UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-88914 A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-73433 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
CVE CVE-2026-17072 A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedde gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0
Launchpad 2068911 [SRU] alsa-ucm-conf: USB audio interfaces lose all profiles on noble (GoXLR, MOTU, Scarlett, Behringer, Steinberg) alsa-ucm-conf
Launchpad 2087772 crash (segfault) in libsqlite3 running multi-join query sqlite3 sqlite3
CVE CVE-2026-54873 Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit th openssl openssl
CVE CVE-2026-42772 Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a openssl openssl
CVE CVE-2026-94287 A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usa libxpm libxpm libxpm libxpm libxpm libxpm libxpm libxpm libxpm libxpm
Launchpad 2168407 Openscap Stop installing /usr/share/openscap/cpe openscap
CVE CVE-2026-71193 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe designate designate designate designate designate designate
CVE CVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing d kf6-kcoreaddons kf6-kcoreaddons
Launchpad 2166017 KShell: Incorrect command line parsing kf6-kcoreaddons kf6-kcoreaddons
Launchpad 2114620 package xrdp 0.9.17-2ubuntu3 failed to install/upgrade: installed xrdp package post-installation script subprocess returned error exit status 1 xrdp xrdp xrdp
Launchpad 2167720 FTBFS on resolute with hosts running 7.x kernels postfix postfix
Launchpad 2165958 package postfix 3.10.6-4ubuntu2.1 failed to install/upgrade: old postfix package postinst maintainer script subprocess failed with exit status 1 postfix postfix
Launchpad 2068765 [MIR][jammy] oem-stella-banhou-meta oem-stella-banhou-meta
Launchpad 1997645 [MIR][jammy] oem-stella-mii-meta oem-stella-mii-meta
Launchpad 2115842 [MIR][noble] oem-somerville-inkay-meta oem-somerville-inkay-meta
Launchpad 2084015 gnome-shell has no response when plug-in unauthorized thunderbolt devices gnome-shell gnome-shell



About   -   Send Feedback to @ubuntu_updates