Your IP : 216.73.217.154


Current Path : /snap/core22/current/usr/share/doc/
Upload File :
Current File : //snap/core22/current/usr/share/doc/ChangeLog

24/08/2026, commit https://github.com/canonical/core-base/tree/3d5932d91cd499a5cae182f213776150953fa0b4

[ Changes in the core22 snap ]

JP Meijers (1):
      hooks: create /usr/lib/wsl mount point (#435)

Mohit Chachada (2):
      README: document where to find changelog (#451)
      github: sync release-manual workflow to the latest state of action-rebuild-base (#458)

Valentin David (1):
      patch/netplan-apply.diff: fix path

[ Changes in primed packages ]

netplan-generator (0.107.1-3ubuntu0.22.04.4): new primed package

python3-netplan (0.107.1-3ubuntu0.22.04.4): new primed package

ca-certificates (built from ca-certificates) updated from 20240203~22.04.1 to 20260601~22.04.1:

  ca-certificates (20260601~22.04.1) jammy-security; urgency=medium

    * Update Mozilla certificate authority bundle to version 2.86
      (LP: #2156786)
      The following certificate authority was added (+):
      + e-Szigno TLS Root CA 2023
      The following certificate authorities were removed (-):
      - QuoVadis Root CA 2
      - QuoVadis Root CA 3
      - DigiCert Assured ID Root CA
      - DigiCert Global Root CA
      - DigiCert High Assurance EV Root CA
      - SwissSign Gold CA - G2
      - SecureTrust CA
      - Secure Global CA
      - COMODO Certification Authority
      - Certigna
      - certSIGN ROOT CA
      - AffirmTrust Commercial
      - AffirmTrust Networking
      - AffirmTrust Premium
      - AffirmTrust Premium ECC
      - TeliaSonera Root CA v1
      - Entrust Root Certification Authority - G2
      - Entrust Root Certification Authority - EC1
      - Trustwave Global Certification Authority
      - Trustwave Global ECC P256 Certification Authority
      - Trustwave Global ECC P384 Certification Authority
      - GLOBALTRUST 2020
      - GTS Root R2
      - FIRMAPROFESIONAL CA ROOT-A WEB
      The following certificate authority was renamed (~):
      ~ "OISTE Server Root RSA G1" (removed leading space)
    * Update Mozilla certificate authority bundle to version 2.82
      The following certificate authorities were added (+):
      + TrustAsia TLS ECC Root CA
      + TrustAsia TLS RSA Root CA
      + SwissSign RSA TLS Root CA 2022 - 1
      + OISTE Server Root ECC G1
      +  OISTE Server Root RSA G1
      The following certificate authorities were removed (-):
      - GlobalSign Root CA
      - Entrust.net Premium 2048 Secure Server CA
      - Baltimore CyberTrust Root (closes: #1121936)
      - Comodo AAA Services root
      - XRamp Global CA Root
      - Go Daddy Class 2 CA
      - Starfield Class 2 CA
      - CommScope Public Trust ECC Root-01
      - CommScope Public Trust ECC Root-02
      - CommScope Public Trust RSA Root-01
      - CommScope Public Trust RSA Root-02
    * Update Mozilla certificate authority bundle to version 2.74.
      The following certificate authorities were added (+):
      + D-TRUST BR Root CA 2 2023
      + D-TRUST EV Root CA 2 2023
      The following certificate authorities were removed (-):
      - Entrust Root Certification Authority - G4
      - SecureSign RootCA11
      - Security Communication RootCA3
      - SwissSign Silver CA - G2
    * Update Mozilla certificate authority bundle to version 2.70.
      The following certificate authorities were added (+):
      + Telekom Security TLS ECC Root 2020
      + Telekom Security TLS RSA Root 2023
      + FIRMAPROFESIONAL CA ROOT-A WEB
      + TWCA CYBER Root CA
      + SecureSign Root CA12
      + SecureSign Root CA14
      + SecureSign Root CA15
      The following certificate authorities were removed (-):
      - Security Communication Root CA (closes: #1063093)

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 15 Jun 2026 12:17:29 -0400

cloud-init (built from cloud-init) updated from 25.3-0ubuntu1~22.04.1 to 26.1-0ubuntu1~22.04.1:

  cloud-init (26.1-0ubuntu1~22.04.1) jammy; urgency=medium

    * d/p/0001-Revert-fix-DNS-resolution-performance-regression-dur.patch revert Ec2 URL change 
    * d/p/0001-Revert-fix-support-bond-names-in-network_data.patch revert bond name change
    * d/rules: provide PACKAGED_VERSION env var to force setuptools version to
      match downstream DEB_VERSION
    * refresh patches:
      - d/p/no-nocloud-network.patch
      - d/p/no-single-process.patch
      - d/p/retain-ec2-default-net-update-events.patch
      - d/p/retain-setuptools.patch. Read PACKAGED_VERSION environment variable
      - d/p/revert-551f560d-cloud-config-after-snap-seeding.patch
      - d/p/status-do-not-remove-duplicated-data.patch
      - d/p/status-retain-recoverable-error-exit-code.patch
    * Upstream snapshot based on upstream/main at 52ef4d17.
    * Upstream snapshot based on 26.1. (LP: #2146833).
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/26.1/ChangeLog

   -- Chad Smith <chad.smith@canonical.com>  Mon, 30 Mar 2026 12:56:49 -0600

distro-info-data (built from distro-info-data) updated from 0.52ubuntu0.11 to 0.72-0ubuntu0.22.04.1:

  distro-info-data (0.72-0ubuntu0.22.04.1) jammy; urgency=medium

    * New data update release
      - Add Ubuntu Legacy Support extension data (new eol-legacy column)
        (LP: #2131678)
      - Move forward the Debian bookworm EoL (hand-off to LTS)
    * Convert source package from a native package to an upstream package to
      make it easier to track differences in the data versus in the packaging.

