Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-59797 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache | apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 |
| CVE | CVE-2026-57941 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2 | apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 |
| CVE | CVE-2026-56154 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: fr | apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 apache2 |
| CVE | CVE-2026-41066 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (w | lxml lxml lxml lxml lxml lxml lxml lxml |
| CVE | CVE-2026-49825 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ` | lxml lxml lxml lxml lxml lxml lxml lxml lxml lxml lxml lxml |
| Launchpad | 2166409 | [SRU] Please backport golang-1.25 (1.25.12) and golang-1.26 (1.26.7) to resolute, noble and jammy | golang-1.25 golang-1.25 golang-1.25 golang-1.25 |
| Launchpad | 2158102 | [SRU] 2.77.1 | snapd snapd snapd snapd snapd snapd |
| CVE | CVE-2026-39821 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl | golang-1.24 golang-1.21 golang-1.24 golang-1.21 golang-1.18 golang-1.18 golang-golang-x-net golang-golang-x-net |
| Launchpad | 2166537 | [SRU] python-glance-store 2024.1 fix Cinder Dell PowerFlex | python-glance-store |
| CVE | CVE-2026-63909 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops Commit d07b2 | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-72382 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject undersized DACLs before parsing ACEs parse_dacl() limits the atta | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64023 | In the Linux kernel, the following vulnerability has been resolved: gpio: aggregator: fix a potential use-after-free On error we free aggr->lookups | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64239 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() DAMON sysfs mai | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-63884 | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-63920 | In the Linux kernel, the following vulnerability has been resolved: ipv6: validate extension header length before copying to cmsg ip6_datagram_recv | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74388 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data The OSS seq | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74387 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize output teardown with event_input event_process_midi( | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64243 | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds check simple_mux_control_put( | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-74385 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check return value of nvmet_tcp_set_queue_sock The return value of n | linux-nvidia-tegra linux-nvidia-tegra |
| CVE | CVE-2026-64026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg This i | linux-nvidia-tegra linux-nvidia-tegra |
About
-
Send Feedback to @ubuntu_updates