Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-39821 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl | golang-1.24 golang-1.21 golang-1.24 golang-1.21 golang-1.18 golang-1.18 |
| Launchpad | 2166537 | [SRU] python-glance-store 2024.1 fix Cinder Dell PowerFlex | python-glance-store |
| CVE | CVE-2026-63909 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops Commit d07b2 | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-72382 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject undersized DACLs before parsing ACEs parse_dacl() limits the atta | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64023 | In the Linux kernel, the following vulnerability has been resolved: gpio: aggregator: fix a potential use-after-free On error we free aggr->lookups | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64239 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() DAMON sysfs mai | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-63884 | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-63920 | In the Linux kernel, the following vulnerability has been resolved: ipv6: validate extension header length before copying to cmsg ip6_datagram_recv | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74388 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data The OSS seq | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74387 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize output teardown with event_input event_process_midi( | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64243 | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds check simple_mux_control_put( | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74385 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check return value of nvmet_tcp_set_queue_sock The return value of n | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg This i | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74338 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable BPF_LSM_CGROUP programs at load time The cgroup shim runs | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-63923 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mb | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64123 | In the Linux kernel, the following vulnerability has been resolved: net: hsr: defer node table free until after RCU readers HSR node-list and node- | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64095 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid double decrement of bla.num_requests The bla.num_request | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-72485 | In the Linux kernel, the following vulnerability has been resolved: coresight: platform: defer connection counter increment until alloc succeeds co | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64222 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_ | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64017 | In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if | linux-nvidia-tegra linux-nvidia-tegra |
About
-
Send Feedback to @ubuntu_updates