Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2165958 | package postfix 3.10.6-4ubuntu2.1 failed to install/upgrade: old postfix package postinst maintainer script subprocess failed with exit status 1 | postfix postfix |
| Launchpad | 2068765 | [MIR][jammy] oem-stella-banhou-meta | oem-stella-banhou-meta |
| Launchpad | 1997645 | [MIR][jammy] oem-stella-mii-meta | oem-stella-mii-meta |
| Launchpad | 2115842 | [MIR][noble] oem-somerville-inkay-meta | oem-somerville-inkay-meta |
| Launchpad | 2084015 | gnome-shell has no response when plug-in unauthorized thunderbolt devices | gnome-shell gnome-shell |
| Launchpad | 2108011 | Screen zoom with multiple displays results in screen corruption | gnome-shell gnome-shell |
| Launchpad | 2164856 | sssd_be leaves an [ldap_child] \u003cdefunct\u003e zombie on every backend start | sssd sssd |
| Launchpad | 2169024 | [SRU] test-upstream autopkgtest failing for OpenSSH upgrades | crypto-policies |
| CVE | CVE-2026-8404 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `C | python-django python-django python-django python-django python-django python-django |
| CVE | CVE-2026-15307 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as | python-django python-django python-django python-django python-django python-django |
| CVE | CVE-2026-88924 | A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by call | gvfs gvfs gvfs gvfs gvfs gvfs |
| CVE | CVE-2026-84268 | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a l | gvfs gvfs gvfs gvfs gvfs gvfs |
| CVE | CVE-2026-86219 | Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_ | libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl libauthen-sasl-perl |
| CVE | CVE-2026-19387 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient | gst-plugins-bad1.0 gst-plugins-bad1.0 gst-plugins-bad1.0 gst-plugins-bad1.0 |
| CVE | CVE-2026-45184 | Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used. | mlt kdenlive mlt kdenlive |
| Launchpad | 2168441 | Kdenlive: Remote code execution via malicious project file | mlt kdenlive mlt kdenlive |
| CVE | CVE-2026-80183 | In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under an | keystone keystone keystone keystone keystone keystone |
| CVE | CVE-2026-80184 | In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) | keystone keystone keystone keystone keystone keystone |
| CVE | CVE-2026-80182 | In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new | keystone keystone keystone keystone keystone keystone |
| CVE | CVE-2026-84732 | Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted | openvpn openvpn openvpn openvpn openvpn openvpn |
About
-
Send Feedback to @ubuntu_updates