   -- Benjamin Drung <bdrung@ubuntu.com>  Tue, 14 Jul 2026 13:29:47 +0200

  distro-info-data (0.52ubuntu0.12) jammy; urgency=medium

    * Add Ubuntu 26.10 "Stonking Stingray" (LP: #2150234)

   -- Oliver Reiche <oliver.reiche@canonical.com>  Tue, 28 Apr 2026 16:20:05 +0200

libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.13 to 2.35-0ubuntu3.14:

  glibc (2.35-0ubuntu3.14) jammy-security; urgency=medium

    * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets
      - debian/patches/CVE-2026-4046.patch: Use pending character state in
        IBM1390, IBM1399 character sets in iconvdata/Makefile,
        iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.
      - CVE-2026-4046
    * SECURITY UPDATE: out-of-bounds write in deprecated debugging function
      - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in
        ns_sprintrrf in resolv/ns_print.c.
      - CVE-2026-5435
    * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc
      - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in
        scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-
        bz34008.c, stdio-common/vfscanf-internal.c.
      - CVE-2026-5450
    * SECURITY UPDATE: crash or info disclosure in ungetwc function
      - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte
        stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.
      - CVE-2026-5928
    * SECURITY UPDATE: crash in deprecated debugging functions
      - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,
        __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.
      - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf
        formatting of class, type values in resolv/ns_print.c.
      - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of
        unknown records in ns_sprintrrf in resolv/ns_print.c.
      - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop
        failure in ns_sprintrrf in resolv/ns_print.c.
      - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in
        ns_sprintrrf in resolv/ns_print.c.
      - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-
        ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.
      - CVE-2026-6238

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 24 Jul 2026 08:11:17 -0400

libgnutls30:amd64 (built from gnutls28) updated from 3.7.3-4ubuntu1.8 to 3.7.3-4ubuntu1.9:

