UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-85498 Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow policykit-1 policykit-1 policykit-1 policykit-1
CVE CVE-2025-27773 The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature c simplesamlphp
Launchpad 2166531 [SRU] Update DCN 3.5 microcode to match DCN 3.6 microcode in noble linux-firmware-amd-graphics
Launchpad 2164946 xxd missing from ubuntu-minimal:26.04 images ubuntu-meta
Launchpad 2165137 [SRU] Missing X.Org input drivers break keyboard and mouse input on minimal installation ubuntukylin-meta
Launchpad 2163338 Include Intel NVL thermal support thermald
Launchpad 2156681 Calamares fails to finish the install when there are multiple LUKS devices calamares
Launchpad 2164630 [SRU][Resolute] Fix use-after-free caused by reentrant client teardown in GATT implementation bluez bluez
Launchpad 2164626 [SRU][Resolute] Fix sending extra bytes with MGMT_OP_ADD_EXT_ADV_DATA bluez bluez
Launchpad 2164618 [SRU][Resolute] Fix PBAP PullPhoneBook failure with ebook backend bluez bluez
Launchpad 2163625 [SRU][Resolute] Set L2CAP IMTU for OBEX profile listeners to fix OPP Rx KPI bluez bluez
Launchpad 2160129 Descriptor file for amd-sev is not compatible with SEV-SNP edk2-hwe edk2 edk2-hwe edk2
Launchpad 2155240 masakari-hostmonitor fails to start: masakarimonitors.cmd not installed masakari-monitors masakari-monitors
Launchpad 2165138 [SRU] RC ISO pulls in gnome-shell ubuntu-budgie-meta
CVE CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit dracut dracut dracut dracut
CVE CVE-2026-42533 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege nginx nginx nginx nginx nginx nginx nginx nginx nginx nginx nginx nginx
CVE CVE-2026-50292 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root libinput libinput libinput libinput libinput libinput libinput libinput
Launchpad 2166202 [SRU] Backport 0.10.0 to Resolute rust-coreutils
CVE CVE-2026-9323 The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randr urwid urwid
CVE CVE-2025-55763 Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP civetweb civetweb



About   -   Send Feedback to @ubuntu_updates