UbuntuUpdates.org

Latest Changelogs for all releases

All releases Jammy Noble Plucky Resolute
Include all PPAs Exclude daily builds PPAs Exclude all PPAs
Include levels: securityupdatesproposedbackportsbase

Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).

webkit2gtk Aug 31st 14:07
Release: noble Repo: universe Level: security New version: 2.52.6-0ubuntu0.24.04.1
Packages in group:  libjavascriptcoregtk-4.0-bin libjavascriptcoregtk-4.1-dev libjavascriptcoregtk-6.0-dev libjavascriptcoregtk-bin libwebkit2gtk-4.1-dev libwebkitgtk-6.0-dev webkit2gtk-driver

webkit2gtk (2.52.6-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.52.6 to fix security issues.
    - CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902,
      CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907,
      CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953,
      CVE-2026-28955, CVE-2026-28958, CVE-2026-28984, CVE-2026-39872,
      CVE-2026-43658, CVE-2026-43660, CVE-2026-43663, CVE-2026-43676,
      CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707,
      CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716,
      CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726,
      CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734,
      CVE-2026-43740, CVE-2026-43742, CVE-2026-43745, CVE-2026-43804,
      CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730,
      CVE-2026-64757, CVE-2026-64783, CVE-2026-64787
  * Remove patches included in new version:
    - debian/patches/fix-atomics-detection.patch
    - debian/patches/fix-big-endian-string.patch

 -- Marc Deslauriers Fri, 21 Aug 2026 13:04:27 -0400

CVE-2026-28847 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28883 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,
CVE-2026-28901 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28902 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28903 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
More...

linux-firmware Aug 31st 14:07
Release: noble Repo: main Level: proposed New version: 20240318.git3b128b60.0ubuntu3.1
Packages in group:  linux-firmware-minimal

linux-firmware (20240318.git3b128b60.0ubuntu3.1) noble; urgency=medium

  * Split linux-firmware into multiple packages (LP: #1958518)
    - First release of meta package for Noble

 -- Juerg Haefliger Tue, 14 Jul 2026 10:24:24 +0200


diffutils Aug 31st 14:07
Release: noble Repo: main Level: updates New version: 1:3.10-1ubuntu0.1
Packages in group:  diffutils-doc

diffutils (1:3.10-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Integer Overflow
    - debian/patches/CVE-2026-53910-1.patch: diff3: check for integer overflows
      when reading line numbers from diff in NEWS, THANKS, src/diff3.c.
    - debian/patches/CVE-2026-53910-2.patch: diff3: prevent overflow in line
      offsets in src/diff3.c.
    - CVE-2026-53910

 -- John Breton Wed, 26 Aug 2026 14:15:46 -0400

CVE-2026-53910 diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In

bind9 Aug 31st 14:07
Release: noble Repo: main Level: updates New version: 1:9.18.39-0ubuntu0.24.04.7
Packages in group:  bind9-dev bind9-dnsutils bind9-doc bind9-host bind9-libs bind9-utils

bind9 (1:9.18.39-0ubuntu0.24.04.7) noble-security; urgency=medium

  * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3
    both present
    - debian/patches/CVE-2026-13204-1.patch: dns_rdataset_addnoqname() could
      find unsigned NSEC/NSEC3 in lib/dns/rbtdb.c, lib/dns/rdatalist.c,
      lib/dns/resolver.c, lib/ns/query.c.
    - debian/patches/CVE-2026-13204-2.patch: Reproducer for #5985 addnoqname
      mismatch in
      bin/tests/system/repro_5985_findnoqname_runtime_check/ans1/ans.py,
      bin/tests/system/repro_5985_findnoqname_runtime_check/ns2/named.conf.j2,
      bin/tests/system/repro_5985_findnoqname_runtime_check/server.py, bin/tests
      /system/repro_5985_findnoqname_runtime_check/tests_repro_5985_findnoqname_
      runtime_check.py.
    - debian/patches/CVE-2026-13204-3.patch: Update reproducer #5985 in
      bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py,
      bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2, bin/tests/
      system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py.
    - CVE-2026-13204