  gnutls28 (3.7.3-4ubuntu1.9) jammy-security; urgency=medium

    * SECURITY UPDATE: buffer overflow in DTLS handshake fragment reassembly
      - debian/patches/CVE-2026-33846-pre1.patch: buffers: shorten
        merge_handshake_packet using recv_buf in lib/buffers.c.
      - debian/patches/CVE-2026-33846.patch: buffers: add more checks to DTLS
        reassembly in lib/buffers.c.
      - CVE-2026-33846
    * SECURITY UPDATE: DTLS packets sequence number ordering issue
      - debian/patches/CVE-2026-42009-pre1.patch: buffers: match DTLS datagrams by
        sequence number in lib/buffers.c.
      - debian/patches/CVE-2026-42009-1.patch: lib/buffers: ensure packets have
        differing sequence numbers in lib/buffers.c.
      - debian/patches/CVE-2026-42009-2.patch: buffers: fix handshake_compare when
        sequence numbers match in lib/buffers.c.
      - CVE-2026-42009
    * SECURITY UPDATE: OOB read via malformed fragments with zero length and
      non-zero offset
      - debian/patches/CVE-2026-33845-pre1.patch: buffers: rename a variable in
        parse_handshake_header in lib/buffers.c.
      - debian/patches/CVE-2026-33845.patch: buffers: switch from end_offset over
        to frag_length in lib/buffers.c, lib/gnutls_int.h.
      - debian/patches/CVE-2026-33845-2.patch: buffers: simplify and tighten
        parse_handshake_header checks in lib/buffers.c.
      - CVE-2026-33845
    * SECURITY UPDATE: malformed OCSP response issue
      - debian/patches/CVE-2026-3832-pre1.patch: iterate ocsp response records
        for matching certificate in doc/examples/ex-ocsp-client.c,
        lib/cert-session.c, lib/ocsp-api.c, src/ocsptool-common.c.
      - debian/patches/CVE-2026-3832-pre2.patch: fix formatting in
        doc/examples/ex-ocsp-client.c, lib/cert-session.c, lib/ocsp-api.c,
        src/ocsptool-common.c.
      - debian/patches/CVE-2026-3832.patch: cert-session: fix multi-entry OCSP
        revocation bypass in lib/cert-session.c.
      - CVE-2026-3832
    * SECURITY UPDATE: policy bypass via x509 case-sensitive comparisons
      - debian/patches/CVE-2026-3833.patch: x509/name-constraints: compare domain
        names case-insensitive in lib/x509/name_constraints.c.
      - CVE-2026-3833
    * SECURITY UPDATE: permitted name constrains were incorrectly ignored
      - debian/patches/CVE-2026-42011.patch: x509/name_constraints: fix
        intersecting empty constraints in lib/x509/name_constraints.c.
      - CVE-2026-42011
    * SECURITY UPDATE: 
      - debian/patches/CVE-2026-42010.patch: lib/auth/rsa_psk: fix binary PSK
        identity lookup in lib/auth/rsa_psk.c.
      - CVE-2026-42010
    * SECURITY UPDATE: incorrect username parsing with NUL characters
      - debian/patches/CVE-2026-5260-1.patch: lib/auth/rsa: check that ciphertext
        matches the modulus size in lib/auth/rsa.c, lib/auth/rsa_psk.c.
      - debian/patches/CVE-2026-5260-2.patch: lib/pkcs11_privkey: guard against
        overreading on short ciphertexts in lib/pkcs11_privkey.c.
      - CVE-2026-5260
    * SECURITY UPDATE: 
      - debian/patches/CVE-2026-42012-pre1.patch: x509/hostname-verify: refactor
        and simplify CN fallback logic in lib/x509/hostname-verify.c.
      - debian/patches/CVE-2026-42012-pre2.patch: Fix for #1132 in
        lib/includes/gnutls/gnutls.h.in, lib/x509/common.h,
        lib/x509/name_constraints.c, lib/x509/output.c, lib/x509/virt-san.c,
        lib/x509/x509.c, tests/Makefile.am, tests/x509-upnconstraint.c.
      - debian/patches/CVE-2026-42012-pre3.patch: x509: add bare-bones awareness
        of SRV virtual SAN in lib/includes/gnutls/gnutls.h.in, lib/x509/common.h,
        lib/x509/name_constraints.c, lib/x509/output.c, lib/x509/virt-san.c,
        lib/x509/x509.c.
      - debian/patches/CVE-2026-42012-pre4.patch: datum, mem, str: add helper
        functions to steal pointers in lib/datum.h, lib/mem.h, lib/str.h.
      - debian/patches/CVE-2026-42012.patch: x509/hostname-verify: make URI/SRV
        SAN preclude CN fallback in lib/x509/hostname-verify.c.
      - CVE-2026-42012
    * SECURITY UPDATE: incorrect URI or SRV Subject Alternative Names checking
      - debian/patches/CVE-2026-42013-pre1.patch: x509/email-verify: call
        fallback DN fallback in lib/x509/email-verify.c.
      - debian/patches/CVE-2026-42013.patch: x509: prevent fallback on oversized
        SAN in lib/x509/email-verify.c, lib/x509/hostname-verify.c.
      - CVE-2026-42013
    * SECURITY UPDATE: UaF when changing the Security Officer PIN
      - debian/patches/CVE-2026-42014.patch: pkcs11_write: fix UAF and leak in
        gnutls_pkcs11_token_set_pin in lib/pkcs11_write.c.
      - CVE-2026-42014
    * SECURITY UPDATE: buffer overflow when appending to a PKCS#12 bag
      - debian/patches/CVE-2026-42015.patch: x509/pkcs12_bag: fix off-by-one in
        bag element bounds check in lib/x509/pkcs12_bag.c.
      - CVE-2026-42015

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 08 May 2026 14:50:04 -0400

gzip (built from gzip) updated from 1.10-4ubuntu4.1 to 1.10-4ubuntu4.2:

  gzip (1.10-4ubuntu4.2) jammy-security; urgency=medium

    * SECURITY UPDATE: insecure temp file handling
      - debian/patches/CVE-2026-41991.patch: gzexe: use -C if lacking mktemp in
        gzexe.in, zdiff.in.
      - CVE-2026-41991
    * SECURITY UPDATE: overflow in LZH decompression logic
      - debian/patches/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z
        in unlzh.c.
      - CVE-2026-41992

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 03 Jul 2026 07:55:53 -0400

iproute2 (built from iproute2) updated from 5.15.0-1ubuntu2 to 5.15.0-1ubuntu2.2:

  iproute2 (5.15.0-1ubuntu2.2) jammy; urgency=medium

    * Modify tc/tbf and tc/htb to allow 64 bit burst parameter (LP: #2147525)
      - /d/p/lp2147525-1-tc-tbf-enable-64-bit-burst.patch
      - /d/p/lp2147525-2-tc-htb-enable-64-bit-burst.patch

   -- Ioana Lazea <ioana.lazea@canonical.com>  Wed, 15 Apr 2026 10:15:26 +0300

  iproute2 (5.15.0-1ubuntu2.1) jammy; urgency=medium

    * Modify tc police to permit burst sizes up greater than 4GB (LP: #2125448)
      - /d/p/2001-lib-Update-backend-of-print_size-to-accept-64-bit-si.patch
      - /d/p/2002-tc-Add-get_size64-and-get_size64_and_cell.patch
      - /d/p/2003-tc-Expand-tc_calc_xmittime-tc_calc_xmitsize-to-u64.patch
      - /d/p/2004-tc-police-enable-use-of-64-bit-burst-parameter.patch 

