UbuntuUpdates.org

Latest Changelogs for all releases

All releases Jammy Noble Plucky Resolute
Include all PPAs Exclude daily builds PPAs Exclude all PPAs
Include levels: securityupdatesproposedbackportsbase

Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).

dnsmasq Sep 2nd 04:07
Release: jammy Repo: main Level: updates New version: 2.91-0ubuntu0.22.04.1
Packages in group:  dnsmasq-base dnsmasq-utils

dnsmasq (2.91-0ubuntu0.22.04.1) jammy; urgency=medium

  * New upstream release 2.91 (LP: #2138412, #2026757)
    - Security fixes:
      + Fix out-of-bounds heap read in order_qsort() (potential SIGSEGV).
      + Fix buffer overflow with overly long lease-change script names.
    - Bug fixes:
      + Fix crash when no upstream servers are defined.
      + Fix erroneous "DNSSEC validated" state with non-DNSSEC upstream servers.
      + Fix TFTP off-by-2 bug.
      + Fix handling of EDNS0 UDP packet sizes.
      + Improve behaviour with non-responsive upstream TCP DNS servers.
      + Improve handling of truncated upstream answers.
    - New features:
      + Implement DNS-0x20 encoding (--do-0x20-encode, default off).
      + Add --dhcp-option-pxe for PXE-only DHCP options, including proxy mode.
      + Support PXE proxy-DHCP and DHCP-relay simultaneously.
      + Set --fast-dns-retries by default when DNSSEC is enabled.
    - d/patches: Refresh all patches to apply on top of new upstream version.
  * d/patches/CVE-*: add Origin headers.
  * d/tests: Backport autopkgtests from Questing.

 -- Guilherme Puida Moreira Fri, 07 Aug 2026 10:25:13 -0300

2138412 DNSSEC validation with stale cache enabled does not properly retry truncated response

firefox Sep 2nd 03:08
This package belongs to a PPA: Mozilla ESR
Release: resolute Repo: main Level: base New version: 155.0+build1-0ubuntu0.26.04.1~mt1
Packages in group:  firefox-dbg firefox-dev firefox-geckodriver firefox-locale-af firefox-locale-an firefox-locale-ar firefox-locale-as firefox-locale-ast firefox-locale-az firefox-locale-be firefox-locale-bg (... see all)

 firefox (155.0+build1-0ubuntu0.26.04.1~mt1) resolute; urgency=medium
 .
   * New upstream release (155.0+build1)
 .


firefox Sep 2nd 03:08
This package belongs to a PPA: Mozilla ESR
Release: noble Repo: main Level: base New version: 155.0+build1-0ubuntu0.24.04.1~mt1
Packages in group:  firefox-dbg firefox-dev firefox-geckodriver firefox-locale-af firefox-locale-an firefox-locale-ar firefox-locale-as firefox-locale-ast firefox-locale-az firefox-locale-be firefox-locale-bg (... see all)

 firefox (155.0+build1-0ubuntu0.24.04.1~mt1) noble; urgency=medium
 .
   * New upstream release (155.0+build1)
 .


firefox Sep 2nd 03:08
This package belongs to a PPA: Mozilla ESR
Release: jammy Repo: main Level: base New version: 155.0+build1-0ubuntu0.22.04.1~mt1
Packages in group:  firefox-dbg firefox-dev firefox-geckodriver firefox-locale-af firefox-locale-an firefox-locale-ar firefox-locale-as firefox-locale-ast firefox-locale-az firefox-locale-be firefox-locale-bg (... see all)

 firefox (155.0+build1-0ubuntu0.22.04.1~mt1) jammy; urgency=medium
 .
   * New upstream release (155.0+build1)
 .


network-manager Sep 2nd 02:07
Release: jammy Repo: universe Level: updates New version: 1.36.6-0ubuntu2.5
Packages in group:  network-manager-config-connectivity-debian

network-manager (1.36.6-0ubuntu2.5) jammy; urgency=medium

  * Backport Connectivity-check.ubuntu.com URI fix LP: #2148643
    - Adding a dot works to reduce the number of DNS requests, but has a side
      effect of breaking captive portals and transparent proxies/firewalls.
      the same URI is passed as get parameter.
      The risk of having the DNS flooding is mitigated by a systemd fix, so the
      side effect remains to have 2 DNS queries instead of one

 -- Gianfranco Costamagna Thu, 18 Jun 2026 11:33:21 +0200

2148643 [SRU] connectivity-check.ubuntu.com URL change?

network-manager Sep 2nd 02:07
Release: jammy Repo: main Level: updates New version: 1.36.6-0ubuntu2.5
Packages in group:  gir1.2-nm-1.0 libnm0 libnm-dev network-manager-config-connectivity-ubuntu network-manager-dev

network-manager (1.36.6-0ubuntu2.5) jammy; urgency=medium

  * Backport Connectivity-check.ubuntu.com URI fix LP: #2148643
    - Adding a dot works to reduce the number of DNS requests, but has a side
      effect of breaking captive portals and transparent proxies/firewalls.
      the same URI is passed as get parameter.
      The risk of having the DNS flooding is mitigated by a systemd fix, so the
      side effect remains to have 2 DNS queries instead of one

 -- Gianfranco Costamagna Thu, 18 Jun 2026 11:33:21 +0200

2148643 [SRU] connectivity-check.ubuntu.com URL change?

