UbuntuUpdates.org

Latest Changelogs for all releases

All releases Bionic Focal Jammy Noble Oracular Plucky Xenial
Include all PPAs Exclude daily builds PPAs Exclude all PPAs
Include levels: securityupdatesbackportsproposedbase

Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).

linux-signed-realtime Jun 20th 00:07
Release: plucky Repo: universe Level: security New version: 6.14.0-1004.4
Packages in group:  linux-image-6.14.0-1004-realtime linux-image-uc-6.14.0-1004-realtime

  linux-signed-realtime (6.14.0-1004.4) plucky; urgency=medium

  * Main version: 6.14.0-1004.4

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package

1786013 Packaging resync


linux-restricted-signatures Jun 20th 00:07
Release: plucky Repo: restricted Level: security New version: 6.14.0-22.22
Packages in group:  linux-modules-nvidia-535-server-open-6.14.0-15-generic linux-modules-nvidia-535-server-open-6.14.0-22-generic linux-modules-nvidia-550-server-open-6.14.0-15-generic linux-modules-nvidia-550-server-open-6.14.0-22-generic linux-modules-nvidia-570-open-6.14.0-15-generic linux-modules-nvidia-570-open-6.14.0-22-generic linux-modules-nvidia-570-server-open-6.14.0-15-generic linux-modules-nvidia-570-server-open-6.14.0-22-generic linux-signatures-nvidia-6.14.0-15-generic linux-signatures-nvidia-6.14.0-22-generic

  linux-restricted-signatures (6.14.0-22.22) plucky; urgency=medium

  * Main version: 6.14.0-22.22

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package

 -- Stefan Bader <email address hidden> Wed, 21 May 2025 11:43:25 +0200

1786013 Packaging resync

linux-restricted-signatures-gcp Jun 20th 00:07
Release: plucky Repo: restricted Level: security New version: 6.14.0-1008.8
Packages in group:  linux-modules-nvidia-535-server-open-6.14.0-1006-gcp linux-modules-nvidia-535-server-open-6.14.0-1008-gcp linux-modules-nvidia-550-server-open-6.14.0-1006-gcp linux-modules-nvidia-550-server-open-6.14.0-1008-gcp linux-modules-nvidia-570-open-6.14.0-1006-gcp linux-modules-nvidia-570-open-6.14.0-1008-gcp linux-modules-nvidia-570-server-open-6.14.0-1006-gcp linux-modules-nvidia-570-server-open-6.14.0-1008-gcp linux-signatures-nvidia-6.14.0-1006-gcp linux-signatures-nvidia-6.14.0-1008-gcp

  linux-restricted-signatures-gcp (6.14.0-1008.8) plucky; urgency=medium

  * Main version: 6.14.0-1008.8

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package
    - [Packaging] debian/dkms-versions -- update from kernel-versions
      (main/2025.04.14)
    - [Packaging] debian/tracking-bug -- resync from main package

  * Miscellaneous Ubuntu changes
    - Ubuntu-gcp-6.14.0-1007.7

 -- Tim Whisonant <email address hidden> Tue, 27 May 2025 12:12:21 -0700

1786013 Packaging resync


linux-restricted-modules-gcp Jun 20th 00:07
Release: plucky Repo: restricted Level: security New version: 6.14.0-1008.8
Packages in group:  linux-modules-nvidia-525-server-gcp linux-modules-nvidia-525-server-open-gcp linux-modules-nvidia-535-gcp linux-modules-nvidia-535-open-gcp linux-modules-nvidia-535-server-6.14.0-1006-gcp linux-modules-nvidia-535-server-6.14.0-1008-gcp linux-modules-nvidia-535-server-gcp linux-modules-nvidia-535-server-open-gcp linux-modules-nvidia-550-gcp linux-modules-nvidia-550-open-gcp linux-modules-nvidia-550-server-6.14.0-1006-gcp (... see all)

  linux-restricted-modules-gcp (6.14.0-1008.8) plucky; urgency=medium

  * Main version: 6.14.0-1008.8

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package
    - [Packaging] debian/dkms-versions -- update from kernel-versions
      (main/2025.04.14)
    - [Packaging] debian/tracking-bug -- resync from main package

  * Miscellaneous Ubuntu changes
    - Ubuntu-gcp-6.14.0-1007.7

 -- Tim Whisonant <email address hidden> Tue, 27 May 2025 12:12:21 -0700

1786013 Packaging resync

linux-riscv Jun 20th 00:07
Release: plucky Repo: main Level: security New version: 6.14.0-22.22.1
Packages in group:  linux-riscv-headers-6.14.0-22

  linux-riscv (6.14.0-22.22.1) plucky; urgency=medium

  * plucky/linux-riscv: 6.14.0-22.22.1 -proposed tracker (LP: #2110649)