   -- Jorge Merlino <jorge.merlino@canonical.com>  Fri, 03 Oct 2025 10:53:16 -0300

kmod, libkmod2:amd64 (built from kmod) updated from 29-1ubuntu1 to 29-1ubuntu1.1:

  kmod (29-1ubuntu1.1) jammy-security; urgency=medium

    * Disable loading of algif_aead module to mitigate CVE-2026-31431
      (LP: #2150743)
      - debian/modprobe.d/disable-algif_aead.conf

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 30 Apr 2026 08:32:42 -0400

libgssapi-krb5-2:amd64, libk5crypto3:amd64, libkrb5-3:amd64, libkrb5support0:amd64 (built from krb5) updated from 1.19.2-2ubuntu0.7 to 1.19.2-2ubuntu0.8:

  krb5 (1.19.2-2ubuntu0.8) jammy-security; urgency=medium

    * SECURITY UPDATE: nteger underflow berval2tl_data()
      - debian/patches/CVE-2026-11850.patch: Prevent read overrun in libkdb_ldap
        in src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c.
      - CVE-2026-11850
    * SECURITY UPDATE: security issues in the NegoEx mechanism
      - debian/patches/CVE-2026-4035x.patch: Fix two NegoEx parsing
        vulnerabilities in src/lib/gssapi/spnego/negoex_util.c.
      - CVE-2026-40355
      - CVE-2026-40356

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 15 Jul 2026 14:26:34 -0400

libcap2-bin, libcap2:amd64 (built from libcap2) updated from 1:2.44-1ubuntu0.22.04.2 to 1:2.44-1ubuntu0.22.04.3:

  libcap2 (1:2.44-1ubuntu0.22.04.3) jammy-security; urgency=medium

    * SECURITY UPDATE: potential TOCTOU race condition in cap_set_file()
      - debian/patches/CVE-2026-4878.patch: fix race in libcap/cap_file.c,
        progs/quicktest.sh.
      - CVE-2026-4878

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 09 Apr 2026 11:04:48 -0400

libgcrypt20:amd64 (built from libgcrypt20) updated from 1.9.4-3ubuntu3 to 1.9.4-3ubuntu3.2:

  libgcrypt20 (1.9.4-3ubuntu3.2) jammy-security; urgency=medium

    * SECURITY UPDATE: Heap-based buffer overflow via crafted ECDH ciphertext
      - debian/patches/CVE-2026-41989.patch: cipher:ecc: Fix decoding a point on
        Montgomery curve. in cipher/ecc-misc.c.
      - CVE-2026-41989
    * This package does _not_ contain the changes from 1.9.4-3ubuntu3.1 in
      jammy-proposed.

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 12 May 2026 14:17:54 +0200

libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3ubuntu0.4 to 1.6.37-3ubuntu0.6:

  libpng1.6 (1.6.37-3ubuntu0.6) jammy-security; urgency=medium

    * SECURITY UPDATE: Interpretation conflict in APNG parser
      paths.
      - debian/patches/CVE-2026-40930.patch: Restructure the trailing-fdAT
        path in pngpread.c
      - debian/patches/CVE-2026-40930-post1.patch: Fix hardcoded length in
        png_ensure_sequence_number in pngpread.c
      - CVE-2026-40930

   -- Kyle Kernick <kyle.kernick@canonical.com>  Thu, 13 Aug 2026 10:20:26 -0600

  libpng1.6 (1.6.37-3ubuntu0.5) jammy-security; urgency=medium

    * SECURITY UPDATE: use-after-free via shared buffers
      - debian/patches/CVE-2026-33416-pre1.patch: Fix a memory leak in
        png_set_tRNS in pngset.c.
      - debian/patches/CVE-2026-33416-pre2.patch: Avoid a memory leak when
        allocation of a pCAL buffer fails in pngset.c.
      - debian/patches/CVE-2026-33416-1.patch: fix: Resolve use-after-free on
        `png_ptr->trans_alpha` in pngread.c, pngrutil.c, pngset.c, pngwrite.c.
      - debian/patches/CVE-2026-33416-2.patch: fix: Resolve use-after-free on
        `png_ptr->palette` in pngread.c, pngrtran.c, pngrutil.c, pngset.c,
        pngwrite.c.
      - debian/patches/CVE-2026-33416-3.patch: fix: Initialize tail bytes in
        `trans_alpha` buffers in pngset.c.
      - debian/patches/CVE-2026-33416-4.patch: fix: Sync `info_ptr->palette` after
        in-place transforms in pngrtran.c.
      - debian/patches/CVE-2026-33416-5.patch: fix: Sync `info_ptr->palette`
        unconditionally after in-place transforms in pngrtran.c.
      - CVE-2026-33416
    * SECURITY UPDATE: out-of-bounds access in ARM palette expansion path
      - debian/patches/CVE-2026-33636.patch: fix(arm): Resolve out-of-bounds
        read/write in NEON palette expansion in arm/palette_neon_intrinsics.c.
      - CVE-2026-33636
    * SECURITY UPDATE: getter-to-setter aliasing issues
      - debian/patches/CVE-2026-34757-1.patch: fix: Handle self-referencing
        pointers in getter-to-setter aliasing in CMakeLists.txt, Makefile.am,
        contrib/libtests/pnggetset.c, pngset.c, tests/pnggetset.
      - debian/patches/CVE-2026-34757-2.patch: fix: Handle getter-to-setter
        aliasing in append-style chunk setters in contrib/libtests/pnggetset.c,
        pngset.c.
      - debian/rules: set exec permissions on tests/pnggetset.
      - CVE-2026-34757
    * SECURITY UPDATE: integer overflow in rowbytes computation
      - debian/patches/rowbytes_overflow.patch: fix: Prevent integer overflow in
        rowbytes computation in pngrtran.c.
      - No CVE number

