Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2161038 | broadcom-sta-dkms fails to build with kernel 7.0 HWE | broadcom-sta |
| Launchpad | 2138412 | DNSSEC validation with stale cache enabled does not properly retry truncated response | dnsmasq dnsmasq dnsmasq dnsmasq |
| Launchpad | 2158603 | Fingerprint enrollment: click \ | gnome-control-center gnome-control-center |
| Launchpad | 2103418 | [25.04 FEAT] [post announcement] [KRN2304] CPU-MF Counters for new IBM Z hardware - libpfm4 part | libpfm4 libpfm4 |
| CVE | CVE-2026-42250 | bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds w | bzip2 bzip2 bzip2 bzip2 bzip2 bzip2 |
| CVE | CVE-2026-54371 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p | attr attr attr attr attr attr |
| CVE | CVE-2026-13204 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B | bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 bind9 |
| CVE | CVE-2026-53910 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In | diffutils diffutils diffutils diffutils diffutils diffutils |
| CVE | CVE-2026-56391 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. Th | coreutils coreutils |
| CVE | CVE-2025-5278 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory ou | coreutils coreutils coreutils coreutils coreutils coreutils |
| CVE | CVE-2026-59850 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data | libssh libssh libssh libssh libssh libssh |
| CVE | CVE-2026-59849 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when | libssh libssh |
| CVE | CVE-2026-59848 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing | libssh libssh libssh libssh libssh libssh |
| CVE | CVE-2026-59847 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al | libssh libssh libssh libssh libssh libssh |
| CVE | CVE-2026-59846 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment v | libssh libssh libssh libssh libssh libssh |
| CVE | CVE-2026-59845 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b | libssh libssh libssh libssh libssh libssh |
| CVE | CVE-2026-59844 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP ser | libssh libssh |
| CVE | CVE-2026-59843 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write | libssh libssh libssh libssh libssh libssh |
| CVE | CVE-2026-15370 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack | libssh libssh |
| Launchpad | 2165413 | freerdp3 3.31.0 security update tracking bug | freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 freerdp3 |
About
-
Send Feedback to @ubuntu_updates