UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-12064 When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl curl curl curl curl
CVE CVE-2026-11586 By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a curl curl
CVE CVE-2026-11564 libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle th curl curl
CVE CVE-2026-11352 An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. curl curl
CVE CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR curl curl curl curl curl curl
Launchpad 2158262 Please drop pollinate from the default installed set in ubuntu server ubuntu-meta
CVE CVE-2026-24660 A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2026-24450 An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2026-21413 A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2026-20889 A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2026-20884 An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2026-5342 A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4
CVE CVE-2026-2369 A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4
CVE CVE-2026-57053 GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_intern libidn libidn libidn libidn libidn libidn libidn libidn libidn libidn libidn libidn
CVE CVE-2025-22869 SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, golang-go.crypto golang-go.crypto
CVE CVE-2025-47913 SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process. golang-go.crypto golang-go.crypto
Launchpad 2153486 Backport open-vm-tools 13.0.10 to noble open-vm-tools open-vm-tools
Launchpad 2156482 Transition the 535 graphics driver packages to 580 fabric-manager-535 libnvidia-nscq-535 nvidia-graphics-drivers-535-server nvidia-graphics-drivers-535 fabric-manager-535 libnvidia-nscq-535 nvidia-graphics-drivers-535-server nvidia-graphics-drivers-535
CVE CVE-2026-10037 A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files ma mailcap mailcap mailcap mailcap



About   -   Send Feedback to @ubuntu_updates