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 05 May 2026 15:14:16 -0400

libncurses6:amd64, libncursesw6:amd64, libtinfo6:amd64, ncurses-base, ncurses-bin (built from ncurses) updated from 6.3-2ubuntu0.1 to 6.3-2ubuntu0.2:

  ncurses (6.3-2ubuntu0.2) jammy-security; urgency=medium

    * SECURITY UPDATE: stack-based buffer overflow in infocmp
      - debian/patches/CVE-2025-69720.patch: clamp length to
        MAX_TERMINFO_LENGTH before copying into buf2 in analyze_string.
      - CVE-2025-69720

   -- Paulo Flabiano Smorigo <pfsmorigo@canonical.com>  Tue, 30 Jun 2026 21:25:30 +0000

libnetplan0:amd64, netplan.io (built from netplan.io) updated from 0.106.1-7ubuntu0.22.04.4 to 0.107.1-3ubuntu0.22.04.4:

  netplan.io (0.107.1-3ubuntu0.22.04.4) jammy; urgency=medium

    * d/p/lp2076319-fix-dir-permissions.patch:
      Change default umask when creating dirctories (LP: #2076319)

   -- Robert Malz <robert.malz@canonical.com>  Wed, 23 Apr 2026 14:17:38 +0100

  netplan.io (0.107.1-3ubuntu0.22.04.3) jammy; urgency=medium

    * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:
      execute udev rules before starting sriov apply service (LP: #2139598)

   -- Robert Malz <robert.malz@canonical.com>  Tue, 03 Mar 2026 12:18:29 +0100

  netplan.io (0.107.1-3ubuntu0.22.04.2) jammy; urgency=medium

    * debian/patches/lp1988018: VF-LAG activation
      Fixes the order in which SR-IOV configuration is performed and
      cooperates with VF-LAG activation (LP: #1988018).
    * debian/patches/lp2020409:
      Enables setting the embedded-switch mode without having to define
      virtual functions (LP: #2020409).
    * debian/libnetplan0.symbols: New symbol _netplan_netdef_get_bond_mode.

   -- Danilo Egea Gondolfo <danilo.egea.gondolfo@canonical.com>  Mon, 07 Oct 2024 10:57:38 +0100

