UbuntuUpdates.org

Release lucid does not exist.

Latest Changelogs for all releases

All releases Jammy Noble Plucky Resolute
Include all PPAs Exclude daily builds PPAs Exclude all PPAs
Include levels: securityupdatesproposedbackportsbase

Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).

netplan.io Sep 15th 04:07
Release: resolute Repo: main Level: updates New version: 1.2-1ubuntu5.1
Packages in group:  libnetplan1 libnetplan-dev netplan-generator python3-netplan

netplan.io (1.2-1ubuntu5.1) resolute; urgency=medium

  * d/p/lp2104373-return-exit-code-1-on-error.patch: return exit code 1 when
    netplan exits on error (LP: #2104373)

 -- Guilherme Puida Moreira Mon, 31 Aug 2026 09:23:48 -0300

2104373 [Bug] Failed 'netplan set' operation doesn't return non-0 error (Netplan 1.1.1 in Ubuntu 24.04)

krb5 Sep 15th 04:07
Release: noble Repo: universe Level: updates New version: 1.20.1-6ubuntu2.10
Packages in group:  krb5-admin-server krb5-gss-samples krb5-k5tls krb5-kdc krb5-kdc-ldap krb5-kpropd krb5-otp krb5-pkinit krb5-user

krb5 (1.20.1-6ubuntu2.10) noble; urgency=medium

  * d/t/control: Don't run kinit-pwexpire on 32-bit architectures
    The test verifies correct behavior for dates in the far future
    (~70 years after the time of test), which krb5's date parser
    only accepts on 64 bit arches.


krb5 Sep 15th 04:07
Release: noble Repo: main Level: updates New version: 1.20.1-6ubuntu2.10
Packages in group:  krb5-doc krb5-locales krb5-multidev libgssapi-krb5-2 libgssrpc4t64 libk5crypto3 libkadm5clnt-mit12 libkadm5srv-mit12 libkdb5-10t64 libkrad0 libkrad-dev (... see all)

krb5 (1.20.1-6ubuntu2.10) noble; urgency=medium

  * d/t/control: Don't run kinit-pwexpire on 32-bit architectures
    The test verifies correct behavior for dates in the far future
    (~70 years after the time of test), which krb5's date parser
    only accepts on 64 bit arches.


netplan.io Sep 15th 04:07
Release: noble Repo: main Level: updates New version: 1.1.2-8ubuntu1~24.04.3
Packages in group:  libnetplan1 libnetplan-dev netplan-generator python3-netplan

netplan.io (1.1.2-8ubuntu1~24.04.3) noble; urgency=medium

  * d/p/lp2104373-return-exit-code-1-on-error.patch: return exit code 1 when
    netplan exits on error (LP: #2104373)

 -- Guilherme Puida Moreira Mon, 31 Aug 2026 09:19:49 -0300

2104373 [Bug] Failed 'netplan set' operation doesn't return non-0 error (Netplan 1.1.1 in Ubuntu 24.04)

krb5 Sep 15th 04:07
Release: jammy Repo: universe Level: updates New version: 1.19.2-2ubuntu0.10
Packages in group:  krb5-admin-server krb5-gss-samples krb5-k5tls krb5-kdc krb5-kdc-ldap krb5-kpropd krb5-otp krb5-pkinit krb5-user

krb5 (1.19.2-2ubuntu0.10) jammy; urgency=medium

  * d/t/control: Don't run kinit-pwexpire on 32-bit architectures
    The test verifies correct behavior for dates in the far future
    (~70 years after the time of test), which krb5's date parser
    only accepts on 64 bit arches.


krb5 Sep 15th 04:07
Release: jammy Repo: main Level: updates New version: 1.19.2-2ubuntu0.10
Packages in group:  krb5-doc krb5-locales krb5-multidev libgssapi-krb5-2 libgssrpc4 libk5crypto3 libkadm5clnt-mit12 libkadm5srv-mit12 libkdb5-10 libkrad0 libkrad-dev (... see all)

krb5 (1.19.2-2ubuntu0.10) jammy; urgency=medium

  * d/t/control: Don't run kinit-pwexpire on 32-bit architectures
    The test verifies correct behavior for dates in the far future
    (~70 years after the time of test), which krb5's date parser
    only accepts on 64 bit arches.


netplan.io Sep 15th 04:07
Release: jammy Repo: main Level: updates New version: 0.107.1-3ubuntu0.22.04.5
Packages in group:  libnetplan0 libnetplan-dev netplan-generator python3-netplan

netplan.io (0.107.1-3ubuntu0.22.04.5) jammy; urgency=medium

  * d/p/lp2104373-return-exit-code-1-on-error.patch: return exit code 1 when
    netplan exits on error (LP: #2104373)