 -- Marc Deslauriers Thu, 27 Aug 2026 10:10:14 -0400

CVE-2026-13204 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B

attr Aug 31st 14:07
Release: noble Repo: main Level: updates New version: 1:2.5.2-1ubuntu0.1
Packages in group:  libattr1 libattr1-dev

attr (1:2.5.2-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Symlink Traversal
    - d/p/CVE-2026-54371-01-add-visibility-attribute-header.patch: Add
      visibility attribute header in include/Makemodule.am, include/visibility-
      hidden.h.
    - d/p/CVE-2026-54371-02-add-xattrat-syscall-wrappers.patch: Add xattrat
      syscall wrappers in configure.ac, include/Makemodule.am,
      include/xattrat.h, libmisc/Makemodule.am, libmisc/xattrat.c.
    - d/p/CVE-2026-54371-03-add-xattrat-syscall-backwards-compatibility-
      code.patch: Add xattrat syscall backwards compatibility code in
      include/Makemodule.am, include/xattrat_compat.h, libmisc/Makemodule.am,
      libmisc/getxattrat_compat.c, libmisc/listxattrat_compat.c, libmisc/proc-
      self-fd.c, libmisc/proc-self-fd.h, libmisc/removexattrat_compat.c,
      libmisc/setxattrat_compat.c.
    - d/p/CVE-2026-54371-04-rename-walk_tree-to-old_walk_tree.patch: Rename
      walk_tree to old_walk_tree in include/Makemodule.am,
      include/old_walk_tree.h, libmisc/Makemodule.am, libmisc/old_walk_tree.c,
      tools/getfattr.c.
    - d/p/CVE-2026-54371-05-add-the-new-walk_tree-helper.patch: Add the new
      walk_tree helper in include/Makemodule.am, include/walk_tree.h,
      libmisc/Makemodule.am, libmisc/walk_tree.c.
    - debian/patches/CVE-2026-54371-06-harden-getfattr.patch: harden getfattr in
      man/man1/getfattr.1, tools/getfattr.c, test/root/getfattr.test.
    - d/p/CVE-2026-54371-07-setfattr-multiple-restore-accesses-freed-
      buffer.patch: setfattr: multiple --restore accesses freed buffer in
      tools/setfattr.c.
    - d/p/CVE-2026-54371-08-setfattr-do-not-ignore-no-dereference-after-
      restore.patch: setfattr: Do not ignore --no-dereference after --restore in
      tools/setfattr.c.
    - d/p/CVE-2026-54371-09-add-openat2-syscall-wrapper.patch: Add openat2
      syscall wrapper in configure.ac, include/Makemodule.am, include/openat2.h,
      libmisc/Makemodule.am, libmisc/openat2.c.
    - debian/patches/CVE-2026-54371-10-harden-setfattr-restore.patch: harden
      setfattr --restore in configure.ac, man/man1/setfattr.1,
      test/Makemodule.am, tools/setfattr.c, test/restore.test.
    - CVE-2026-54371

 -- John Breton Sun, 23 Aug 2026 21:39:46 -0400

(See more...)
CVE-2026-54371 attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p

webkit2gtk Aug 31st 14:07
Release: noble Repo: main Level: security New version: 2.52.6-0ubuntu0.24.04.1
Packages in group:  gir1.2-javascriptcoregtk-4.1 gir1.2-javascriptcoregtk-6.0 gir1.2-webkit2-4.1 gir1.2-webkit-6.0 libjavascriptcoregtk-4.1-0 libjavascriptcoregtk-6.0-1 libwebkit2gtk-4.0-doc libwebkit2gtk-4.1-0 libwebkitgtk-6.0-4 libwebkitgtk-doc

webkit2gtk (2.52.6-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.52.6 to fix security issues.
    - CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902,
      CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907,
      CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953,
      CVE-2026-28955, CVE-2026-28958, CVE-2026-28984, CVE-2026-39872,
      CVE-2026-43658, CVE-2026-43660, CVE-2026-43663, CVE-2026-43676,
      CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707,
      CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716,
      CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726,
      CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734,
      CVE-2026-43740, CVE-2026-43742, CVE-2026-43745, CVE-2026-43804,
      CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730,
      CVE-2026-64757, CVE-2026-64783, CVE-2026-64787
  * Remove patches included in new version:
    - debian/patches/fix-atomics-detection.patch
    - debian/patches/fix-big-endian-string.patch

 -- Marc Deslauriers Fri, 21 Aug 2026 13:04:27 -0400

CVE-2026-28847 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28883 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,
CVE-2026-28901 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28902 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28903 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
More...

util-linux Aug 31st 14:07
Release: noble Repo: main Level: security New version: 2.39.3-9ubuntu6.6
Packages in group:  bsdextrautils bsdutils eject fdisk libblkid1 libblkid-dev libfdisk1 libfdisk-dev libmount1 libmount-dev libsmartcols1 (... see all)

util-linux (2.39.3-9ubuntu6.6) noble-security; urgency=medium

  * SECURITY UPDATE: Heap use-after-free via crafted block device image
    - debian/patches/CVE-2026-13595.patch: libblkid: fix use-after-free in
      nested partition probing in libblkid/src/partitions/partitions.c.
    - CVE-2026-13595
  * SECURITY UPDATE: TOCTOU in mount utility
    - debian/patches/CVE-2026-27456.patch: loopdev: add LOOPDEV_FL_NOFOLLOW to
      prevent symlink attacks in include/loopdev.h, lib/loopdev.c,
      libmount/src/hook_loopdev.c.
    - CVE-2026-27456
  * SECURITY UPDATE: Local Privilege Escalation via TOCTOU in mount
    - debian/patches/CVE-2026-53612.patch: libmount: use fd-based fchownat/chmod
      in hook_owner in libmount/src/hook_owner.c.
    - CVE-2026-53612
  * SECURITY UPDATE: Another local Privilege Escalation via TOCTOU in mount
    - debian/patches/CVE-2026-53613-pre1.patch: lib/fileutils: add
      ul_open_no_symlinks() in configure.ac, include/fileutils.h,
      lib/fileutils.c, meson.build.
    - debian/patches/CVE-2026-53613.patch: libmount: add fd_target to context
      for TOCTOU prevention in libmount/src/context.c,
      libmount/src/context_mount.c, libmount/src/hook_mount.c,
      libmount/src/hook_mount_legacy.c, libmount/src/mountP.h.
    - CVE-2026-53613
  * SECURITY UPDATE: Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2
    Environment Variable
    - debian/patches/CVE-2026-53614.patch: libmount: fix SUID bypass via
      LIBMOUNT_FORCE_MOUNT2 and legacy mount path in libmount/src/hook_mount.c,
      libmount/src/hook_mount_legacy.c.
    - CVE-2026-53614
  * SECURITY UPDATE: Integer Overflow or Wraparound in dos.c
    - debian/patches/CVE-2026-53615.patch: libblkid: dos: validate EBR data and
      links within extended partition in libblkid/src/partitions/dos.c.
    - CVE-2026-53615

 -- Marc Deslauriers Wed, 19 Aug 2026 12:47:51 -0400

CVE-2026-13595 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers
CVE-2026-27456 util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified
CVE-2026-53612 Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown
CVE-2026-53613 Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection
CVE-2026-53614 Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8)
More...

