Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-64531 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores gene | linux-hwe-6.17 linux linux linux linux-hwe-7.0 linux-hwe-6.8 linux-lowlatency-hwe-6.8 linux-riscv linux-qcom linux-azure-nvidia linux-riscv-6.8 linux-xilinx linux-xilinx-zynqmp linux-riscv-7.0 |
| CVE | CVE-2026-52999 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_m | linux-hwe-6.17 |
| CVE | CVE-2026-52982 | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a | linux-hwe-6.17 |
| CVE | CVE-2026-56003 | A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf | libxfont libxfont libxfont |
| CVE | CVE-2026-56002 | A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to exec | libxfont libxfont libxfont |
| CVE | CVE-2026-56001 | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the | libxfont libxfont libxfont |
| Launchpad | 2161162 | 1:10.2p1-2ubuntu3.4 built without crypt() | openssh build-essential openssh build-essential |
| Launchpad | 2147129 | [SRU] dbx updates fail to notify snapd on default image | fwupd fwupd |
| Launchpad | 2153804 | SRU: New upstream version 7.2.4 | rocm-cmake |
| Launchpad | 2159601 | SRU: pkg-rocm-tools: enable gfx950 (AMD Instinct MI350 / CDNA4) build target for resolute | pkg-rocm-tools |
| Launchpad | 2156423 | Fix grub-initrd-fallback.service order | grub2 grub2 |
| Launchpad | 2161092 | tzdata 2026c release | tzdata tzdata tzdata tzdata tzdata |
| CVE | CVE-2026-12391 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| CVE | CVE-2026-11386 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| CVE | CVE-2026-9494 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT | ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools |
| Launchpad | 2160650 | tar after USN-8477-1 cannot extract previously valid files | tar tar tar tar tar tar tar tar tar tar tar tar |
| Launchpad | 2155110 | Autopkgtest failure on amd64v3 | ghostty |
| Launchpad | 2148769 | [SRU] ghostty does not start: Illegal instruction | ghostty |
| Launchpad | 2158737 | autopkgtest fails in Noble because of missing scsi_debug kernel module | gvfs |
| Launchpad | 2159018 | [SRU] gnome-control-center 50.3 | gnome-control-center |
About
-
Send Feedback to @ubuntu_updates