Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-13608 | A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptogra | curl curl curl curl |
| Launchpad | 2167779 | Reverted security upload 8.20.0-2ubuntu4, broken checksrc and CVE-2026-8927 backport | curl curl curl curl curl curl |
| Launchpad | 2167969 | Upstream update to CVE-2026-9080 fix missing in Resolute | curl curl |
| Launchpad | 2167418 | [SRU] mutter: fullscreen applications run below the display refresh rate | mutter mutter |
| Launchpad | 2083548 | apparmor transmission-daemon | apparmor apparmor |
| Launchpad | 2161023 | [SRU] Enable support for Hibiscus Cloud Archive | software-properties software-properties |
| Launchpad | 2156069 | software-properties-gtk is mostly untranslated | software-properties software-properties |
| CVE | CVE-2026-76957 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CV | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-76641 | Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external e | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-66046 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-72522 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Uni | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56132 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled w | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56131 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a us | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56411 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56407 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56406 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-56410 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | expat expat expat expat expat expat expat expat expat expat expat expat |
| CVE | CVE-2026-74248 | OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor | octavia octavia octavia octavia octavia octavia |
| CVE | CVE-2026-94571 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f | octavia octavia octavia octavia octavia octavia |
About
-
Send Feedback to @ubuntu_updates