Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-1801 | A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so | libsoup2.4 libsoup3 libsoup3 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup2.4 libsoup2.4 libsoup2.4 |
| CVE | CVE-2026-87766 | A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via | bubblewrap bubblewrap bubblewrap bubblewrap bubblewrap bubblewrap |
| Launchpad | 2159565 | [SRU] Fix port-naming formatting regression in ALSA sequencer bridge | pipewire pipewire |
| CVE | CVE-2026-56389 | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration var | bison bison bison bison bison bison |
| Launchpad | 2150053 | [SRU] Ensure brcmfmac firmware present in dracut initrd | ubuntu-raspi-settings |
| CVE | CVE-2026-18649 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size | gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 gst-plugins-good1.0 |
| Launchpad | 2167436 | CPU throttled to 400MHz on Dell AIO QB24250 | thermald |
| Launchpad | 2158525 | mysql root account locked out after upgrade to 26.04 | ubuntu-release-upgrader ubuntu-release-upgrader |
| CVE | CVE-2026-85522 | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file sr | valkey valkey |
| CVE | CVE-2026-63639 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream | valkey valkey |
| CVE | CVE-2026-56684 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin | valkey valkey |
| Launchpad | 2158643 | [SRU] lxc: incorrect free() of cap_to_text() result in ambient caps setup causes intermittent startup failure | lxc lxc |
| Launchpad | 2069523 | click 0.5.2-2ubuntu4 fails to install on Ubuntu 24.04 LTS | click |
| Launchpad | 2163501 | [SRU] Mesa 25.2.8 disabled legacy `bind_wayland_display` code path | mesa mesa |
| CVE | CVE-2026-69249 | python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, whe | python-cryptography python-cryptography |
| CVE | CVE-2026-69248 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an inte | python-cryptography python-cryptography |
| CVE | CVE-2026-69247 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, | python-cryptography python-cryptography |
| CVE | CVE-2026-39113 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05c | sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 sqlite3 |
| Launchpad | 2167438 | [SRU] Neutron gazpacho stable releases | neutron neutron |
| Launchpad | 2150273 | [SRU] SSH fails on IPA-joined systems when logging in with an alternative UPN suffix | openssh openssh |
About
-
Send Feedback to @ubuntu_updates