UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2161038 broadcom-sta-dkms fails to build with kernel 7.0 HWE broadcom-sta
Launchpad 2138412 DNSSEC validation with stale cache enabled does not properly retry truncated response dnsmasq dnsmasq dnsmasq dnsmasq
Launchpad 2158603 Fingerprint enrollment: click \ gnome-control-center gnome-control-center
Launchpad 2103418 [25.04 FEAT] [post announcement] [KRN2304] CPU-MF Counters for new IBM Z hardware - libpfm4 part libpfm4 libpfm4
CVE CVE-2026-42250 bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds w bzip2 bzip2 bzip2 bzip2 bzip2 bzip2
CVE CVE-2026-54371 attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p attr attr attr attr attr attr
CVE CVE-2026-13204 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9
CVE CVE-2026-53910 diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In diffutils diffutils diffutils diffutils diffutils diffutils
CVE CVE-2026-56391 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. Th coreutils coreutils
CVE CVE-2025-5278 A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory ou coreutils coreutils coreutils coreutils coreutils coreutils
CVE CVE-2026-59850 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data libssh libssh libssh libssh libssh libssh
CVE CVE-2026-59849 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when libssh libssh
CVE CVE-2026-59848 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing libssh libssh libssh libssh libssh libssh
CVE CVE-2026-59847 A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al libssh libssh libssh libssh libssh libssh
CVE CVE-2026-59846 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment v libssh libssh libssh libssh libssh libssh
CVE CVE-2026-59845 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b libssh libssh libssh libssh libssh libssh
CVE CVE-2026-59844 A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP ser libssh libssh
CVE CVE-2026-59843 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write libssh libssh libssh libssh libssh libssh
CVE CVE-2026-15370 A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack libssh libssh
Launchpad 2165413 freerdp3 3.31.0 security update tracking bug freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3



About   -   Send Feedback to @ubuntu_updates