UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2110056 Incomplete fix for CVE-2025-32912 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4
Launchpad 2097688 [BPO] openvpn/2.6.12 from Noble to Jammy openvpn
Launchpad 2104836 Remove unnecessary hyper-v patch linux-azure-6.11 linux-azure-6.11 linux-azure-6.8 linux-azure-6.8 linux-azure
Launchpad 2105912 Apply missing MANA cleanup patch linux-azure-6.11 linux-azure-6.11 linux-azure-6.8 linux-azure-6.8
CVE CVE-2025-46421 A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-46420 A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that conta libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32913 A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32911 A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a maliciou libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32912 A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash. libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32910 A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup clie libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32909 A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32914 A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a maliciou libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-32906 A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup2.4 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3 libsoup3
CVE CVE-2025-23016 FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values libfcgi libfcgi libfcgi libfcgi libfcgi libfcgi libfcgi libfcgi
CVE CVE-2025-43964 In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values. libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2025-43963 In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not ch libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2025-43962 In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 v libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
CVE CVE-2025-43961 In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser. libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw libraw
Launchpad 2091225 openjdk-23 fails to build in jammy armhf with dtrace enabled openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts openjdk-lts
CVE CVE-2025-30698 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported openjdk-8 openjdk-24 openjdk-21 openjdk-17 openjdk-lts openjdk-21 openjdk-8 openjdk-24 openjdk-21 openjdk-17 openjdk-lts openjdk-21 openjdk-8 openjdk-21 openjdk-17 openjdk-lts openjdk-21 openjdk-17 openjdk-lts openjdk-lts openjdk-8 openjdk-21 openjdk-17 openjdk-lts openjdk-8 openjdk-24 openjdk-21 openjdk-17 openjdk-lts openjdk-21 openjdk-21 openjdk-8 openjdk-21 openjdk-17 openjdk-lts openjdk-21 openjdk-17 openjdk-8 openjdk-21 openjdk-17 openjdk-lts openjdk-lts openjdk-8 openjdk-21 openjdk-17 openjdk-lts openjdk-lts openjdk-8 openjdk-24 openjdk-21 openjdk-17 openjdk-lts openjdk-8 openjdk-21 openjdk-17 openjdk-lts



About   -   Send Feedback to @ubuntu_updates