Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| Launchpad | 2154589 | [SRU] package lxqt-panel (not installed) failed to install/upgrade: trying to overwrite '/etc/xdg/lxqt/panel.conf', which is also in package lxqt-bra | lxqt-panel |
| Launchpad | 2164500 | malcontent-gui missing dependency of malcontent | malcontent malcontent |
| Launchpad | 2162116 | Multiple malcontent services not able to run due to needed user not exist | malcontent malcontent |
| Launchpad | 2155233 | cuda-toolkit cannot compile minimal example | cuda-crt-13-1 |
| Launchpad | 2153419 | SRU: New Upstream Version 7.2.4 | rocr-runtime |
| Launchpad | 2164608 | [SRU] backport golang-1.24 (1.24.13) to jammy and noble | golang-1.24 golang-1.24 |
| Launchpad | 2166415 | [SRU Exception] Update ubuntu-release-upgrader data for 24.04.5 | ubuntu-release-upgrader ubuntu-release-upgrader ubuntu-release-upgrader ubuntu-release-upgrader |
| Launchpad | 2078579 | Holding Back libpcap0.8t64:amd64 rather than change libibverbs1:amd64 | ubuntu-release-upgrader ubuntu-release-upgrader ubuntu-release-upgrader ubuntu-release-upgrader |
| Launchpad | 2166356 | linux: dtbs_install fails on Resolute builders due to uutils install(1) EEXIST race under parallel make | linux linux linux-hwe-7.0 |
| Launchpad | 2165873 | Bluetooth fails to initialize due to a kernel NULL pointer error | linux linux linux-hwe-6.8 linux-lowlatency-hwe-6.8 |
| Launchpad | 2163303 | [regression] linux-firmware 20240318.git3b128b60-0ubuntu2.29 causes half-screen corruption/black screens on AMD Navi 21; 0ubuntu2.26 works | linux-firmware-amd-graphics |
| CVE | CVE-2026-57966 | A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any loc | spice-vdagent spice-vdagent spice-vdagent spice-vdagent spice-vdagent spice-vdagent |
| CVE | CVE-2026-57965 | A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This | spice-vdagent spice-vdagent spice-vdagent spice-vdagent spice-vdagent spice-vdagent |
| CVE | CVE-2026-66035 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server | libssh2 libssh2 libssh2 libssh2 |
| CVE | CVE-2026-66033 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in | libssh2 libssh2 libssh2 libssh2 |
| CVE | CVE-2026-66032 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio | libssh2 libssh2 libssh2 libssh2 |
| CVE | CVE-2026-73283 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. | openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh |
| CVE | CVE-2026-73282 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. | openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh |
| CVE | CVE-2026-73281 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens | openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh |
| CVE | CVE-2026-57062 | CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to b | gnupg2 gnupg2 gnupg2 gnupg2 gnupg2 gnupg2 gnupg2 gnupg2 |
About
-
Send Feedback to @ubuntu_updates