Latest Changelogs for all releases
Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).
| webkit2gtk | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: universe | Level: security | New version: 2.52.6-0ubuntu0.24.04.1 |
| Packages in group: | libjavascriptcoregtk-4.0-bin libjavascriptcoregtk-4.1-dev libjavascriptcoregtk-6.0-dev libjavascriptcoregtk-bin libwebkit2gtk-4.1-dev libwebkitgtk-6.0-dev webkit2gtk-driver | ||
|
webkit2gtk (2.52.6-0ubuntu0.24.04.1) noble-security; urgency=medium * Update to 2.52.6 to fix security issues.
-- Marc Deslauriers Fri, 21 Aug 2026 13:04:27 -0400 |
|||
| CVE-2026-28847 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma | ||
| CVE-2026-28883 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, | ||
| CVE-2026-28901 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis | ||
| CVE-2026-28902 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis | ||
| CVE-2026-28903 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma | ||
| More... | |||
| linux-firmware | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: proposed | New version: 20240318.git3b128b60.0ubuntu3.1 |
| Packages in group: | linux-firmware-minimal | ||
|
linux-firmware (20240318.git3b128b60.0ubuntu3.1) noble; urgency=medium * Split linux-firmware into multiple packages (LP: #1958518)
-- Juerg Haefliger Tue, 14 Jul 2026 10:24:24 +0200 |
|||
| diffutils | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 1:3.10-1ubuntu0.1 |
| Packages in group: | diffutils-doc | ||
|
diffutils (1:3.10-1ubuntu0.1) noble-security; urgency=medium * SECURITY UPDATE: Integer Overflow
-- John Breton Wed, 26 Aug 2026 14:15:46 -0400 |
|||
| CVE-2026-53910 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In | ||
| bind9 | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 1:9.18.39- |
| Packages in group: | bind9-dev bind9-dnsutils bind9-doc bind9-host bind9-libs bind9-utils | ||
|
bind9 (1:9.18.39-0ubuntu0.24.04.7) noble-security; urgency=medium * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3
-- Marc Deslauriers Thu, 27 Aug 2026 10:10:14 -0400 |
|||
| CVE-2026-13204 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B | ||
| attr | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: updates | New version: 1:2.5.2-1ubuntu0.1 |
| Packages in group: | libattr1 libattr1-dev | ||
|
attr (1:2.5.2-1ubuntu0.1) noble-security; urgency=medium * SECURITY UPDATE: Symlink Traversal
-- John Breton Sun, 23 Aug 2026 21:39:46 -0400 (See more...) |
|||
| CVE-2026-54371 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p | ||
| webkit2gtk | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 2.52.6-0ubuntu0.24.04.1 |
| Packages in group: | gir1.2-javascriptcoregtk-4.1 gir1.2-javascriptcoregtk-6.0 gir1.2-webkit2-4.1 gir1.2-webkit-6.0 libjavascriptcoregtk-4.1-0 libjavascriptcoregtk-6.0-1 libwebkit2gtk-4.0-doc libwebkit2gtk-4.1-0 libwebkitgtk-6.0-4 libwebkitgtk-doc | ||
|
webkit2gtk (2.52.6-0ubuntu0.24.04.1) noble-security; urgency=medium * Update to 2.52.6 to fix security issues.
