UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-88373 libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length libde265 libde265
CVE CVE-2026-86144 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for libxml2 libxml2 libxml2 libxml2 libxml2 libxml2
CVE CVE-2026-86143 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a l libxml2 libxml2 libxml2 libxml2 libxml2 libxml2
CVE CVE-2026-86142 In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. libxml2 libxml2 libxml2 libxml2 libxml2 libxml2
CVE CVE-2026-86139 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. libxml2 libxml2
CVE CVE-2026-86138 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. libxml2 libxml2 libxml2 libxml2 libxml2 libxml2
CVE CVE-2026-76781 A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML libxml2 libxml2 libxml2 libxml2 libxml2 libxml2
Launchpad 2168785 Systemd based collection fails to get WSL version ubuntu-insights
Launchpad 2169719 sdot on arm64 adds the caller's v0 register to the result (Neoverse N1, AmpereOne, Apple silicon, ThunderX2/3) openblas
Launchpad 2101888 fsck.xfs can drop into a rescue shell when fsck.mode=force is set xfsprogs
Launchpad 2168936 pcs output with broken lines - why? pcs pcs
Launchpad 2169164 tmux server SIGSEGV in control_write() when a control-mode client is still connecting (fixed upstream in 3.7) tmux tmux tmux
CVE CVE-2026-53583 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2
Launchpad 2167992 SRU: Fix crash on rapid addition/removal of interfaces (Upstream #744) lldpd lldpd
Launchpad 2165836 mate-notification-daemon segfaults in libgobject at session start (glib 2.88 regression) mate-notification-daemon
CVE CVE-2026-16517 A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zi libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive libarchive
Launchpad 1998592 [SRU] in specific situations, nano can eat characters nano nano
Launchpad 2165869 glib2 GTask bug causes livelocks in Evolution (and others) glib2.0 glib2.0
Launchpad 2144770 plymouth reload sometimes switches to text mode plymouth plymouth plymouth plymouth
Launchpad 2168772 [SRU] orca 50.3 orca



About   -   Send Feedback to @ubuntu_updates