  [ Ubuntu: 6.14.0-22.22 ]

  * plucky/linux: 6.14.0-22.22 -proposed tracker (LP: #2111404)
  * snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes
    (LP: #2110289)
    - fs/eventpoll: fix endless busy loop after timeout has expired

  [ Ubuntu: 6.14.0-20.20 ]

  * plucky/linux: 6.14.0-20.20 -proposed tracker (LP: #2110652)
  * Rotate the Canonical Livepatch key (LP: #2111244)
    - [Config] Prepare for Canonical Livepatch key rotation
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268)
    - soc: qcom: ice: introduce devm_of_qcom_ice_get
    - mmc: sdhci-msm: fix dev reference leaked through of_qcom_ice_get
    - PM: EM: use kfree_rcu() to simplify the code
    - PM: EM: Address RCU-related sparse warnings
    - media: i2c: imx214: Use subdev active state
    - media: i2c: imx214: Simplify with dev_err_probe()
    - media: i2c: imx214: Convert to CCI register access helpers
    - media: i2c: imx214: Replace register addresses with macros
    - media: i2c: imx214: Check number of lanes from device tree
    - media: i2c: imx214: Fix link frequency validation
    - media: ov08x40: Move ov08x40_identify_module() function up
    - media: ov08x40: Add missing ov08x40_identify_module() call on stream-start
    - iio: adc: ad7768-1: Move setting of val a bit later to avoid unnecessary
      return value check
    - iio: adc: ad7768-1: Fix conversion result sign
    - of: resolver: Simplify of_resolve_phandles() using __free()
    - of: resolver: Fix device node refcount leakage in of_resolve_phandles()
    - scsi: ufs: qcom: fix dev reference leaked through of_qcom_ice_get
    - PCI/MSI: Convert pci_msi_ignore_mask to per MSI domain flag
    - PCI/MSI: Handle the NOMASK flag correctly for all PCI/MSI backends
    - PCI/MSI: Add an option to write MSIX ENTRY_DATA before any reads
    - irqchip/renesas-rzv2h: Simplify rzv2h_icu_init()
    - irqchip/renesas-rzv2h: Add struct rzv2h_hw_info with t_offs variable
    - irqchip/renesas-rzv2h: Prevent TINT spurious interrupt
    - drm/xe/ptl: Apply Wa_14023061436
    - drm/xe/xe3lpg: Add Wa_13012615864
    - drm/xe: Add performance tunings to debugfs
    - drm/xe/rtp: Drop sentinels from arg to xe_rtp_process_to_sr()
    - drm/xe: Ensure fixed_slice_mode gets set after ccs_mode change
    - lib/Kconfig.ubsan: Remove 'default UBSAN' from UBSAN_INTEGER_WRAP
    - ceph: Fix incorrect flush end position calculation
    - dma/contiguous: avoid warning about unused size_bytes
    - virtio_pci: Use self group type for cap commands
    - cpufreq: cppc: Fix invalid return value in .get() callback
    - cpufreq: Do not enable by default during compile testing
    - cpufreq: fix compile-test defaults
    - btrfs: avoid page_lockend underflow in btrfs_punch_hole_lock_range()
    - cgroup/cpuset-v1: Add missing support for cpuset_v2_mode
    - vhost-scsi: Add b

(See more...)
2110289 snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes
2111244 Rotate the Canonical Livepatch key
2111268 Plucky update: v6.14.5 upstream stable release
1786013 Packaging resync
2109367 Plucky update: v6.14.4 upstream stable release
More...

linux-signed Jun 20th 00:07
Release: plucky Repo: main Level: security New version: 6.14.0-22.22
Packages in group:  linux-image-6.14.0-22-generic linux-image-uc-6.14.0-22-generic

  linux-signed (6.14.0-22.22) plucky; urgency=medium

  * Main version: 6.14.0-22.22

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package

1786013 Packaging resync

linux-signed-gcp Jun 20th 00:07
Release: plucky Repo: main Level: security New version: 6.14.0-1008.8
Packages in group:  linux-image-6.14.0-1008-gcp

  linux-signed-gcp (6.14.0-1008.8) plucky; urgency=medium

  * Main version: 6.14.0-1008.8

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package
    - [Packaging] debian/tracking-bug -- resync from main package

