UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the cl openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) becaus openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argum openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
CVE CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controll openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh openssh
Launchpad 2145785 portblock does not work due to iptables changes resource-agents resource-agents
Launchpad 2156047 [SRU] Terminal profile is out of sync with the Desktop theme wsl-setup wsl-setup
Launchpad 2145790 ocf:heartbeat:nfsserver resource's stop operation fails due to /var/lib/nfs filesystem failing to unmount resource-agents resource-agents resource-agents resource-agents
CVE CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte linux-azure-nvidia linux-azure-nvidia linux
Launchpad 2156472 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer linux-azure-nvidia linux-azure-nvidia
Launchpad 2155222 [hyperv] Ensure MMIO Mapping is Correct for Kexec / kdump kernel on Azure v6 Instance Types linux-azure-nvidia linux-azure-nvidia
Launchpad 2155434 net: mana: Avoid queue struct allocation failure under memory fragmentation linux-azure-nvidia linux-azure-nvidia
Launchpad 2156920 Fix MANA RX queue creation/error-cleanup path issues when RXQ initialization fails partway through linux-azure-nvidia linux-azure-nvidia
Launchpad 2157545 azure: backport \ linux-azure-nvidia linux-azure-nvidia
Launchpad 2158920 noble-stable-2026-06-16 dropped a bracket causing FTBFS linux-azure-nvidia linux-azure-nvidia linux
CVE CVE-2026-5773 libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequen curl curl curl curl
CVE CVE-2026-12064 When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl curl curl curl curl



About   -   Send Feedback to @ubuntu_updates