meta |
| Launchpad | 1999966 | [MIR][jammy] oem-stella-slowpoke-rpl-meta | oem-stella-slowpoke-rpl-meta |
| CVE | CVE-2026-18297 | GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb | gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 gst-plugins-base1.0 |
| CVE | CVE-2026-18299 | GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
| CVE | CVE-2026-18298 | GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
About
-
Send Feedback to @ubuntu_updates