  netplan.io (0.107.1-3ubuntu0.22.04.1) jammy; urgency=medium

    * Backport netplan.io 0.107.1-3 to 22.04 (LP: #2058031):
      - Support for "dummy" (`dummy-devices`) interfaces (LP: 1774203) (!361)
      - Support for "veth" (`virtual-ethernets`) interfaces (!368)
      - Add Python bindings for libnetplan (!385)
      - netplan: Handle command exceptions (!334)
      - WPA3 (personal) support (LP: 2023238) (!369)
      - Add all the commands to the bash completion file (LP: 1749869) (!326)
      - New submodule for state manipulation (!379)
      - commands/status: show routes from all routing tables (!390)
      - cli:status: Make rich pretty printing optional (!388)
      - libnetplan: expose dhcp4 and dhcp6 properties (!394)
      - Expose macaddress and DNS configuration from the netdef (!395)
      - libnetplan: expose the routes list in the netdef (!397)
      - NetworkManager: Wireguard private key flag support (!371)
      - Add a netplan_parser_load_keyfile() Python binding (!351)
      - keyfile parser: add support for all tunnel types (LP: 2016473) (!360)
      - parse-nm:wg: add support for reading the listen-port property (!372)
      - parse-nm: add support for VRF devices (!398)
      - Vlan keyfile parser support (!370)
      - Netplan docs rework (!333 & !337)
      - docs: Add a short netplan-everywhere howto (!325)
      - doc: make us of sphinx copybutton plugin (!354)
      - doc: Add Ubuntu Code of Conduct 2.0 (!355)
      - doc: Explanation about 00-network-manager-all.yaml (!378)
      - wifi: add support for WPA3-Enterprise (LP: 2029876) (!402)
      - wifi: support WPA2 and WPA3 Personal simultaneously (!404)
      - added mii-monitor-interval example (!411)
      - docs: Add "Contribute Documentation" how-to
      - auth: add support for LEAP and EAP-PWD (!415)
      - tests: Add autopkgtest for (LP: 1959570) (!419)
      - wifi: make it possible to have a psk and an eap password simultaneously
        (!416)
      - doc: Set-up some basic Doxygen project (!423)
      - doc: Make Sphinx to handle autodoxygen project, using breathe (!423)
      - doc: create libnetplan apidoc structure (!423)
      - inc: Start documenting public API (!423)
      - doc: Update 'Netplan everywhere' for 23.10 (!418)
      SECURITY UPDATE: weak permissions on secret files, command injection
      - d/p/lp2065738/0014-libnetplan-use-more-restrictive-file-permissions.patch:
        Use more restrictive file permissions to prevent unprivileged users to
        read sensitive data from back end files (LP: 2065738, 1987842)
      - CVE-2022-4968
      - d/p/lp2066258/0015-libnetplan-escape-control-characters.patch:
        Escape control characters in the parser and double quotes in backend
        files.
      - d/p/lp2066258/0016-backends-escape-file-paths.patch:
        Escape special characters in file paths.
      - d/p/lp2066258/0017-backends-escape-semicolons-in-service-units.patch:
        Escape isolated semicolons in systemd service units. (LP: 2066258)
      - debian/netplan-generator.postinst: Add a postinst maintainer script to
        call the generator. It's needed so the file permissions fixes will be
        applied automatically.
      Bug fixes:
      - Fix FTBFS on Fedora and refresh RPM packaging (!323)
      - parser: validate lacp-rate properly (LP: 1745648) (!324)
      - use meson-make-symlink.sh helper instead of install_symlink() (!327)
      - netplan: cli: fix typo from 'unkown' to 'unknown' (!328)
      - Handle duplication during parser second pass (LP: 2007682) (!329)
      - parse:ovs: Ignore deprecated OpenFlow1.6 protocol (LP: 1963735) (!332)
      - dbus: Build the copy path correctly (!331)
      - tests: add new spread based snapd integration test (!330)
      - Use controlled execution environment, to avoid failure if PATH is unset
        (LP: 1959570) (!336)
      - Some refactoring (!338)
      - netplan: adjust the maximum buffer size to 1MB (!340)
      - parse: use "--" with systemd-escape (!347)
      - docs: fix bridge parameters types and add examples (!346)
      - vrfs: skip policies parsing if list is NULL (LP: 2016427) (!341)
      - networkd: plug a memory leak (!344)
      - libnetplan: don't try to read from a NULL file (!342)
      - nm: return if write_routes() fails (!345)
      - parse: plug a memory leak (!348)
      - parse: set the backend on nm-devices to NM (!349)
      - parse: don't point to the wrong node on validation (!343)
      - rtd: set the OS and Python versions explicitly (!357)
      - Fix 8021x eap method parsing (LP: 2016625) (!358)
      - CI: update canonical/setup-lxd to v0.1.1 (!359)
      - CI: fix dch after adding the new 0.106.1 tag (!364)
      - Provide frequency to wpa_supplicant in adhoc mode (LP: 2020754) (!363)
      - Improve the coverage of the memory leak tests (!365)
      - Fix keyfile parsing of wireguard config (!366)
      - routes: fix metric rendering (LP: 2023681) (!367)
      - CI: add DebCI integration test (!362)
      - CI: initial NetworkManager autopkgtests (!374)
      - parse-nm: handle cloned-mac-address special cases (LP: 2026230) (!376)
      - Improve autopkgtest stability with systemd 253 & iproute 6.4 (!377)
      - Fixes for minor issues (!380)
      - tests:integration: Adopt for systemd v254 (Closes: #1041310) (!381)
      - parse: Downgrade NM passthrough warning to debug (!384)
      - Don't drop files with just global values (LP: 2027584) (!382)
      - Fixing Coverity issues (!383)
      - CLI: Refactoring to avoid namespace clash with public bindings (!387)
      - tests: fix test coverage report with newer python-coverage (!389)
      - github: add a scheduled action to run Coverity (!391)
      - github: only run the coverity workflow on our repository (!392)
      - Addressing a few issues found (!393)
      - Wireguard fixes (!352)
      - Fix a memory leak, an assert and an error message (!350)
      - ovs: don't allow peers with the same name (!353)
      - CI: make use of the canonical/setup-lxd action (!356)
      - test:ovs: Avoid NetworkManager taking contol, breaking a test
      - parse: allow COMMON_LINK_HANDLERS for VRFs (!401)
      - util: don't return a placeholder netdef in the iterator (!406)
      - tunnels/validation: do not error out if "local" is not defined (!407)
      - tests: add some integration tests without the local address (!407)
      - wireguard: ignore empty endpoints (LP: 2038811) (!414)
      - parse: improve the parsing of access-points (LP: 1809994) (!413)
      - wifi: replace the previously defined AP with the new one (!413)
      - doc: spelling check improvements (!417)
      - Fix permissions on folder '/run/NetworkManager/' (!422)
      - cli:try: avoid linting error for type hints (Closes: #1058524) (!422)
      - nm-parse: always read the PSK into the new psk variable (!416)
      - networkd: fix formatting (!424)
      - networkd: replace deprecated CriticalConnection= by KeepConfiguration=
        (!424)
      - networkd: move KeepConfiguration= into [Network] section
      - apply: bring "lo" back up if it's managed by NM (!408)
      - apply: don't assume the NM loopback connection is called "lo" (!408)
      Packaging restructuring:
      - Split netplan-generator into separate package to make the Python
        dependency optional.
      - Split python3-netplan bindings into a separate package
    * Add patches for bug fixes from netplan.io 1.0-1 and 1.0.1-1:
      - debian/patches/lp2041727:
        Check if ovsdb-server.service is active before displaying warning
        (LP: 2041727) (!421)
      - d/p/0004-tests-assert-generated-.service-files-in-assert_srio.patch,
        d/p/0005-tests-sriov-test-if-the-generated-netplan-rebind-ser.patch,
        d/p/0006-sriov-don-t-generate-duplicate-entries-in-the-rebind.patch:
        Don't generate duplicate entries in the netplan-sriov-rebind.service
        (!437)
      - d/p/0017-emitter-allow-unicode-characters-in-the-emitter.patch.
        Allow non-ascii characters in the YAML emitter (LP: 2071652) (!485).
      - d/p/0018-parse-do-not-escape-all-non-ascii-bytes.patch.
        Don't escape all non-ascii bytes (!486).
    * Drop patches not required for 22.04:
      - debian/patches/python-limited-stable-api.patch
      - d/p/sru-compat/0013-Keep-old-file-permission-for-backwards-compatibility.patch.
        From now on we want libnetplan to create files with tight permissions.
    * Add patches for SRU backwards compatibility:
      - 0014-Demote-lacp-rate-validation-error-to-warning-for-bac.patch:
        Convert the error to a warning in a new validation for the option
        'lacp-rate' to prevent breaking existing setups
    * debian/control:
      - Drop python3-rich dependency to Suggests
      - Drop build dependency on systemd-dev
    * debian/netplan.io.preinst:
      - This preinst script is intended to cleanup the .pyc files from
        share/netplan/netplan. This directory is supposed to be removed after
        the upgrade from netplan.io 0.106.1 to 0.107.1, as the Python code
        was moved to it's own python3-netplan package, but it's left behind
        due to Python cached files.
    * Drop changes related to usr-merge and not required for 22.04
      - debian/netplan-generator.install
      - debian/netplan-generator.dirs
      - debian/netplan-generator.postinst
      - debian/netplan-generator.preinst
    * d/netplan-generator.lintian-overrides, d/netplan.io.lintian-overrides:
      - Drop overrides file. It wasn't really silencing any lintian warnings.

