Latest Changelogs for all releases
Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).
| coreutils | Aug 31st 15:08 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 9.7-3ubuntu2.1 |
| Packages in group: | gnu-coreutils | ||
|
coreutils (9.7-3ubuntu2.1) resolute-security; urgency=medium * SECURITY UPDATE: out-of-bounds read in sort
-- Marc Deslauriers Tue, 25 Aug 2026 11:07:27 -0400 |
|||
| CVE-2025-5278 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory ou | ||
| CVE-2026-56391 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. Th | ||
| freerdp3 | Aug 31st 15:08 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: updates | New version: 3.31.0+ |
| Packages in group: | freerdp3-dev libfreerdp3-3 libfreerdp-client3-3 libfreerdp-server3-3 libfreerdp-server-proxy3-3 libfreerdp-shadow3-3 libfreerdp-shadow-subsystem3-3 libwinpr3-3 libwinpr3-dev libwinpr-tools3-3 winpr-utils (... see all) | ||
|
freerdp3 (3.31.0+dfsg-0ubuntu0.26.04.1) resolute-security; urgency=medium * SECURITY UPDATE: Updated to upstream 3.31.0 to fix multiple security
-- Marc Deslauriers Thu, 27 Aug 2026 12:56:28 -0400 |
|||
| 2165413 | freerdp3 3.31.0 security update tracking bug | ||
| zfs-linux | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: security | New version: 2.4.1-1ubuntu5.1 |
| Packages in group: | libnvpair3linux libuutil3linux libzfs7linux libzfsbootenv1linux libzfslinux-dev libzpool7linux python3-pyzfs pyzfs-doc zfs-dracut zfsutils-linux zfs-zed (... see all) | ||
|
zfs-linux (2.4.1-1ubuntu5.1) resolute-security; urgency=medium * Fixes for unprivileged user access to pool operations (LP: #2164774)
-- John Cabaj Fri, 21 Aug 2026 12:55:11 -0500 |
|||
| 2164774 | OpenZFS Linux open zpool manipulation and escapes via unprivileged userns | ||
| cpio | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: resolute | Repo: main | Level: security | New version: 2.15+dfsg-2.1ubuntu0.1 |
| Packages in group: | |||
|
cpio (2.15+dfsg-2.1ubuntu0.1) resolute-security; urgency=medium * SECURITY UPDATE: Unbounded stack allocation
-- Isabel Garcia Contreras Mon, 17 Aug 2026 16:31:23 -0400 |
|||
| CVE-2026-66485 | GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack m | ||
| CVE-2026-66484 | GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the | ||
| CVE-2026-66486 | GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio | ||
| CVE-2019-14866 | In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro | ||
| mysql-8.0 | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: updates | New version: 8.0.46-0ubuntu0.24.04.4 |
| Packages in group: | mysql-router mysql-source-8.0 mysql-testsuite mysql-testsuite-8.0 | ||
|
mysql-8.0 (8.0.46-0ubuntu0.24.04.4) noble-security; urgency=medium * SECURITY UPDATE: July 2026 security issues
-- Marc Deslauriers Wed, 26 Aug 2026 08:41:48 -0400 |
|||
| CVE-2026-46936 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Se | ||
| CVE-2026-47012 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My | ||
| CVE-2026-47023 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are | ||
| CVE-2026-47052 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server: | ||
| CVE-2026-47064 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My | ||
| More... | |||
| zlib | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: updates | New version: 1:1.3.dfsg-3.1ubuntu2.2 |
| Packages in group: | libminizip1t64 libminizip-dev minizip | ||
|
zlib (1:1.3.dfsg-3.1ubuntu2.2) noble-security; urgency=medium * SECURITY UPDATE: resource consumption via infinite loop
-- Chrisa Oikonomou Tue, 25 Aug 2026 13:41:30 +0300 |
|||
| CVE-2026-27171 | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no te | ||
| freerdp3 | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: updates | New version: 3.31.0+ |
| Packages in group: | freerdp3-dev freerdp3-shadow-x11 freerdp3-wayland freerdp3-x11 libfreerdp-shadow3-3 libfreerdp-shadow-subsystem3-3 winpr3-utils | ||
|
freerdp3 (3.31.0+dfsg-0ubuntu0.24.04.1) noble-security; urgency=medium * SECURITY UPDATE: Updated to upstream 3.31.0 to fix multiple security
-- Marc Deslauriers Thu, 27 Aug 2026 12:56:28 -0400 |
|||
| 2165413 | freerdp3 3.31.0 security update tracking bug | ||
| zfs-linux | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: security | New version: 2.2.2-0ubuntu9.5 |
| Packages in group: | libpam-zfs zfs-dkms zfs-dracut zfs-test | ||
