UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-59797 Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2
CVE CVE-2026-57941 Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2
CVE CVE-2026-56154 Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: fr apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2
CVE CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (w lxml lxml lxml lxml lxml lxml lxml lxml
CVE CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ` lxml lxml lxml lxml lxml lxml lxml lxml lxml lxml lxml lxml
Launchpad 2166409 [SRU] Please backport golang-1.25 (1.25.12) and golang-1.26 (1.26.7) to resolute, noble and jammy golang-1.25 golang-1.25 golang-1.25 golang-1.25
Launchpad 2158102 [SRU] 2.77.1 snapd snapd snapd snapd snapd snapd
CVE CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl golang-1.24 golang-1.21 golang-1.24 golang-1.21 golang-1.18 golang-1.18 golang-golang-x-net golang-golang-x-net
Launchpad 2166537 [SRU] python-glance-store 2024.1 fix Cinder Dell PowerFlex python-glance-store
CVE CVE-2026-63909 In the Linux kernel, the following vulnerability has been resolved: ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops Commit d07b2 linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-72382 In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject undersized DACLs before parsing ACEs parse_dacl() limits the atta linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-64023 In the Linux kernel, the following vulnerability has been resolved: gpio: aggregator: fix a potential use-after-free On error we free aggr->lookups linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-64239 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() DAMON sysfs mai linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-63884 In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-63920 In the Linux kernel, the following vulnerability has been resolved: ipv6: validate extension header length before copying to cmsg ip6_datagram_recv linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-74388 In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data The OSS seq linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-74387 In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize output teardown with event_input event_process_midi( linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-64243 In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds check simple_mux_control_put( linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-74385 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check return value of nvmet_tcp_set_queue_sock The return value of n linux-nvidia-tegra linux-nvidia-tegra
CVE CVE-2026-64026 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg This i linux-nvidia-tegra linux-nvidia-tegra



About   -   Send Feedback to @ubuntu_updates