udisks2 Aug 31st 14:07
Release: noble Repo: main Level: security New version: 2.10.1-6ubuntu1.5
Packages in group:  gir1.2-udisks-2.0 libudisks2-0 libudisks2-dev udisks2-doc

udisks2 (2.10.1-6ubuntu1.5) noble-security; urgency=medium

  * SECURITY UPDATE: Privilege escalation via mount point injection
    - debian/patches/CVE-2026-7867-1.patch: udiskslinuxfilesystem: Separate real
      caller identity from as-user target in src/udiskslinuxfilesystem.c.
    - debian/patches/CVE-2026-7867-2.patch: udiskslinuxfilesystem: Rework fstab
      mount authorization for as-user in data/org.freedesktop.UDisks2.xml,
      src/udiskslinuxfilesystem.c.
    - debian/patches/CVE-2026-7867-3.patch: udiskslinuxfilesystem: Log real
      caller uid for as-user mounts in src/udiskslinuxfilesystem.c.
    - debian/patches/CVE-2026-7867-4.patch: udisksdaemonutil: Pass as-user
      target to polkit details in src/udisksdaemonutil.c.
    - debian/patches/CVE-2026-7867-5.patch: tests: Add security tests for as-
      user mount authorization in src/tests/dbus-tests/test_80_filesystem.py.
    - CVE-2026-7867

 -- Marc Deslauriers Mon, 17 Aug 2026 10:49:58 -0400

CVE-2026-7867 A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option

bind9 Aug 31st 14:07
Release: jammy Repo: universe Level: updates New version: 1:9.18.39-0ubuntu0.22.04.6
Packages in group:  bind9utils dnsutils

bind9 (1:9.18.39-0ubuntu0.22.04.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3
    both present
    - debian/patches/CVE-2026-13204-1.patch: dns_rdataset_addnoqname() could
      find unsigned NSEC/NSEC3 in lib/dns/rbtdb.c, lib/dns/rdatalist.c,
      lib/dns/resolver.c, lib/ns/query.c.
    - debian/patches/CVE-2026-13204-2.patch: Reproducer for #5985 addnoqname
      mismatch in
      bin/tests/system/repro_5985_findnoqname_runtime_check/ans1/ans.py,
      bin/tests/system/repro_5985_findnoqname_runtime_check/ns2/named.conf.j2,
      bin/tests/system/repro_5985_findnoqname_runtime_check/server.py, bin/tests
      /system/repro_5985_findnoqname_runtime_check/tests_repro_5985_findnoqname_
      runtime_check.py.
    - debian/patches/CVE-2026-13204-3.patch: Update reproducer #5985 in
      bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py,
      bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2, bin/tests/
      system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py.
    - CVE-2026-13204

 -- Marc Deslauriers Thu, 27 Aug 2026 10:11:12 -0400

CVE-2026-13204 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B

bind-dyndb-ldap Aug 31st 14:07
Release: jammy Repo: universe Level: updates New version: 11.9-5ubuntu0.22.04.17
Packages in group:  bind9-dyndb-ldap

bind-dyndb-ldap (11.9-5ubuntu0.22.04.17) jammy-security; urgency=medium

  * No change rebuild with bind9-libs 1:9.18.39-0ubuntu0.22.04.6

 -- Marc Deslauriers Thu, 27 Aug 2026 11:24:02 -0400


diffutils Aug 31st 14:07
Release: jammy Repo: main Level: updates New version: 1:3.8-0ubuntu2.1
Packages in group:  diffutils-doc

diffutils (1:3.8-0ubuntu2.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Integer Overflow
    - debian/patches/CVE-2026-53910-1.patch: diff3: check for integer overflows
      when reading line numbers from diff in NEWS, THANKS, src/diff3.c.
    - debian/patches/CVE-2026-53910-2.patch: diff3: prevent overflow in line
      offsets in src/diff3.c.
    - CVE-2026-53910

