UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2143042 exec_mailer: Set group as well as uid when running the mailer sudo sudo sudo sudo sudo sudo sudo sudo sudo sudo sudo sudo
CVE CVE-2025-61985 ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used. openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2025-61984 ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-3497 Vulnerability in the OpenSSH GSSAPI delta included in various Linux di ... openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-26007 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers python-cryptography python-cryptography python-cryptography python-cryptography python-cryptography python-cryptography
Launchpad 2130487 rabbitmq-server install fails when another package is using port 5672 rabbitmq-server rabbitmq-server rabbitmq-server
CVE CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bo freetype freetype freetype freetype freetype freetype freetype freetype
CVE CVE-2026-3805 When doing a second SMB request to the same host again, curl would wro ... curl
CVE CVE-2026-3784 curl would wrongly reuse an existing HTTP proxy connection doing CONNE ... curl curl curl
CVE CVE-2026-3783 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ... curl curl curl
CVE CVE-2026-1965 libcurl can in some circumstances reuse the wrong connection when aske ... curl curl curl
Launchpad 2142446 [SRU] The entire desktop session crashes when browsing/playing videos/scrolling in firefox budgie-session budgie-session
Launchpad 2139061 [SRU] Add support for new Goodix device 27c6:66a9 libfprint libfprint libfprint libfprint libfprint libfprint libfprint libfprint
Launchpad 2143028 [SRU] Add quirks support for Goodix touchpad libinput libinput libinput libinput libinput libinput libinput libinput
CVE CVE-2025-0167 When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the follo curl curl curl curl
CVE CVE-2025-69662 SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used python-geopandas python-geopandas python-geopandas python-geopandas python-geopandas python-geopandas
Launchpad 2143861 1.10.2-4ubuntu0.1 regresses MFA in some cases network-manager-openvpn network-manager-openvpn network-manager-openvpn network-manager-openvpn
CVE CVE-2026-26127 Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. dotnet9 dotnet10 dotnet10 dotnet9 dotnet10 dotnet10
CVE CVE-2026-26130 Allocation of resources without limits or throttling in ASP.NET Core a ... dotnet8 dotnet8 dotnet8 dotnet9 dotnet10 dotnet10 dotnet9 dotnet10 dotnet8 dotnet10 dotnet8 dotnet8
Launchpad 2143198 [SRU] Fix GPU hang on gfx1152 and gfx1153 hardware linux-firmware linux-firmware



About   -   Send Feedback to @ubuntu_updates