UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-85522 A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file sr valkey
CVE CVE-2026-63639 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream valkey
CVE CVE-2026-56684 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin valkey
Launchpad 2158643 [SRU] lxc: incorrect free() of cap_to_text() result in ambient caps setup causes intermittent startup failure lxc lxc
Launchpad 2069523 click 0.5.2-2ubuntu4 fails to install on Ubuntu 24.04 LTS click
Launchpad 2163501 [SRU] Mesa 25.2.8 disabled legacy `bind_wayland_display` code path mesa mesa
CVE CVE-2026-69249 python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, whe python-cryptography python-cryptography
CVE CVE-2026-69248 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an inte python-cryptography python-cryptography
CVE CVE-2026-69247 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, python-cryptography python-cryptography
CVE CVE-2026-39113 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05c sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3
Launchpad 2167438 [SRU] Neutron gazpacho stable releases neutron neutron
Launchpad 2150273 [SRU] SSH fails on IPA-joined systems when logging in with an alternative UPN suffix openssh openssh
Launchpad 2127049 wireplumber crashed with SIGABRT; \ wireplumber wireplumber
CVE CVE-2026-62377 libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory( libheif libheif libheif libheif
CVE CVE-2026-62291 libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 au libheif libheif libheif libheif
Launchpad 2160197 open-vm-tools FTBFS with glib 2.88: g_free macro redefinition in glib_stubs.c open-vm-tools open-vm-tools
Launchpad 2166910 open-vm-tools.service unnecessary ordering constraint blocks cloud-init on non-VMware platforms open-vm-tools open-vm-tools open-vm-tools open-vm-tools
CVE CVE-2026-56211 A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder' aom aom aom aom aom aom aom aom
CVE CVE-2026-56210 A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Vi aom aom aom aom aom aom aom aom
CVE CVE-2026-56209 An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Vid aom aom aom aom aom aom aom aom



About   -   Send Feedback to @ubuntu_updates