Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-88914 | A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
| CVE | CVE-2026-73434 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
| CVE | CVE-2026-73433 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
| CVE | CVE-2026-17072 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedde | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
| Launchpad | 2068911 | [SRU] alsa-ucm-conf: USB audio interfaces lose all profiles on noble (GoXLR, MOTU, Scarlett, Behringer, Steinberg) | alsa-ucm-conf |
| Launchpad | 2087772 | crash (segfault) in libsqlite3 running multi-join query | sqlite3 sqlite3 |
| CVE | CVE-2026-54873 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit th | openssl openssl |
| CVE | CVE-2026-42772 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a | openssl openssl |
| CVE | CVE-2026-94287 | A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usa | libxpm libxpm libxpm libxpm libxpm libxpm libxpm libxpm libxpm libxpm |
| Launchpad | 2168407 | Openscap Stop installing /usr/share/openscap/cpe | openscap |
| CVE | CVE-2026-71193 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe | designate designate designate designate designate designate |
| CVE | CVE-2026-41526 | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing d | kf6-kcoreaddons kf6-kcoreaddons |
| Launchpad | 2166017 | KShell: Incorrect command line parsing | kf6-kcoreaddons kf6-kcoreaddons |
| Launchpad | 2114620 | package xrdp 0.9.17-2ubuntu3 failed to install/upgrade: installed xrdp package post-installation script subprocess returned error exit status 1 | xrdp xrdp xrdp |
| Launchpad | 2167720 | FTBFS on resolute with hosts running 7.x kernels | postfix postfix |
| Launchpad | 2165958 | package postfix 3.10.6-4ubuntu2.1 failed to install/upgrade: old postfix package postinst maintainer script subprocess failed with exit status 1 | postfix postfix |
| Launchpad | 2068765 | [MIR][jammy] oem-stella-banhou-meta | oem-stella-banhou-meta |
| Launchpad | 1997645 | [MIR][jammy] oem-stella-mii-meta | oem-stella-mii-meta |
| Launchpad | 2115842 | [MIR][noble] oem-somerville-inkay-meta | oem-somerville-inkay-meta |
| Launchpad | 2084015 | gnome-shell has no response when plug-in unauthorized thunderbolt devices | gnome-shell gnome-shell |
About
-
Send Feedback to @ubuntu_updates