Latest Changelogs for all releases
Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).
| pyasn1 | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: security | New version: 0.6.3-1ubuntu0.1 |
| Packages in group: | python3-pyasn1 python-pyasn1-doc | ||
|
pyasn1 (0.6.3-1ubuntu0.1) resolute-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 13:20:40 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| libevent | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 2.1.12-stable-9ubuntu2.1 |
| Packages in group: | libevent-2.1-7t64 libevent-core-2.1-7t64 libevent-dev libevent-extra-2.1-7t64 libevent-openssl-2.1-7t64 libevent-pthreads-2.1-7t64 | ||
|
libevent (2.1.12-stable-9ubuntu2.1) noble-security; urgency=medium * SECURITY UPDATE: dangling pointer in buffer reference handling
-- Shafayat Hossain Majumder Fri, 28 Aug 2026 16:44:18 -0400 |
|||
| CVE-2026-63381 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere | ||
| CVE-2026-63382 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra | ||
| CVE-2026-63383 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c | ||
| CVE-2026-63384 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta | ||
| CVE-2026-63385 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int | ||
| ncurses | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 6.4+20240113-1ubuntu2.2 |
| Packages in group: | lib32ncurses6 lib32ncurses-dev lib32ncursesw6 lib32tinfo6 libncurses6 libncurses-dev libncursesw6 libtinfo6 ncurses-base ncurses-bin ncurses-doc (... see all) | ||
|
ncurses (6.4+20240113-1ubuntu2.2) noble-security; urgency=medium * SECURITY UPDATE: Stack-based buffer overflow
-- John Breton Mon, 31 Aug 2026 07:36:06 -0400 |
|||
| CVE-2025-6141 | A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_t | ||
| pyasn1 | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 0.4.8-4ubuntu0.3 |
| Packages in group: | python3-pyasn1 python-pyasn1-doc | ||
|
pyasn1 (0.4.8-4ubuntu0.3) noble-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 13:36:50 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| ncurses | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: updates | New version: 6.3-2ubuntu0.3 |
| Packages in group: | libncurses5 libncursesw5 libtinfo5 | ||
|
ncurses (6.3-2ubuntu0.3) jammy-security; urgency=medium * SECURITY UPDATE: Stack-based buffer overflow
-- John Breton Mon, 31 Aug 2026 07:36:57 -0400 |
|||
| CVE-2025-6141 | A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_t | ||
| pyasn1 | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: security | New version: 0.4.8-1ubuntu0.3 |
| Packages in group: | pypy-pyasn1 | ||
|
pyasn1 (0.4.8-1ubuntu0.3) jammy-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 18:00:34 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| libevent | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 2.1.12-stable-1ubuntu0.1 |
| Packages in group: | libevent-2.1-7 libevent-core-2.1-7 libevent-dev libevent-extra-2.1-7 libevent-openssl-2.1-7 libevent-pthreads-2.1-7 | ||
|
libevent (2.1.12-stable-1ubuntu0.1) jammy-security; urgency=medium * SECURITY UPDATE: dangling pointer in buffer reference handling
-- Shafayat Hossain Majumder Fri, 28 Aug 2026 16:44:15 -0400 |
|||
| CVE-2026-63381 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere | ||
| CVE-2026-63382 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra | ||
| CVE-2026-63383 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c | ||
| CVE-2026-63384 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta | ||
| CVE-2026-63385 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int | ||
| ncurses | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 6.3-2ubuntu0.3 |
| Packages in group: | lib32ncurses6 lib32ncurses-dev lib32ncursesw6 lib32tinfo6 libncurses5-dev libncurses6 libncurses-dev libncursesw5-dev libncursesw6 libtinfo6 libtinfo-dev (... see all) | ||
|
ncurses (6.3-2ubuntu0.3) jammy-security; urgency=medium * SECURITY UPDATE: Stack-based buffer overflow
-- John Breton Mon, 31 Aug 2026 07:36:57 -0400 |
|||
| CVE-2025-6141 | A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_t | ||
| pyasn1 | Sep 1st 18:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: security | New version: 0.4.8-1ubuntu0.3 |
| Packages in group: | python3-pyasn1 python-pyasn1-doc | ||
|
pyasn1 (0.4.8-1ubuntu0.3) jammy-security; urgency=medium * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
-- Marc Deslauriers Thu, 20 Aug 2026 18:00:34 -0400 |
|||
| CVE-2026-59886 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u | ||
| CVE-2026-59884 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating | ||
| CVE-2026-59885 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua | ||
| libgcrypt20 | Sep 1st 17:07 | ||
|---|---|---|---|
| Release: resolute | Repo: universe | Level: security | New version: 1.12.0-2ubuntu1.1 |
| Packages in group: | libgcrypt-bin libgcrypt-mingw-w64-dev | ||
|
libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| pam | Sep 1st 17:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: security | New version: 1.7.0-5ubuntu3.2 |
| Packages in group: | libpam0g libpam0g-dev libpam-doc libpam-modules libpam-modules-bin libpam-runtime | ||
|
pam (1.7.0-5ubuntu3.2) resolute-security; urgency=medium * SECURITY UPDATE: account lockout bypass in pam_faillock account
-- Shafayat Hossain Majumder Wed, 26 Aug 2026 15:28:39 -0400 |
|||
| 2164901 | pam_faillock lockout silently defeated by cron/systemd-user account-phase calls - Ubuntu pam 1.7.0-5ubuntu3.1 predates upstream fix | ||
| libgcrypt20 | Sep 1st 17:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: security | New version: 1.12.0-2ubuntu1.1 |
| Packages in group: | libgcrypt20-dev libgcrypt20-doc | ||
|
libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| libgcrypt20 | Sep 1st 17:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: security | New version: 1.10.3-2ubuntu0.2 |
| Packages in group: | libgcrypt-mingw-w64-dev | ||
|
libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| libgcrypt20 | Sep 1st 17:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 1.10.3-2ubuntu0.2 |
| Packages in group: | libgcrypt20-dev libgcrypt20-doc | ||
|
libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
-- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400 |
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||
| libgcrypt20 | Sep 1st 17:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: security | New version: 1.9.4-3ubuntu3.3 |
| Packages in group: | libgcrypt-mingw-w64-dev | ||
|
libgcrypt20 (1.9.4-3ubuntu3.3) jammy-security; urgency=medium * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
|
|||
| CVE-2024-2236 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty | ||