UbuntuUpdates.org

Latest Changelogs for all releases

All releases Bionic Focal Jammy Lunar Mantic Noble Precise Trusty Xenial
Include all PPAs Exclude daily builds PPAs Exclude all PPAs
Include levels: securityupdatesbackportsproposedbase

Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).

ubuntustudio-installer May 3rd 20:06
Release: noble Repo: universe Level: proposed New version: 1.18.1
Packages in group: 

  ubuntustudio-installer (1.18.1) noble; urgency=medium

  * Fix missing user audio config (mem limits, group) (LP: #2063899)
  * Fix "Switch Configuration" loop bug (LP: #2064170)

 -- Erich Eickmeyer <email address hidden> Fri, 26 Apr 2024 18:00:44 -0700

2063899 [SRU] Users are not initially configured properly for audio in Ubuntu Studio
2064170 [SRU] \

nautilus May 3rd 20:06
Release: noble Repo: main Level: proposed New version: 1:46.1-0ubuntu1
Packages in group:  gir1.2-nautilus-4.0 libnautilus-extension4 nautilus-data

  nautilus (1:46.1-0ubuntu1) noble; urgency=medium

  * New upstream stable bugfix release (lp: #2064643)

 -- Sebastien Bacher <email address hidden> Thu, 02 May 2024 17:08:57 +0200

2064643 46.1 stable update

xdg-desktop-portal May 3rd 19:07
Release: noble Repo: universe Level: proposed New version: 1.18.4-1ubuntu2
Packages in group:  xdg-desktop-portal-tests

  xdg-desktop-portal (1.18.4-1ubuntu2) noble; urgency=medium

  * Merge with Debian (LP: #2062394). Remaining change:
    - Import https://github.com/flatpak/xdg-desktop-portal/pull/705 as a
      distro-patch to add a portal for managing WebExtensions native messaging
      servers

2062394 Update xdg-desktop-portal to 1.18.4

tzdata May 3rd 19:07
Release: noble Repo: universe Level: proposed New version: 2024a-3ubuntu1.1
Packages in group:  tzdata-icu

  tzdata (2024a-3ubuntu1.1) noble; urgency=medium

  * d/rules: Support creating symlinks pointing to symlinks
  * Fixup for avoid timezones being symlinks to symlinks (LP: #2062522)

2062522 std::chrono::locate_zone(\

smifb2 May 3rd 19:07
Release: noble Repo: universe Level: proposed New version: 2.2.6.3.gbbd2e82-1ubuntu0.1
Packages in group:  smifb2-dkms

  smifb2 (2.2.6.3.gbbd2e82-1ubuntu0.1) noble; urgency=medium

  * Fix Linux 6.8 build LP: #2063344

 -- Paolo Pisati <email address hidden> Wed, 24 Apr 2024 14:18:53 +0000

2063344 smifb2-dkms DKMS FTBFS wrt Linux 6.8

xdg-desktop-portal May 3rd 19:06
Release: noble Repo: main Level: proposed New version: 1.18.4-1ubuntu2
Packages in group:  xdg-desktop-portal-dev

  xdg-desktop-portal (1.18.4-1ubuntu2) noble; urgency=medium

  * Merge with Debian (LP: #2062394). Remaining change:
    - Import https://github.com/flatpak/xdg-desktop-portal/pull/705 as a
      distro-patch to add a portal for managing WebExtensions native messaging
      servers

2062394 Update xdg-desktop-portal to 1.18.4

runc-app May 3rd 18:07
Release: jammy Repo: main Level: proposed New version: 1.1.12-0ubuntu2~22.04.1
Packages in group:  runc

  runc-app (1.1.12-0ubuntu2~22.04.1) jammy; urgency=medium

  * Backport version from Noble to Jammy (LP: #2040460, #2022390).
    - d/rules: override dh_dwz to do nothing to avoid build error.

 -- Lucas Kanashiro <email address hidden> Tue, 12 Mar 2024 17:08:06 -0300


runc-app May 3rd 18:07
Release: focal Repo: main Level: proposed New version: 1.1.12-0ubuntu2~20.04.1
Packages in group:  runc

  runc-app (1.1.12-0ubuntu2~20.04.1) focal; urgency=medium

  * Backport version from Noble to Focal (LP: #2040460, #2022390).
    - d/rules: override dh_dwz to do nothing to avoid build error.

 -- Lucas Kanashiro <email address hidden> Tue, 12 Mar 2024 17:08:06 -0300


linux-restricted-signatures May 3rd 15:07
Release: mantic Repo: restricted Level: proposed New version: 6.5.0-40.40
Packages in group:  linux-modules-nvidia-525-open-6.5.0-12-generic linux-modules-nvidia-525-open-6.5.0-14-generic linux-modules-nvidia-525-open-6.5.0-16-generic linux-modules-nvidia-525-open-6.5.0-17-generic linux-modules-nvidia-525-open-6.5.0-25-generic linux-modules-nvidia-535-open-6.5.0-12-generic linux-modules-nvidia-535-open-6.5.0-14-generic linux-modules-nvidia-535-open-6.5.0-16-generic linux-modules-nvidia-535-open-6.5.0-17-generic linux-modules-nvidia-535-open-6.5.0-25-generic linux-modules-nvidia-535-open-6.5.0-27-generic (... see all)

  linux-restricted-signatures (6.5.0-40.40) mantic; urgency=medium

  * Main version: 6.5.0-40.40

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package

 -- Roxana Nicolescu <email address hidden> Tue, 30 Apr 2024 14:53:01 +0200

1786013 Packaging resync

linux-restricted-modules May 3rd 15:07
Release: mantic Repo: restricted Level: proposed New version: 6.5.0-40.40
Packages in group:  linux-modules-nvidia-435-generic linux-modules-nvidia-435-generic-hwe-22.04 linux-modules-nvidia-435-generic-hwe-22.04-edge linux-modules-nvidia-440-generic linux-modules-nvidia-440-generic-hwe-22.04 linux-modules-nvidia-440-generic-hwe-22.04-edge linux-modules-nvidia-440-oem-20.04 linux-modules-nvidia-450-generic linux-modules-nvidia-450-generic-hwe-22.04 linux-modules-nvidia-450-generic-hwe-22.04-edge linux-modules-nvidia-450-oem-20.04 (... see all)

  linux-restricted-modules (6.5.0-40.40) mantic; urgency=medium

  * Main version: 6.5.0-40.40

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package

 -- Roxana Nicolescu <email address hidden> Tue, 30 Apr 2024 14:53:01 +0200

1786013 Packaging resync

tzdata May 3rd 14:07
Release: noble Repo: main Level: proposed New version: 2024a-3ubuntu1.1
Packages in group:  tzdata-legacy

  tzdata (2024a-3ubuntu1.1) noble; urgency=medium

  * d/rules: Support creating symlinks pointing to symlinks
  * Fixup for avoid timezones being symlinks to symlinks (LP: #2062522)

2062522 std::chrono::locate_zone(\

linux-signed May 3rd 14:07
Release: mantic Repo: main Level: proposed New version: 6.5.0-40.40
Packages in group:  linux-image-6.5.0-12-generic linux-image-6.5.0-14-generic linux-image-6.5.0-16-generic linux-image-6.5.0-17-generic linux-image-6.5.0-25-generic linux-image-6.5.0-27-generic linux-image-6.5.0-33-generic linux-image-6.5.0-34-generic linux-image-6.5.0-40-generic linux-image-uc-6.5.0-12-generic linux-image-uc-6.5.0-14-generic (... see all)

  linux-signed (6.5.0-40.40) mantic; urgency=medium

  * Main version: 6.5.0-40.40

  * Packaging resync (LP: #1786013)
    - [Packaging] debian/tracking-bug -- resync from main package

 -- Roxana Nicolescu <email address hidden> Tue, 30 Apr 2024 14:52:49 +0200

1786013 Packaging resync

linux-meta May 3rd 14:07
Release: mantic Repo: main Level: proposed New version: 6.5.0.40.40
Packages in group:  linux-cloud-tools-generic linux-cloud-tools-generic-hwe-22.04 linux-cloud-tools-generic-hwe-22.04-edge linux-cloud-tools-virtual linux-cloud-tools-virtual-hwe-22.04 linux-cloud-tools-virtual-hwe-22.04-edge linux-crashdump linux-generic linux-generic-hwe-22.04 linux-generic-hwe-22.04-edge linux-headers-generic (... see all)

  linux-meta (6.5.0.40.40) mantic; urgency=medium

  * Bump ABI 6.5.0-40

 -- Roxana Nicolescu <email address hidden> Tue, 30 Apr 2024 14:52:43 +0200


linux May 3rd 14:07
Release: mantic Repo: main Level: proposed New version: 6.5.0-40.40
Packages in group:  linux-buildinfo-6.5.0-12-generic linux-buildinfo-6.5.0-14-generic linux-buildinfo-6.5.0-16-generic linux-buildinfo-6.5.0-17-generic linux-buildinfo-6.5.0-25-generic linux-buildinfo-6.5.0-27-generic linux-buildinfo-6.5.0-33-generic linux-buildinfo-6.5.0-34-generic linux-buildinfo-6.5.0-40-generic linux-cloud-tools-6.5.0-12 linux-cloud-tools-6.5.0-12-generic (... see all)

  linux (6.5.0-40.40) mantic; urgency=medium

  * mantic/linux: 6.5.0-40.40 -proposed tracker (LP: #2063709)

  * [Mantic] Compile broken on armhf (cc1 out of memory) (LP: #2060446)
    - Revert "minmax: relax check to allow comparison between unsigned arguments
      and signed constants"
    - Revert "minmax: allow comparisons of 'int' against 'unsigned char/short'"
    - Revert "minmax: allow min()/max()/clamp() if the arguments have the same
      signedness."
    - Revert "minmax: add umin(a, b) and umax(a, b)"

  * Drop fips-checks script from trees (LP: #2055083)
    - [Packaging] Remove fips-checks script

  * alsa/realtek: adjust max output valume for headphone on 2 LG machines
    (LP: #2058573)
    - ALSA: hda/realtek: fix the hp playback volume issue for LG machines

  * Mantic update: upstream stable patchset 2024-03-27 (LP: #2059284)
    - asm-generic: make sparse happy with odd-sized put_unaligned_*()
    - powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
    - arm64: irq: set the correct node for VMAP stack
    - drivers/perf: pmuv3: don't expose SW_INCR event in sysfs
    - powerpc: Fix build error due to is_valid_bugaddr()
    - powerpc/mm: Fix build failures due to arch_reserved_kernel_pages()
    - powerpc/64s: Fix CONFIG_NUMA=n build due to create_section_mapping()
    - x86/boot: Ignore NMIs during very early boot
    - powerpc: pmd_move_must_withdraw() is only needed for
      CONFIG_TRANSPARENT_HUGEPAGE
    - powerpc/lib: Validate size for vector operations
    - x86/mce: Mark fatal MCE's page as poison to avoid panic in the kdump kernel
    - perf/core: Fix narrow startup race when creating the perf nr_addr_filters
      sysfs file
    - debugobjects: Stop accessing objects after releasing hash bucket lock
    - regulator: core: Only increment use_count when enable_count changes
    - audit: Send netlink ACK before setting connection in auditd_set
    - ACPI: video: Add quirk for the Colorful X15 AT 23 Laptop
    - PNP: ACPI: fix fortify warning
    - ACPI: extlog: fix NULL pointer dereference check
    - ACPI: NUMA: Fix the logic of getting the fake_pxm value
    - PM / devfreq: Synchronize devfreq_monitor_[start/stop]
    - ACPI: APEI: set memory failure flags as MF_ACTION_REQUIRED on synchronous
      events
    - FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree
    - jfs: fix array-index-out-of-bounds in dbAdjTree
    - pstore/ram: Fix crash when setting number of cpus to an odd number
    - crypto: octeontx2 - Fix cptvf driver cleanup
    - erofs: fix ztailpacking for subpage compressed blocks
    - crypto: stm32/crc32 - fix parsing list of devices
    - afs: fix the usage of read_seqbegin_or_lock() in afs_lookup_volume_rcu()
    - afs: fix the usage of read_seqbegin_or_lock() in afs_find_server*()
    - rxrpc_find_service_conn_rcu: fix the usage of read_seqbegin_or_lock()
    - jfs: fix array-index-out-of-bounds in diNewExt
    - arch: consolidate arch_irq_work_raise prototypes
    - s390/vfio-ap: fix

(See more...)
2060446 [Mantic] Compile broken on armhf (cc1 out of memory)
2055083 Drop fips-checks script from trees
2058573 alsa/realtek: adjust max output valume for headphone on 2 LG machines
2059284 Mantic update: upstream stable patchset 2024-03-27
2059068 Mantic update: upstream stable patchset 2024-03-26
More...

php7.4 May 3rd 14:06
Release: focal Repo: universe Level: updates New version: 7.4.3-4ubuntu2.22
Packages in group:  libphp7.4-embed php7.4-bcmath php7.4-bz2 php7.4-dba php7.4-enchant php7.4-fpm php7.4-imap php7.4-interbase php7.4-intl php7.4-mbstring php7.4-phpdbg (... see all)

  php7.4 (7.4.3-4ubuntu2.22) focal-security; urgency=medium

  * SECURITY UPDATE: Heap buffer-overflow
    - debian/patches/CVE-2022-4900.patch: prevent potential buffer
      overflow for large valye of php_cli_server_workers_max in
      sapi/cli/php_cli_server.c.
    - CVE-2022-4900
  * SECURITY UPDATE: Cookie by pass
    - debian/patches/CVE-2024-2756.patch: adds more mangling rules
      in main/php_variable.c.
    - CVE-2024-2756
  * SECURITY UPDATE: Account take over risk
    - debian/patches/CVE-2024-3096.patch: disallow null character in bcrypt
      password in ext/standard/password.c,
      ext/standard/tests/password_bcrypt_errors.phpt.
    - CVE-2024-3096

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 01 May 2024 07:11:33 -0300

CVE-2022-4900 A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
CVE-2024-2756 Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard in
CVE-2024-3096 In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00



About   -   Send Feedback to @ubuntu_updates