UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-56409 xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. expat expat expat expat expat expat expat expat expat expat expat expat
CVE CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. expat expat expat expat expat expat expat expat expat expat expat expat
CVE CVE-2026-56410 xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. expat expat expat expat expat expat expat expat expat expat expat expat
CVE CVE-2026-74248 OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor octavia octavia octavia octavia octavia octavia
CVE CVE-2026-94571 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f octavia octavia octavia octavia octavia octavia
CVE CVE-2026-94572 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The octavia octavia octavia octavia octavia octavia
CVE CVE-2022-49234 In the Linux kernel, the following vulnerability has been resolved: net: dsa: Avoid cross-chip syncing of VLAN filtering Changes to VLAN filtering linux linux-xilinx-zynqmp linux
CVE CVE-2022-49359 In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Job should reference MMU not file_priv For a while now it's been linux linux-xilinx-zynqmp linux
CVE CVE-2022-49651 In the Linux kernel, the following vulnerability has been resolved: srcu: Tighten cleanup_srcu_struct() GP checks Currently, cleanup_srcu_struct() linux linux-xilinx-zynqmp linux
CVE CVE-2025-21759 In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: extend RCU protection in igmp6_send() igmp6_send() can be called w linux linux-xilinx-zynqmp linux
CVE CVE-2022-49562 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use __try_cmpxchg_user() to update guest PTE A/D bits Use the recentl linux linux-xilinx-zynqmp linux
CVE CVE-2025-21947 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request re linux linux-xilinx-zynqmp linux
CVE CVE-2022-49858 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix SQE threshold checking Current way of checking available SQE linux linux-xilinx-zynqmp linux
CVE CVE-2026-43456 In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skb linux linux-xilinx-zynqmp linux
CVE CVE-2022-50071 In the Linux kernel, the following vulnerability has been resolved: mptcp: move subflow cleanup in mptcp_destroy_common() If the mptcp socket creat linux linux-xilinx-zynqmp linux
CVE CVE-2023-53320 In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info() The function mpi3mr_get_a linux linux-xilinx-zynqmp linux
CVE CVE-2022-50303 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix double release compute pasid If kfd_process_device_init_vm retu linux linux-xilinx-zynqmp linux
CVE CVE-2022-1205 A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protoc linux linux-xilinx-zynqmp linux
Launchpad 2129861 udpgro.sh from ubuntu_kselftests_net failed with J-5.15 (udpgso_bench_rx: recv: bad packet len) linux linux-xilinx-zynqmp linux
Launchpad 2107442 [SRU] selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value linux linux-xilinx-zynqmp linux



About   -   Send Feedback to @ubuntu_updates