 -- John Breton Wed, 26 Aug 2026 14:17:15 -0400

CVE-2026-53910 diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In

attr Aug 31st 14:07
Release: jammy Repo: main Level: updates New version: 1:2.5.1-1ubuntu0.1
Packages in group:  libattr1 libattr1-dev

attr (1:2.5.1-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Symlink Traversal
    - d/p/CVE-2026-54371-01-add-visibility-attribute-header.patch: Add
      visibility attribute header in include/Makemodule.am, include/visibility-
      hidden.h.
    - d/p/CVE-2026-54371-02-add-xattrat-syscall-wrappers.patch: Add xattrat
      syscall wrappers in configure.ac, include/Makemodule.am,
      include/xattrat.h, libmisc/Makemodule.am, libmisc/xattrat.c.
    - d/p/CVE-2026-54371-03-add-xattrat-syscall-backwards-compatibility-
      code.patch: Add xattrat syscall backwards compatibility code in
      include/Makemodule.am, include/xattrat_compat.h, libmisc/Makemodule.am,
      libmisc/getxattrat_compat.c, libmisc/listxattrat_compat.c, libmisc/proc-
      self-fd.c, libmisc/proc-self-fd.h, libmisc/removexattrat_compat.c,
      libmisc/setxattrat_compat.c.
    - d/p/CVE-2026-54371-04-rename-walk_tree-to-old_walk_tree.patch: Rename
      walk_tree to old_walk_tree in include/Makemodule.am,
      include/old_walk_tree.h, libmisc/Makemodule.am, libmisc/old_walk_tree.c,
      tools/getfattr.c.
    - d/p/CVE-2026-54371-05-add-the-new-walk_tree-helper.patch: Add the new
      walk_tree helper in include/Makemodule.am, include/walk_tree.h,
      libmisc/Makemodule.am, libmisc/walk_tree.c.
    - debian/patches/CVE-2026-54371-06-harden-getfattr.patch: harden getfattr in
      man/man1/getfattr.1, tools/getfattr.c, test/root/getfattr.test.
    - d/p/CVE-2026-54371-07-setfattr-multiple-restore-accesses-freed-
      buffer.patch: setfattr: multiple --restore accesses freed buffer in
      tools/setfattr.c.
    - d/p/CVE-2026-54371-08-setfattr-do-not-ignore-no-dereference-after-
      restore.patch: setfattr: Do not ignore --no-dereference after --restore in
      tools/setfattr.c.
    - d/p/CVE-2026-54371-09-add-openat2-syscall-wrapper.patch: Add openat2
      syscall wrapper in configure.ac, include/Makemodule.am, include/openat2.h,
      libmisc/Makemodule.am, libmisc/openat2.c.
    - debian/patches/CVE-2026-54371-10-harden-setfattr-restore.patch: harden
      setfattr --restore in configure.ac, man/man1/setfattr.1,
      test/Makemodule.am, tools/setfattr.c, test/restore.test.
    - CVE-2026-54371

 -- John Breton Sun, 23 Aug 2026 21:42:23 -0400

(See more...)
CVE-2026-54371 attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p

bind9 Aug 31st 14:07
Release: jammy Repo: main Level: updates New version: 1:9.18.39-0ubuntu0.22.04.6
Packages in group:  bind9-dev bind9-dnsutils bind9-doc bind9-host bind9-libs bind9-utils

bind9 (1:9.18.39-0ubuntu0.22.04.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3
    both present
    - debian/patches/CVE-2026-13204-1.patch: dns_rdataset_addnoqname() could
      find unsigned NSEC/NSEC3 in lib/dns/rbtdb.c, lib/dns/rdatalist.c,
      lib/dns/resolver.c, lib/ns/query.c.
    - debian/patches/CVE-2026-13204-2.patch: Reproducer for #5985 addnoqname
      mismatch in
      bin/tests/system/repro_5985_findnoqname_runtime_check/ans1/ans.py,
      bin/tests/system/repro_5985_findnoqname_runtime_check/ns2/named.conf.j2,
      bin/tests/system/repro_5985_findnoqname_runtime_check/server.py, bin/tests
      /system/repro_5985_findnoqname_runtime_check/tests_repro_5985_findnoqname_
      runtime_check.py.
    - debian/patches/CVE-2026-13204-3.patch: Update reproducer #5985 in
      bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py,
      bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2, bin/tests/
      system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py.
    - CVE-2026-13204

