Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-57433 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a sign | perl perl |
| CVE | CVE-2026-57432 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an | perl perl |
| CVE | CVE-2026-13221 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when | perl perl |
| CVE | CVE-2026-12087 | Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument | perl perl |
| Launchpad | 2163136 | [SRU] QHD panel doesn't support 60Hz refresh rate but Ubuntu OS can see 60Hz on display setting | mutter mutter |
| CVE | CVE-2026-69806 | Exposure of sensitive information to an unauthorized actor in .NET all ... | dotnet10 dotnet10 |
| CVE | CVE-2026-58649 | Origin validation error in .NET allows an unauthorized attacker to dis ... | dotnet10 dotnet8 dotnet10 dotnet8 |
| CVE | CVE-2026-8932 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. li | curl curl |
| CVE | CVE-2026-73073 | Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr | vim vim vim vim |
| CVE | CVE-2026-6791 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use | glibc glibc glibc glibc glibc glibc glibc glibc |
| CVE | CVE-2026-6368 | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv me | glibc glibc glibc glibc glibc glibc glibc glibc |
| CVE | CVE-2026-19542 | Out-of-bounds stack array access in tdelete | glibc glibc glibc glibc glibc glibc glibc glibc |
| CVE | CVE-2026-15308 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processi | python3.14 python3.14 python3.10 python3.10 python3.14 python3.14 python3.10 python3.10 |
| CVE | CVE-2026-4360 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content fr | python3.14 python3.14 python3.10 python3.10 python3.14 python3.14 python3.10 python3.10 |
| Launchpad | 2126559 | [SRU] Missing usb/host/xhci-pci-renesas kernel module in the initramfs | initramfs-tools |
| CVE | CVE-2026-19487 | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan ear | perl perl perl perl |
| CVE | CVE-2026-15534 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_reg | perl perl perl perl |
| Launchpad | 2163128 | New upstream release 580.178.04 ERD/UDA | fabric-manager-580 nvidia-imex-580 libnvidia-nscq-580 nvidia-graphics-drivers-580-server nvidia-graphics-drivers-580 fabric-manager-580 nvidia-imex-580 libnvidia-nscq-580 nvidia-graphics-drivers-580-server nvidia-graphics-drivers-580 |
| Launchpad | 2163130 | New upstream release 595.91.07 UDA/ERD | fabric-manager-595 nvidia-imex-595 libnvidia-nscq-595 nvidia-graphics-drivers-595-server nvidia-graphics-drivers-595 nvidia-graphics-drivers-595-server nvidia-graphics-drivers-595 fabric-manager-595 nvidia-imex-595 libnvidia-nscq-595 |
| Launchpad | 2163131 | New upstream release 610.57.04 ERD/UDA | nvidia-graphics-drivers-610 nvidia-graphics-drivers-610 |
About
-
Send Feedback to @ubuntu_updates