|
zfs-linux (2.2.2-0ubuntu9.5) noble-security; urgency=medium * Fixes for unprivileged user access to pool operations (LP: #2164774)
-- John Cabaj Fri, 21 Aug 2026 13:28:46 -0500 |
|||
| 2164774 | OpenZFS Linux open zpool manipulation and escapes via unprivileged userns | ||
| libssh | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 0.10.6-2ubuntu0.5 |
| Packages in group: | libssh-4 libssh-dev libssh-doc libssh-gcrypt-4 libssh-gcrypt-dev | ||
|
libssh (0.10.6-2ubuntu0.5) noble-security; urgency=medium * SECURITY UPDATE: Denial of service via zero advertised channel packet size
-- Marc Deslauriers Mon, 24 Aug 2026 10:59:34 -0400 |
|||
| CVE-2026-59843 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write | ||
| CVE-2026-59845 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b | ||
| CVE-2026-59846 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment v | ||
| CVE-2026-59847 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al | ||
| CVE-2026-59848 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing | ||
| More... | |||
| mysql-8.0 | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 8.0.46-0ubuntu0.24.04.4 |
| Packages in group: | libmysqlclient21 libmysqlclient-dev mysql-client mysql-client-8.0 mysql-client-core-8.0 mysql-server mysql-server-8.0 mysql-server-core-8.0 | ||
|
mysql-8.0 (8.0.46-0ubuntu0.24.04.4) noble-security; urgency=medium * SECURITY UPDATE: July 2026 security issues
-- Marc Deslauriers Wed, 26 Aug 2026 08:41:48 -0400 |
|||
| CVE-2026-46936 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Se | ||
| CVE-2026-47012 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My | ||
| CVE-2026-47023 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are | ||
| CVE-2026-47052 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server: | ||
| CVE-2026-47064 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My | ||
| More... | |||
| freerdp3 | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 3.31.0+ |
| Packages in group: | libfreerdp3-3 libfreerdp-client3-3 libfreerdp-server3-3 libwinpr3-3 libwinpr3-dev libwinpr-tools3-3 | ||
|
freerdp3 (3.31.0+dfsg-0ubuntu0.24.04.1) noble-security; urgency=medium * SECURITY UPDATE: Updated to upstream 3.31.0 to fix multiple security
-- Marc Deslauriers Thu, 27 Aug 2026 12:56:28 -0400 |
|||
| 2165413 | freerdp3 3.31.0 security update tracking bug | ||
| zlib | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 1:1.3.dfsg-3.1ubuntu2.2 |
| Packages in group: | lib32z1 lib32z1-dev libx32z1 libx32z1-dev zlib1g zlib1g-dev | ||
|
zlib (1:1.3.dfsg-3.1ubuntu2.2) noble-security; urgency=medium * SECURITY UPDATE: resource consumption via infinite loop
-- Chrisa Oikonomou Tue, 25 Aug 2026 13:41:30 +0300 |
|||
| CVE-2026-27171 | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no te | ||
| coreutils | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 9.4-3ubuntu6.3 |
| Packages in group: | |||
|
coreutils (9.4-3ubuntu6.3) noble-security; urgency=medium * SECURITY UPDATE: out-of-bounds read in sort
-- Marc Deslauriers Tue, 25 Aug 2026 11:09:03 -0400 |
|||
| CVE-2025-5278 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory ou | ||
| zfs-linux | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 2.2.2-0ubuntu9.5 |
| Packages in group: | libnvpair3linux libuutil3linux libzfs4linux libzfsbootenv1linux libzfslinux-dev libzpool5linux python3-pyzfs pyzfs-doc zfs-initramfs zfsutils-linux zfs-zed (... see all) | ||
|
zfs-linux (2.2.2-0ubuntu9.5) noble-security; urgency=medium * Fixes for unprivileged user access to pool operations (LP: #2164774)
-- John Cabaj Fri, 21 Aug 2026 13:28:46 -0500 |
|||
| 2164774 | OpenZFS Linux open zpool manipulation and escapes via unprivileged userns | ||
| cpio | Aug 31st 15:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 2.15+dfsg-1ubuntu2.1 |
| Packages in group: | |||
|
cpio (2.15+dfsg-1ubuntu2.1) noble-security; urgency=medium * SECURITY UPDATE: Unbounded stack allocation
-- Isabel Garcia Contreras Tue, 18 Aug 2026 14:18:51 -0400 |
|||
| CVE-2026-66485 | GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack m | ||
| CVE-2026-66484 | GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the | ||
| CVE-2026-66486 | GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio | ||
| CVE-2019-14866 | In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro | ||