Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-85498 | Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow | policykit-1 policykit-1 policykit-1 policykit-1 |
| CVE | CVE-2025-27773 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature c | simplesamlphp |
| Launchpad | 2166531 | [SRU] Update DCN 3.5 microcode to match DCN 3.6 microcode in noble | linux-firmware-amd-graphics |
| Launchpad | 2164946 | xxd missing from ubuntu-minimal:26.04 images | ubuntu-meta |
| Launchpad | 2165137 | [SRU] Missing X.Org input drivers break keyboard and mouse input on minimal installation | ubuntukylin-meta |
| Launchpad | 2163338 | Include Intel NVL thermal support | thermald |
| Launchpad | 2156681 | Calamares fails to finish the install when there are multiple LUKS devices | calamares |
| Launchpad | 2164630 | [SRU][Resolute] Fix use-after-free caused by reentrant client teardown in GATT implementation | bluez bluez |
| Launchpad | 2164626 | [SRU][Resolute] Fix sending extra bytes with MGMT_OP_ADD_EXT_ADV_DATA | bluez bluez |
| Launchpad | 2164618 | [SRU][Resolute] Fix PBAP PullPhoneBook failure with ebook backend | bluez bluez |
| Launchpad | 2163625 | [SRU][Resolute] Set L2CAP IMTU for OBEX profile listeners to fix OPP Rx KPI | bluez bluez |
| Launchpad | 2160129 | Descriptor file for amd-sev is not compatible with SEV-SNP | edk2-hwe edk2 edk2-hwe edk2 |
| Launchpad | 2155240 | masakari-hostmonitor fails to start: masakarimonitors.cmd not installed | masakari-monitors masakari-monitors |
| Launchpad | 2165138 | [SRU] RC ISO pulls in gnome-shell | ubuntu-budgie-meta |
| CVE | CVE-2026-15816 | A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit | dracut dracut dracut dracut |
| CVE | CVE-2026-42533 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege | nginx nginx nginx nginx nginx nginx nginx nginx nginx nginx nginx nginx |
| CVE | CVE-2026-50292 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root | libinput libinput libinput libinput libinput libinput libinput libinput |
| Launchpad | 2166202 | [SRU] Backport 0.10.0 to Resolute | rust-coreutils |
| CVE | CVE-2026-9323 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randr | urwid urwid |
| CVE | CVE-2025-55763 | Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP | civetweb civetweb |
About
-
Send Feedback to @ubuntu_updates