   -- Danilo Egea Gondolfo <danilo.egea.gondolfo@canonical.com>  Fri, 16 Aug 2024 17:59:32 +0100

openssh-client, openssh-server, openssh-sftp-server (built from openssh) updated from 1:8.9p1-3ubuntu0.14 to 1:8.9p1-3ubuntu0.16:

  openssh (1:8.9p1-3ubuntu0.16) jammy-security; urgency=medium

    * SECURITY UPDATE: sftp downloaded files location issue
      - debian/patches/CVE-2026-59995.patch: upstream: avoid download to server-
        controlled path when performing in sftp.c.
      - CVE-2026-59995
    * SECURITY UPDATE: scp parent directory issue
      - debian/patches/CVE-2026-59996.patch: upstream: resist that return ".." via
        remote glob during in scp.c.
      - CVE-2026-59996
    * SECURITY UPDATE: internal-sftp ignores more than 9 commandline args
      - debian/patches/CVE-2026-59997.patch: upstream: pass >9 commandline
        arguments to the internal-sftp server, in session.c.
      - CVE-2026-59997
    * SECURITY UPDATE: undocumented GSSAPIStrictAcceptorCheck behaviour
      - debian/patches/CVE-2026-59998.patch: upstream: mention a caveat regarding
        GSSAPIStrictAcceptorCheck in in sshd_config.5.
      - CVE-2026-59998
    * SECURITY UPDATE: DisableForwarding=yes not taking proper precedence
      - debian/patches/CVE-2026-59999.patch: upstream: DisableForwarding=yes
        didn't override PermitTunnel=yes in serverloop.c.
      - CVE-2026-59999
    * SECURITY UPDATE: DoS via MaxAuthTries mishandling
      - debian/patches/CVE-2026-60000-1.patch: upstream: Fix multiple RFC 4462
        (GSSAPIAuthentication) compliance in auth2-gss.c.
      - debian/patches/CVE-2026-60000-2.patch: upstream: unused variables in
        auth2-gss.c.
      - CVE-2026-60000
    * SECURITY UPDATE: minimum authentication delay not always honoured
      - debian/patches/CVE-2026-60001.patch: upstream: Fix cases in GSSAPI and
        keyboard-interactive in auth.h, auth2-chall.c, auth2-gss.c, auth2.c.
      - CVE-2026-60001
    * SECURITY UPDATE: Use-after-free during a key re-exchange
      - debian/patches/CVE-2026-60002.patch: upstream: fix ownership and lifetime
        of several bits of client in ssh.c, sshconnect.c, sshconnect.h,
        sshconnect2.c.
      - CVE-2026-60002