  * Miscellaneous Ubuntu changes
    - Ubuntu-gcp-6.14.0-1007.7

 -- Tim Whisonant <email address hidden> Tue, 27 May 2025 12:12:04 -0700

1786013 Packaging resync

linux-meta-gcp Jun 20th 00:07
Release: plucky Repo: main Level: security New version: 6.14.0-1008.8
Packages in group:  linux-gcp linux-headers-gcp linux-image-gcp linux-modules-extra-gcp linux-tools-gcp

  linux-meta-gcp (6.14.0-1008.8) plucky; urgency=medium

  * Main version: 6.14.0-1008.8

  * Miscellaneous Ubuntu changes
    - Ubuntu-gcp-6.14.0-1007.7

 -- Tim Whisonant <email address hidden> Tue, 27 May 2025 12:11:49 -0700



linux Jun 20th 00:07
Release: plucky Repo: main Level: security New version: 6.14.0-22.22
Packages in group:  bpftool linux-bpf-dev linux-buildinfo-6.14.0-22-generic linux-cloud-tools-6.14.0-22 linux-cloud-tools-6.14.0-22-generic linux-cloud-tools-common linux-doc linux-headers-6.14.0-22 linux-headers-6.14.0-22-generic linux-image-unsigned-6.14.0-22-generic linux-libc-dev (... see all)

  linux (6.14.0-22.22) plucky; urgency=medium

  * plucky/linux: 6.14.0-22.22 -proposed tracker (LP: #2111404)

  * snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes
    (LP: #2110289)
    - fs/eventpoll: fix endless busy loop after timeout has expired

2110289 snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes

python3.13 Jun 20th 00:07
Release: plucky Repo: main Level: security New version: 3.13.3-1ubuntu0.2
Packages in group:  libpython3.13 libpython3.13-dbg libpython3.13-dev libpython3.13-minimal libpython3.13-stdlib python3.13-dbg python3.13-dev python3.13-doc python3.13-examples python3.13-gdbm python3.13-minimal (... see all)

  python3.13 (3.13.3-1ubuntu0.2) plucky-security; urgency=medium

  * SECURITY UPDATE: Arbitrary filesystem and metadata write through improper
    tar filtering.
    - debian/patches/CVE-202x-12718-4138-4x3x-4517-pre1.patch: Add additional
      tests in ./Lib/test/test_ntpath.py and ./Lib/test/test_posixpath.py.
    - debian/patches/CVE-202x-12718-4138-4x3x-4517.patch: Add ALLOW_MISSING in
      ./Lib/genericpath.py, ./Lib/ntpath.py, ./Lib/posixpath.py. Change filter
      to handle errors in ./Lib/ntpath.py, ./Lib/posixpath.py. Add checks and
      unfiltered to ./Lib/tarfile.py. Modify tests.
    - CVE-2024-12718
    - CVE-2025-4138
    - CVE-2025-4330
    - CVE-2025-4435
    - CVE-2025-4517

 -- Hlib Korzhynskyy <email address hidden> Mon, 16 Jun 2025 15:45:32 -0230

CVE-2024-12718 Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extrac
CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me
CVE-2025-4330 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me
CVE-2025-4435 When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extrac
CVE-2025-4517 Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if

roundcube Jun 20th 00:07
Release: oracular Repo: universe Level: updates New version: 1.6.8+dfsg-2ubuntu0.1
Packages in group:  roundcube-core roundcube-mysql roundcube-pgsql roundcube-plugins roundcube-sqlite3

  roundcube (1.6.8+dfsg-2ubuntu0.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Remote code execution post authentication
    - debian/patches/CVE-2025-49113.patch: Updated
      program/actions/settings/upload.php,
      program/lib/Roundcube/rcube_utils.php and
      tests/Framework/Utils.php to validate URL parameter in upload code
    - CVE-2025-49113

 -- Chrisa Oikonomou <email address hidden> Wed, 04 Jun 2025 15:41:15 +0300

CVE-2025-49113 Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n

linux-restricted-signatures Jun 20th 00:07
Release: noble Repo: restricted Level: security New version: 6.8.0-62.65
Packages in group:  linux-modules-nvidia-535-open-6.8.0-35-generic linux-modules-nvidia-535-open-6.8.0-36-generic linux-modules-nvidia-535-open-6.8.0-38-generic linux-modules-nvidia-535-open-6.8.0-39-generic linux-modules-nvidia-535-open-6.8.0-40-generic linux-modules-nvidia-535-open-6.8.0-41-generic linux-modules-nvidia-535-open-6.8.0-44-generic linux-modules-nvidia-535-open-6.8.0-45-generic linux-modules-nvidia-535-open-6.8.0-47-generic linux-modules-nvidia-535-open-6.8.0-48-generic linux-modules-nvidia-535-open-6.8.0-49-generic (... see all)

  linux-restricted-signatures (6.8.0-62.65) noble; urgency=medium

  * Main version: 6.8.0-62.65

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package
    - [Packaging] debian/dkms-versions -- update from kernel-versions
      (main/2025.05.19)

 -- Stefan Bader <email address hidden> Mon, 19 May 2025 17:52:06 +0200

1786013 Packaging resync



About   -   Send Feedback to @ubuntu_updates