 -- Marc Deslauriers Thu, 27 Aug 2026 10:11:12 -0400

CVE-2026-13204 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B

util-linux Aug 31st 14:07
Release: jammy Repo: main Level: security New version: 2.37.2-4ubuntu3.6
Packages in group:  bsdextrautils bsdutils eject fdisk libblkid1 libblkid-dev libfdisk1 libfdisk-dev libmount1 libmount-dev libsmartcols1 (... see all)

util-linux (2.37.2-4ubuntu3.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Heap use-after-free via crafted block device image
    - debian/patches/CVE-2026-13595.patch: libblkid: fix use-after-free in
      nested partition probing in libblkid/src/partitions/partitions.c.
    - CVE-2026-13595
  * SECURITY UPDATE: TOCTOU in mount utility
    - debian/patches/CVE-2026-27456.patch: loopdev: add LOOPDEV_FL_NOFOLLOW to
      prevent symlink attacks in include/loopdev.h, lib/loopdev.c,
      libmount/src/context_loopdev.c.
    - CVE-2026-27456
  * SECURITY UPDATE: Another local Privilege Escalation via TOCTOU in mount
    - debian/patches/CVE-2026-53613-pre1.patch: lib/fileutils: add
      ul_open_no_symlinks() in include/fileutils.h, lib/fileutils.c.
    - debian/patches/CVE-2026-53613.patch: libmount: add fd_target to context
      for TOCTOU prevention in libmount/src/context.c,
      libmount/src/context_mount.c, libmount/src/mountP.h.
    - CVE-2026-53613
  * SECURITY UPDATE: Integer Overflow or Wraparound in dos.c
    - debian/patches/CVE-2026-53615.patch: libblkid: dos: validate EBR data and
      links within extended partition in libblkid/src/partitions/dos.c.
    - CVE-2026-53615

 -- Marc Deslauriers Wed, 19 Aug 2026 13:43:12 -0400

CVE-2026-13595 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers
CVE-2026-27456 util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified
CVE-2026-53613 Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection
CVE-2026-53615 Integer Overflow or Wraparound in libblkid/src/partitions/dos.c

mysql-8.4 Aug 31st 13:07
Release: resolute Repo: universe Level: security New version: 8.4.11-0ubuntu0.26.04.1
Packages in group:  mysql-router mysql-source mysql-testsuite

mysql-8.4 (8.4.11-0ubuntu0.26.04.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Update to 8.4.11 to fix security issues
    - CVE-2026-46936, CVE-2026-47012, CVE-2026-47023, CVE-2026-47052,
      CVE-2026-47064, CVE-2026-60145, CVE-2026-60163, CVE-2026-60177,
      CVE-2026-60178, CVE-2026-60182, CVE-2026-60183, CVE-2026-60184,
      CVE-2026-60185, CVE-2026-60186, CVE-2026-60187, CVE-2026-60188,
      CVE-2026-60189, CVE-2026-60190, CVE-2026-60191, CVE-2026-60315,
      CVE-2026-60316, CVE-2026-60331, CVE-2026-60332, CVE-2026-60585,
      CVE-2026-60747, CVE-2026-61081, CVE-2026-61094, CVE-2026-61096,
      CVE-2026-61109

 -- Marc Deslauriers Wed, 26 Aug 2026 08:40:36 -0400

CVE-2026-46936 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Se
CVE-2026-47012 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My
CVE-2026-47023 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are
CVE-2026-47052 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server:
CVE-2026-47064 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are My
More...



About   -   Send Feedback to @ubuntu_updates