 -- Guilherme Puida Moreira Mon, 31 Aug 2026 09:05:38 -0300

2104373 [Bug] Failed 'netplan set' operation doesn't return non-0 error (Netplan 1.1.1 in Ubuntu 24.04)

livecd-rootfs Sep 15th 03:07
Release: jammy Repo: main Level: updates New version: 2.765.57
Packages in group: 

livecd-rootfs (2.765.57) jammy; urgency=medium

  * Cherry-pick fix for autopkgtests from ubuntu/master: (LP: #2124984)
    - Add NOW env variable in autopkgtest.

2124984 build.info is not present on ubuntu-base and ubuntu-oci Jammy images

msr-tools Sep 15th 01:07
Release: noble Repo: main Level: updates New version: 1.3-5ubuntu0.1
Packages in group: 

msr-tools (1.3-5ubuntu0.1) noble; urgency=medium

  * Check scandir return value in rdmsr and wrmsr to prevent a segmentation
    fault when /dev/cpu is absent (LP: #2163089).
    - d/p/lp2163089-check-scandir-return-value-in-rdmsr-and-wrmsr.patch

 -- Leah Goldberg Fri, 14 Aug 2026 17:46:37 -0400

2163089 rdmsr and wrmsr segfault when invoked with -a without the msr module loaded

msr-tools Sep 15th 01:07
Release: jammy Repo: main Level: updates New version: 1.3-4ubuntu0.1
Packages in group: 

msr-tools (1.3-4ubuntu0.1) jammy; urgency=medium

  * Check scandir return value in rdmsr and wrmsr to prevent a segmentation
    fault when /dev/cpu is absent (LP: #2163089).
    - d/p/lp2163089-check-scandir-return-value-in-rdmsr-and-wrmsr.patch

 -- Leah Goldberg Fri, 14 Aug 2026 17:55:24 -0400

2163089 rdmsr and wrmsr segfault when invoked with -a without the msr module loaded

dracut Sep 14th 23:07
Release: resolute Repo: universe Level: updates New version: 110-11ubuntu0.1
Packages in group:  dracut-test

dracut (110-11ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Several security issues
    - debian/patches/fix-base-sanitize-message-written-by-die-to-the-emergency.patch:
      sanitize message written by die() to the emergency hook at
      modules.d/80base/dracut-lib.sh
    - CVE-2026-15816
    - debian/patches/fix-overlayfs-crypt-prevent-eval-injection-in-parse_overl.patch:
      prevent eval injection in parse_overlay_opts() at
      modules.d/71overlayfs-crypt/overlayfs-crypt-lib.sh
    - No CVE number
    - debian/patches/feat-base-add-escape-function-implementing-printf-q.patch:
      add escape function implementing printf %q at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-dracut-lib-sanitize-variable-assignments-using-eval.patch:
      sanitize variable assignments using eval at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-systemd-networkd-escape-values-from-DHCP-options.patch:
      escape values from DHCP options at
      modules.d/11systemd-networkd/networkd-run.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-initiator-and-target-names.patch:
      normalize initiator and target names at
      modules.d/45net-lib/net-lib.sh, modules.d/74iscsi/iscsiroot.sh,
      modules.d/74iscsi/module-setup.sh, modules.d/74iscsi/parse-iscsiroot.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-LUN-parameters.patch:
      validate iSCSI LUN parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-normalize-iSCSI-target-names-on-the-iqn.-eui..patch:
      normalize iSCSI target names on the iqn./eui./naa. path at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-do-not-source-the-boot-time-net-lib.sh-into-mod.patch:
      do not source the boot-time net-lib.sh into module-setup.sh at
      dracut-functions.sh, modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-the-target-name-in-the-generated-netr.patch:
      normalize the target name in the generated netroot= line at
      modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-globbing-does-not-work.patch:
      --remove globbing does not work at dracut.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-allows-removing-files-from-the-host-fil.patch:
      --remove allows removing files from the host filesystem at dracut.sh
    - No CVE number
    - debian/patches/refactor-net-lib-use-strip_non_digits-to-validate-iSCSI-L.patch:
      use strip_non_digits() to validate iSCSI LUN parameters at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-port-parameters.patch:
      validate iSCSI port parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-sanitize-netroot-value-passed-to-initqueue-scri.patch:
      sanitiz

(See more...)
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit

dracut Sep 14th 23:07
Release: resolute Repo: main Level: updates New version: 110-11ubuntu0.1
Packages in group:  dracut-core dracut-install dracut-network

dracut (110-11ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Several security issues
    - debian/patches/fix-base-sanitize-message-written-by-die-to-the-emergency.patch:
      sanitize message written by die() to the emergency hook at
      modules.d/80base/dracut-lib.sh
    - CVE-2026-15816
    - debian/patches/fix-overlayfs-crypt-prevent-eval-injection-in-parse_overl.patch:
      prevent eval injection in parse_overlay_opts() at
      modules.d/71overlayfs-crypt/overlayfs-crypt-lib.sh
    - No CVE number
    - debian/patches/feat-base-add-escape-function-implementing-printf-q.patch:
      add escape function implementing printf %q at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-dracut-lib-sanitize-variable-assignments-using-eval.patch:
      sanitize variable assignments using eval at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-systemd-networkd-escape-values-from-DHCP-options.patch:
      escape values from DHCP options at
      modules.d/11systemd-networkd/networkd-run.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-initiator-and-target-names.patch:
      normalize initiator and target names at
      modules.d/45net-lib/net-lib.sh, modules.d/74iscsi/iscsiroot.sh,
      modules.d/74iscsi/module-setup.sh, modules.d/74iscsi/parse-iscsiroot.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-LUN-parameters.patch:
      validate iSCSI LUN parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-normalize-iSCSI-target-names-on-the-iqn.-eui..patch:
      normalize iSCSI target names on the iqn./eui./naa. path at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-do-not-source-the-boot-time-net-lib.sh-into-mod.patch:
      do not source the boot-time net-lib.sh into module-setup.sh at
      dracut-functions.sh, modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-the-target-name-in-the-generated-netr.patch:
      normalize the target name in the generated netroot= line at
      modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-globbing-does-not-work.patch:
      --remove globbing does not work at dracut.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-allows-removing-files-from-the-host-fil.patch:
      --remove allows removing files from the host filesystem at dracut.sh
    - No CVE number
    - debian/patches/refactor-net-lib-use-strip_non_digits-to-validate-iSCSI-L.patch:
      use strip_non_digits() to validate iSCSI LUN parameters at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-port-parameters.patch:
      validate iSCSI port parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-sanitize-netroot-value-passed-to-initqueue-scri.patch:
      sanitiz

(See more...)
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit

dracut Sep 14th 22:07
Release: resolute Repo: universe Level: security New version: 110-11ubuntu0.1
Packages in group:  dracut-test

dracut (110-11ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Several security issues
    - debian/patches/fix-base-sanitize-message-written-by-die-to-the-emergency.patch:
      sanitize message written by die() to the emergency hook at
      modules.d/80base/dracut-lib.sh
    - CVE-2026-15816
    - debian/patches/fix-overlayfs-crypt-prevent-eval-injection-in-parse_overl.patch:
      prevent eval injection in parse_overlay_opts() at
      modules.d/71overlayfs-crypt/overlayfs-crypt-lib.sh
    - No CVE number
    - debian/patches/feat-base-add-escape-function-implementing-printf-q.patch:
      add escape function implementing printf %q at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-dracut-lib-sanitize-variable-assignments-using-eval.patch:
      sanitize variable assignments using eval at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-systemd-networkd-escape-values-from-DHCP-options.patch:
      escape values from DHCP options at
      modules.d/11systemd-networkd/networkd-run.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-initiator-and-target-names.patch:
      normalize initiator and target names at
      modules.d/45net-lib/net-lib.sh, modules.d/74iscsi/iscsiroot.sh,
      modules.d/74iscsi/module-setup.sh, modules.d/74iscsi/parse-iscsiroot.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-LUN-parameters.patch:
      validate iSCSI LUN parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-normalize-iSCSI-target-names-on-the-iqn.-eui..patch:
      normalize iSCSI target names on the iqn./eui./naa. path at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-do-not-source-the-boot-time-net-lib.sh-into-mod.patch:
      do not source the boot-time net-lib.sh into module-setup.sh at
      dracut-functions.sh, modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-the-target-name-in-the-generated-netr.patch:
      normalize the target name in the generated netroot= line at
      modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-globbing-does-not-work.patch:
      --remove globbing does not work at dracut.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-allows-removing-files-from-the-host-fil.patch:
      --remove allows removing files from the host filesystem at dracut.sh
    - No CVE number
    - debian/patches/refactor-net-lib-use-strip_non_digits-to-validate-iSCSI-L.patch:
      use strip_non_digits() to validate iSCSI LUN parameters at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-port-parameters.patch:
      validate iSCSI port parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-sanitize-netroot-value-passed-to-initqueue-scri.patch:
      sanitiz

(See more...)
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit

dracut Sep 14th 22:07
Release: resolute Repo: main Level: security New version: 110-11ubuntu0.1
Packages in group:  dracut-core dracut-install dracut-network

dracut (110-11ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Several security issues
    - debian/patches/fix-base-sanitize-message-written-by-die-to-the-emergency.patch:
      sanitize message written by die() to the emergency hook at
      modules.d/80base/dracut-lib.sh
    - CVE-2026-15816
    - debian/patches/fix-overlayfs-crypt-prevent-eval-injection-in-parse_overl.patch:
      prevent eval injection in parse_overlay_opts() at
      modules.d/71overlayfs-crypt/overlayfs-crypt-lib.sh
    - No CVE number
    - debian/patches/feat-base-add-escape-function-implementing-printf-q.patch:
      add escape function implementing printf %q at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-dracut-lib-sanitize-variable-assignments-using-eval.patch:
      sanitize variable assignments using eval at
      modules.d/80base/dracut-lib.sh
    - No CVE number
    - debian/patches/fix-systemd-networkd-escape-values-from-DHCP-options.patch:
      escape values from DHCP options at
      modules.d/11systemd-networkd/networkd-run.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-initiator-and-target-names.patch:
      normalize initiator and target names at
      modules.d/45net-lib/net-lib.sh, modules.d/74iscsi/iscsiroot.sh,
      modules.d/74iscsi/module-setup.sh, modules.d/74iscsi/parse-iscsiroot.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-LUN-parameters.patch:
      validate iSCSI LUN parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-normalize-iSCSI-target-names-on-the-iqn.-eui..patch:
      normalize iSCSI target names on the iqn./eui./naa. path at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-do-not-source-the-boot-time-net-lib.sh-into-mod.patch:
      do not source the boot-time net-lib.sh into module-setup.sh at
      dracut-functions.sh, modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-iscsi-normalize-the-target-name-in-the-generated-netr.patch:
      normalize the target name in the generated netroot= line at
      modules.d/74iscsi/module-setup.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-globbing-does-not-work.patch:
      --remove globbing does not work at dracut.sh
    - No CVE number
    - debian/patches/fix-dracut-remove-allows-removing-files-from-the-host-fil.patch:
      --remove allows removing files from the host filesystem at dracut.sh
    - No CVE number
    - debian/patches/refactor-net-lib-use-strip_non_digits-to-validate-iSCSI-L.patch:
      use strip_non_digits() to validate iSCSI LUN parameters at
      modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-net-lib-validate-iSCSI-port-parameters.patch:
      validate iSCSI port parameters at modules.d/45net-lib/net-lib.sh
    - No CVE number
    - debian/patches/fix-iscsi-sanitize-netroot-value-passed-to-initqueue-scri.patch:
      sanitiz

(See more...)
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit

nginx Sep 14th 16:07
Release: resolute Repo: universe Level: updates New version: 1.28.3-2ubuntu1.11
Packages in group:  libnginx-mod-http-geoip libnginx-mod-http-perl libnginx-mod-stream-geoip nginx-dev nginx-extras nginx-full nginx-light

nginx (1.28.3-2ubuntu1.11) resolute-security; urgency=medium

  * SECURITY UPDATE: DoS and possible code execution via map directive
    - debian/patches/CVE-2026-42533.patch: fix DoS and possible code execution
      via map directive in src/http/modules/ngx_http_fastcgi_module.c,
      src/http/modules/ngx_http_grpc_module.c,
      src/http/modules/ngx_http_index_module.c,
      src/http/modules/ngx_http_proxy_module.c,
      src/http/modules/ngx_http_rewrite_module.c,
      src/http/modules/ngx_http_scgi_module.c,
      src/http/modules/ngx_http_try_files_module.c,
      src/http/modules/ngx_http_uwsgi_module.c, src/http/ngx_http_script.c,
      src/http/ngx_http_script.h, src/stream/ngx_stream_script.c,
      src/stream/ngx_stream_script.h.
    - CVE-2026-42533

 -- Marc Deslauriers Sun, 06 Sep 2026 18:21:32 -0400

CVE-2026-42533 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege



About   -   Send Feedback to @ubuntu_updates