UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-64531 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores gene linux-hwe-6.17 linux linux linux linux-hwe-7.0 linux-hwe-6.8 linux-lowlatency-hwe-6.8 linux-riscv linux-qcom linux-azure-nvidia linux-riscv-6.8 linux-xilinx linux-xilinx-zynqmp linux-riscv-7.0
CVE CVE-2026-52999 In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_m linux-hwe-6.17
CVE CVE-2026-52982 In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a linux-hwe-6.17
CVE CVE-2026-56003 A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf libxfont libxfont libxfont
CVE CVE-2026-56002 A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec libxfont libxfont libxfont
CVE CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the libxfont libxfont libxfont
Launchpad 2161162 1:10.2p1-2ubuntu3.4 built without crypt() openssh build-essential openssh build-essential
Launchpad 2147129 [SRU] dbx updates fail to notify snapd on default image fwupd fwupd
Launchpad 2153804 SRU: New upstream version 7.2.4 rocm-cmake
Launchpad 2159601 SRU: pkg-rocm-tools: enable gfx950 (AMD Instinct MI350 / CDNA4) build target for resolute pkg-rocm-tools
Launchpad 2156423 Fix grub-initrd-fallback.service order grub2 grub2
Launchpad 2161092 tzdata 2026c release tzdata tzdata tzdata tzdata tzdata
CVE CVE-2026-12391 An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools
CVE CVE-2026-11386 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools
CVE CVE-2026-9494 An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools ubuntu-advantage-tools
Launchpad 2160650 tar after USN-8477-1 cannot extract previously valid files tar tar tar tar tar tar tar tar tar tar tar tar
Launchpad 2155110 Autopkgtest failure on amd64v3 ghostty
Launchpad 2148769 [SRU] ghostty does not start: Illegal instruction ghostty
Launchpad 2158737 autopkgtest fails in Noble because of missing scsi_debug kernel module gvfs
Launchpad 2159018 [SRU] gnome-control-center 50.3 gnome-control-center



About   -   Send Feedback to @ubuntu_updates