-- Marc Deslauriers Fri, 21 Aug 2026 13:04:27 -0400 |
|||
| CVE-2026-28847 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma | ||
| CVE-2026-28883 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, | ||
| CVE-2026-28901 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis | ||
| CVE-2026-28902 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis | ||
| CVE-2026-28903 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma | ||
| More... | |||
| util-linux | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 2.39.3-9ubuntu6.6 |
| Packages in group: | bsdextrautils bsdutils eject fdisk libblkid1 libblkid-dev libfdisk1 libfdisk-dev libmount1 libmount-dev libsmartcols1 (... see all) | ||
|
util-linux (2.39.3-9ubuntu6.6) noble-security; urgency=medium * SECURITY UPDATE: Heap use-after-free via crafted block device image
-- Marc Deslauriers Wed, 19 Aug 2026 12:47:51 -0400 |
|||
| CVE-2026-13595 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers | ||
| CVE-2026-27456 | util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified | ||
| CVE-2026-53612 | Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown | ||
| CVE-2026-53613 | Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection | ||
| CVE-2026-53614 | Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) | ||
| More... | |||
| udisks2 | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: noble | Repo: main | Level: security | New version: 2.10.1-6ubuntu1.5 |
| Packages in group: | gir1.2-udisks-2.0 libudisks2-0 libudisks2-dev udisks2-doc | ||
|
udisks2 (2.10.1-6ubuntu1.5) noble-security; urgency=medium * SECURITY UPDATE: Privilege escalation via mount point injection
-- Marc Deslauriers Mon, 17 Aug 2026 10:49:58 -0400 |
|||
| CVE-2026-7867 | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option | ||
| bind9 | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: updates | New version: 1:9.18.39- |
| Packages in group: | bind9utils dnsutils | ||
|
bind9 (1:9.18.39-0ubuntu0.22.04.6) jammy-security; urgency=medium * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3
-- Marc Deslauriers Thu, 27 Aug 2026 10:11:12 -0400 |
|||
| CVE-2026-13204 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B | ||
| bind-dyndb-ldap | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: jammy | Repo: universe | Level: updates | New version: 11.9-5ubuntu0.22.04.17 |
| Packages in group: | bind9-dyndb-ldap | ||
|
bind-dyndb-ldap (11.9-5ubuntu0.22.04.17) jammy-security; urgency=medium * No change rebuild with bind9-libs 1:9.18.39-0ubuntu0.22.04.6 -- Marc Deslauriers Thu, 27 Aug 2026 11:24:02 -0400 |
|||
| diffutils | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 1:3.8-0ubuntu2.1 |
| Packages in group: | diffutils-doc | ||
|
diffutils (1:3.8-0ubuntu2.1) jammy-security; urgency=medium * SECURITY UPDATE: Integer Overflow
-- John Breton Wed, 26 Aug 2026 14:17:15 -0400 |
|||
| CVE-2026-53910 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In | ||
| attr | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 1:2.5.1-1ubuntu0.1 |
| Packages in group: | libattr1 libattr1-dev | ||
|
attr (1:2.5.1-1ubuntu0.1) jammy-security; urgency=medium * SECURITY UPDATE: Symlink Traversal
-- John Breton Sun, 23 Aug 2026 21:42:23 -0400 (See more...) |
|||
| CVE-2026-54371 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p | ||
| bind9 | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: updates | New version: 1:9.18.39- |
| Packages in group: | bind9-dev bind9-dnsutils bind9-doc bind9-host bind9-libs bind9-utils | ||
|
bind9 (1:9.18.39-0ubuntu0.22.04.6) jammy-security; urgency=medium * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3
-- Marc Deslauriers Thu, 27 Aug 2026 10:11:12 -0400 |
|||
| CVE-2026-13204 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B | ||
| util-linux | Aug 31st 14:07 | ||
|---|---|---|---|
| Release: jammy | Repo: main | Level: security | New version: 2.37.2-4ubuntu3.6 |
| Packages in group: | bsdextrautils bsdutils eject fdisk libblkid1 libblkid-dev libfdisk1 libfdisk-dev libmount1 libmount-dev libsmartcols1 (... see all) | ||
|
util-linux (2.37.2-4ubuntu3.6) jammy-security; urgency=medium * SECURITY UPDATE: Heap use-after-free via crafted block device image
-- Marc Deslauriers Wed, 19 Aug 2026 13:43:12 -0400 |
|||
| CVE-2026-13595 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers | ||
| CVE-2026-27456 | util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified | ||
| CVE-2026-53613 | Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection | ||
| CVE-2026-53615 | Integer Overflow or Wraparound in libblkid/src/partitions/dos.c | ||
| mysql-8.4 | Aug 31st 13:07 | ||
|---|---|---|---|
| Release: resolute | Repo: universe | Level: security | New version: 8.4.11-0ubuntu0.26.04.1 |
| Packages in group: | mysql-router mysql-source mysql-testsuite | ||
|
mysql-8.4 (8.4.11-0ubuntu0.26.04.1) resolute-security; urgency=medium * SECURITY UPDATE: Update to 8.4.11 to fix security issues
-- Marc Deslauriers Wed, 26 Aug 2026 08:40:36 -0400 |
|||
| CVE-2026-46936 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Se | ||
| CVE-2026-47012 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My | ||
| CVE-2026-47023 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are | ||
| CVE-2026-47052 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server: | ||
| CVE-2026-47064 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My | ||
| More... | |||