Latest Changelogs for all releases
Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).
| firefox-esr | Sep 1st 21:08 | This package belongs to a PPA: Mozilla ESR | |
|---|---|---|---|
| Release: noble | Repo: main | Level: base | New version: 140.15.0esr+ |
| Packages in group: | firefox-esr-dbg firefox-esr-dev firefox-esr-geckodriver firefox-esr-locale-af firefox-esr-locale-an firefox-esr-locale-ar firefox-esr-locale-as firefox-esr-locale-ast firefox-esr-locale-az firefox-esr-locale-be firefox-esr-locale-bg (... see all) | ||
|
firefox-esr (140.15.0esr+build1-0ubuntu0.24.04.1~mt1) noble; urgency=medium
|
|||
| libgcrypt20 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: resolute | Repo: universe | Level: updates | New version: 1.12.0-2ubuntu1.1 |
| Packages in group: | libgcrypt-bin libgcrypt-mingw-w64-dev | ||
|
libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| pyasn1 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 0.6.3-1ubuntu0.1 |
| Packages in group: | python3-pyasn1 python-pyasn1-doc | ||
|
pyasn1 (0.6.3-1ubuntu0.1) resolute-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 13:20:40 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| pam | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 1.7.0-5ubuntu3.2 |
| Packages in group: | libpam0g libpam0g-dev libpam-doc libpam-modules libpam-modules-bin libpam-runtime | ||
|
pam (1.7.0-5ubuntu3.2) resolute-security; urgency=medium * SECURITY UPDATE: account lockout bypass in pam_faillock account
-- Shafayat Hossain Majumder Wed, 26 Aug 2026 15:28:39 -0400 |
|||
| 2164901 | pam_faillock lockout silently defeated by cron/systemd-user account-phase calls - Ubuntu pam 1.7.0-5ubuntu3.1 predates upstream fix | ||
| libgcrypt20 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 1.12.0-2ubuntu1.1 |
| Packages in group: | libgcrypt20-dev libgcrypt20-doc | ||
|
libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| libgcrypt20 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: updates | New version: 1.10.3-2ubuntu0.2 |
| Packages in group: | libgcrypt-mingw-w64-dev | ||
|
libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| pyasn1 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 0.4.8-4ubuntu0.3 |
| Packages in group: | python3-pyasn1 python-pyasn1-doc | ||
|
pyasn1 (0.4.8-4ubuntu0.3) noble-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 13:36:50 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| libgcrypt20 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 1.10.3-2ubuntu0.2 |
| Packages in group: | libgcrypt20-dev libgcrypt20-doc | ||
|
libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| pyasn1 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: updates | New version: 0.4.8-1ubuntu0.3 |
| Packages in group: | pypy-pyasn1 | ||
|
pyasn1 (0.4.8-1ubuntu0.3) jammy-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 18:00:34 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| libgcrypt20 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: updates | New version: 1.9.4-3ubuntu3.3 |
| Packages in group: | libgcrypt-mingw-w64-dev | ||
|
libgcrypt20 (1.9.4-3ubuntu3.3) jammy-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
|
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| pyasn1 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 0.4.8-1ubuntu0.3 |
| Packages in group: | python3-pyasn1 python-pyasn1-doc | ||
|
pyasn1 (0.4.8-1ubuntu0.3) jammy-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 18:00:34 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| libgcrypt20 | Sep 1st 19:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 1.9.4-3ubuntu3.3 |
| Packages in group: | libgcrypt20-dev libgcrypt20-doc | ||
|
libgcrypt20 (1.9.4-3ubuntu3.3) jammy-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
|
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| opencryptoki | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: resolute | Repo: universe | Level: updates | New version: 3.26.0+dfsg-0ubuntu1.1 |
| Packages in group: | libopencryptoki0 libopencryptoki-dev | ||
|
opencryptoki (3.26.0+dfsg-0ubuntu1.1) resolute-security; urgency=medium * d/p/lp-2163255-fix-ckm-ecdh-aes-key-wrap-buffer-size.patch: Fix
-- Frank Heimes Tue, 18 Aug 2026 15:24:04 +0000 |
|||
| CVE-2026-22791 | openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AE | ||
| CVE-2026-40253 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared | ||
| CVE-2026-23893 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running i | ||
| rust-sudo-rs | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 0.2.13-0ubuntu1.2 |
| Packages in group: | sudo-rs | ||
|
rust-sudo-rs (0.2.13-0ubuntu1.2) resolute-security; urgency=medium * d/patches/fix-sudoedit.patch: Fix privilege escalation race in sudoedit
-- Simon Johnsson Thu, 27 Aug 2026 10:15:26 +0200 |
|||
| 2165142 | Time-of-check vs time-of-use issue in sudoedit allows local privilege escalation | ||
| libevent | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 2.1.12- |
| Packages in group: | libevent-2.1-7t64 libevent-core-2.1-7t64 libevent-dev libevent-extra-2.1-7t64 libevent-openssl-2.1-7t64 libevent-pthreads-2.1-7t64 | ||
|
libevent (2.1.12-stable-10ubuntu0.1) resolute-security; urgency=medium * SECURITY UPDATE: dangling pointer in buffer reference handling
-- Shafayat Hossain Majumder Fri, 28 Aug 2026 16:44:21 -0400 |
|||
| CVE-2026-63381 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere | ||
| CVE-2026-63382 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra | ||
| CVE-2026-63383 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c | ||
| CVE-2026-63384 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta | ||
| CVE-2026-63385 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int | ||