thunderbird Sep 1st 23:08
This package belongs to a PPA: Mozilla ESR
Release: noble Repo: main Level: base New version: 1:140.15.0+build1-0ubuntu0.24.04.1~mt1
Packages in group:  thunderbird-dbg thunderbird-dev thunderbird-gnome-support thunderbird-gnome-support-dbg thunderbird-locale-af thunderbird-locale-ar thunderbird-locale-ast thunderbird-locale-be thunderbird-locale-bg thunderbird-locale-bn thunderbird-locale-bn-bd (... see all)

 thunderbird (1:140.15.0+build1-0ubuntu0.24.04.1~mt1) noble; urgency=medium
 .
   * New upstream stable release (THUNDERBIRD_140_15_0esr_BUILD1)


thunderbird Sep 1st 23:08
This package belongs to a PPA: Mozilla ESR
Release: jammy Repo: main Level: base New version: 1:140.15.0+build1-0ubuntu0.22.04.1~mt1
Packages in group:  thunderbird-dbg thunderbird-dev thunderbird-gnome-support thunderbird-gnome-support-dbg thunderbird-locale-af thunderbird-locale-ar thunderbird-locale-ast thunderbird-locale-be thunderbird-locale-bg thunderbird-locale-bn thunderbird-locale-bn-bd (... see all)

 thunderbird (1:140.15.0+build1-0ubuntu0.22.04.1~mt1) jammy; urgency=medium
 .
   * New upstream stable release (THUNDERBIRD_140_15_0esr_BUILD1)


firefox-esr Sep 1st 23:08
This package belongs to a PPA: Mozilla ESR
Release: jammy Repo: main Level: base New version: 140.15.0esr+build1-0ubuntu0.22.04.1~mt1
Packages in group:  firefox-esr-dbg firefox-esr-dev firefox-esr-geckodriver firefox-esr-locale-af firefox-esr-locale-an firefox-esr-locale-ar firefox-esr-locale-as firefox-esr-locale-ast firefox-esr-locale-az firefox-esr-locale-be firefox-esr-locale-bg (... see all)

 firefox-esr (140.15.0esr+build1-0ubuntu0.22.04.1~mt1) jammy; urgency=medium
 .
   * New upstream stable release (FIREFOX_140_15_0esr_BUILD1)


firefox-esr Sep 1st 21:08
This package belongs to a PPA: Mozilla ESR
Release: noble Repo: main Level: base New version: 140.15.0esr+build1-0ubuntu0.24.04.1~mt1
Packages in group:  firefox-esr-dbg firefox-esr-dev firefox-esr-geckodriver firefox-esr-locale-af firefox-esr-locale-an firefox-esr-locale-ar firefox-esr-locale-as firefox-esr-locale-ast firefox-esr-locale-az firefox-esr-locale-be firefox-esr-locale-bg (... see all)

 firefox-esr (140.15.0esr+build1-0ubuntu0.24.04.1~mt1) noble; urgency=medium
 .
   * New upstream stable release (FIREFOX_140_15_0esr_BUILD1)


libgcrypt20 Sep 1st 19:07
Release: resolute Repo: universe Level: updates New version: 1.12.0-2ubuntu1.1
Packages in group:  libgcrypt-bin libgcrypt-mingw-w64-dev

libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.h,
      tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty

pyasn1 Sep 1st 19:07
Release: resolute Repo: main Level: updates New version: 0.6.3-1ubuntu0.1
Packages in group:  python3-pyasn1 python-pyasn1-doc

pyasn1 (0.6.3-1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
    unbounded long-form tag IDs
    - debian/patches/CVE-2026-59886.patch: Merge commit from fork in
      pyasn1/type/univ.py, tests/codec/ber/test_decoder.py,
      tests/codec/cer/test_decoder.py, tests/codec/der/test_decoder.py,
      tests/type/test_univ.py.
    - CVE-2026-59886
  * SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER and
    RELATIVE-OID processing allows denial of service
    - debian/patches/CVE-2026-59884.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/type/tag.py,
      tests/codec/ber/test_decoder.py, tests/codec/cer/test_decoder.py,
      tests/codec/der/test_decoder.py, tests/type/test_tag.py.
    - CVE-2026-59884
  * SECURITY UPDATE: Uncontrolled resource consumption when converting
    decoded REAL values
    - debian/patches/CVE-2026-59885.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/codec/ber/encoder.py,
      tests/codec/ber/test_decoder.py, tests/codec/ber/test_encoder.py.
    - CVE-2026-59885

 -- Marc Deslauriers Thu, 20 Aug 2026 13:20:40 -0400

CVE-2026-59886 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u
CVE-2026-59884 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating
CVE-2026-59885 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua

pam Sep 1st 19:07
Release: resolute Repo: main Level: updates New version: 1.7.0-5ubuntu3.2
Packages in group:  libpam0g libpam0g-dev libpam-doc libpam-modules libpam-modules-bin libpam-runtime

pam (1.7.0-5ubuntu3.2) resolute-security; urgency=medium

  * SECURITY UPDATE: account lockout bypass in pam_faillock account
    management phase (LP: #2164901)
    - debian/patches/lp-2164901.patch: skip clearing user's failed
      attempt in modules/pam_faillock/pam_faillock.8.xml,
      modules/pam_faillock/pam_faillock.c.
    - No CVE number

 -- Shafayat Hossain Majumder Wed, 26 Aug 2026 15:28:39 -0400

2164901 pam_faillock lockout silently defeated by cron/systemd-user account-phase calls - Ubuntu pam 1.7.0-5ubuntu3.1 predates upstream fix

libgcrypt20 Sep 1st 19:07
Release: resolute Repo: main Level: updates New version: 1.12.0-2ubuntu1.1
Packages in group:  libgcrypt20-dev libgcrypt20-doc

libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.h,
      tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty

libgcrypt20 Sep 1st 19:07
Release: noble Repo: universe Level: updates New version: 1.10.3-2ubuntu0.2
Packages in group:  libgcrypt-mingw-w64-dev

libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.c,
      src/const-time.h, tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty



About   -   Send Feedback to @ubuntu_updates