UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2156085 [SRU] Update rocwmma to 7.2.4 in Resolute rocwmma
Launchpad 2155138 SRU: New upstream version 7.2.4 rocsolver
Launchpad 2155653 SRU: New upstream version 7.2.4 hipblaslt
Launchpad 2156252 SRU: New upstream version 7.2.4 hipsparse
Launchpad 2155392 SRU: New upstream version 7.2.4 rocfft
Launchpad 2158673 qemu: virtio-net host-to-guest RX stalls under sustained traffic qemu qemu qemu qemu
Launchpad 2154711 SRU: New upstream version 7.2.4 rocthrust
Launchpad 2156307 drive-mirror/blockdev-mirror/active blockcommit silently lose guest writes during job startup qemu-hwe qemu qemu-hwe qemu qemu qemu
Launchpad 2160034 [Ubuntu 26.04] qemu s390x: interface hardening fixes qemu-hwe qemu qemu-hwe qemu
Launchpad 2164757 Release the CUDA-13-2 packages on Resolute cuda-cudart-13-2 libcusparse-13-2
Launchpad 2155648 SRU: New upstream version 7.2.4 hipcub
Launchpad 2154553 SRU: New upstream version 7.2.4 rocsparse
CVE CVE-2026-80186 A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez
CVE CVE-2026-80185 BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SD bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez
CVE CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez
CVE CVE-2026-19774 BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez bluez
Launchpad 2154493 SRU: New upstream version 7.2.4 hiprand
CVE CVE-2026-88373 libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length libde265 libde265 libde265 libde265
CVE CVE-2026-86144 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2
CVE CVE-2026-86143 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a l libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2 libxml2



About   -   Send Feedback to @ubuntu_updates