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 09 Jul 2026 14:38:00 -0400

  openssh (1:8.9p1-3ubuntu0.15) jammy-security; urgency=medium

    * SECURITY UPDATE: unexpected scp setuid and setgid
      - debian/patches/CVE-2026-35385.patch: clear setuid/setgid bits from
        downloaded files in scp.c.
      - CVE-2026-35385
    * SECURITY UPDATE: command execution via shell metacharacters in username
      - debian/patches/CVE-2026-35386-pre1.patch: apply validity rules on
        ProxyJump usernames and hostnames in readconf.c, readconf.h, ssh.c.
      - debian/patches/CVE-2026-35386.patch: move username check earlier in
        ssh.c.
      - CVE-2026-35386
    * SECURITY UPDATE: use of unintended ECDSA algorithms
      - debian/patches/CVE-2026-35387_35414.patch: correctly match ECDSA
        signature algorithms against algorithm allowlists in
        auth2-hostbased.c, auth2-pubkey.c, sshconnect2.c.
      - CVE-2026-35387
    * SECURITY UPDATE: missing connection multiplexing confirmation
      - debian/patches/CVE-2026-35388.patch: add missing askpass check in
        mux.c.
      - CVE-2026-35388
    * SECURITY UPDATE: authorized_keys principals option mishandling
      - debian/patches/CVE-2026-35387_35414.patch: check for commas in
        auth2-pubkey.c.
      - CVE-2026-35414

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 27 Apr 2026 20:38:10 -0400

libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.23 to 3.0.2-0ubuntu1.26:

  openssl (3.0.2-0ubuntu1.26) jammy-security; urgency=medium

    * SECURITY UPDATE: HollowByte Denial of Service issue (LP: #2161371)
      - debian/patches/lp2161371.patch: Grow the init_buf incrementally as we
        receive data in ssl/statem/statem.c, ssl/statem/statem_lib.c.
      - No CVE number

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 29 Jul 2026 12:56:04 -0400

  openssl (3.0.2-0ubuntu1.25) jammy-security; urgency=medium

    * SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing
      - debian/patches/CVE-2026-34180.patch: Avoid length truncation in
        ASN1_STRING_set in crypto/asn1/tasn_dec.c.
      - CVE-2026-34180
    * SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages
      - debian/patches/CVE-2026-34182-pre1.patch: Ensure
        ossl_cms_EncryptedContent_init_bio() reports an error on no OID in
        crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt,
        include/openssl/cmserr.h.
      - debian/patches/CVE-2026-34182-1.patch: CMS: Produce error when AEAD
        algorithms are used in enveloped data in crypto/cms/cms_enc.c,
        crypto/cms/cms_env.c, crypto/cms/cms_err.c, crypto/cms/cms_local.h,
        crypto/err/openssl.txt, include/openssl/cmserr.h, test/cms-msg/enveloped-
        content-type-for-aes-gcm.pem, test/cmsapitest.c,
        test/recipes/80-test_cms.t.
      - debian/patches/CVE-2026-34182-2.patch: Reject potentially forged encrypted
        CMS AuthEnvelopedData messages in crypto/cms/cms_enc.c.
      - debian/patches/CVE-2026-34182-3.patch: Add tests for CVE-2026-34182 in
        test/cmsapitest.c.
      - CVE-2026-34182
    * SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption
      - debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference
        processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c.
      - CVE-2026-42766
    * SECURITY UPDATE: NULL Pointer Dereference in CRMF EncryptedValue Decryption
      - debian/patches/CVE-2026-42767.patch: Fix potential NULL dereference in
        OSSL_CRMF_ENCRYPTEDVALUE_decrypt() in crypto/crmf/crmf_lib.c.
      - CVE-2026-42767
    * SECURITY UPDATE: FFC-DH Peer Validation Uses Attacker-Supplied q
      - debian/patches/CVE-2026-42770.patch: Match the local q DHX parameter
        against the peer's q in providers/implementations/exchange/dh_exch.c.
      - CVE-2026-42770
    * SECURITY UPDATE: AES-OCB IV Ignored on EVP_Cipher() Path
      - debian/patches/CVE-2026-45445.patch: Apply the buffered IV on the AES-OCB
        EVP_Cipher() path in providers/implementations/ciphers/cipher_aes_ocb.c,
        test/evp_extra_test.c.
      - CVE-2026-45445
    * SECURITY UPDATE: Incorrect Tag Processing for Empty Messages in
      AES-GCM-SIV and AES-SIV modes
      - debian/patches/CVE-2026-45446.patch: Fix handling of empty-ciphertext
        messages in AES-SIV in providers/implementations/ciphers/cipher_aes_siv.c,
        test/evp_extra_test.c.
      - CVE-2026-45446
    * SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify()
      - debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary
        PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c.
      - debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in
        OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c.
      - debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in
        PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty-
        digest-set.eml.
      - CVE-2026-45447
    * SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String
      Conversion
      - debian/patches/CVE-2026-7383.patch: Reject oversized inputs in
        ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c.
      - CVE-2026-7383
    * SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption
      - debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds
        read in check-byte validation in crypto/cms/cms_pwri.c.
      - CVE-2026-9076

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 02 Jun 2026 15:33:25 -0400

libpam-modules-bin, libpam-modules:amd64, libpam-runtime, libpam0g:amd64 (built from pam) updated from 1.4.0-11ubuntu2.6 to 1.4.0-11ubuntu2.7:

  pam (1.4.0-11ubuntu2.7) jammy-security; urgency=medium

    * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb
      module string comparisons
      - debian/patches/CVE-2026-54411-pre1.patch: libpam: add helper to compare
        strings in constant time in libpam/include/pam_inline.h.
      - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison
        timing leak in libpam/include/pam_inline.h,
        modules/pam_userdb/pam_userdb.c.
      - CVE-2026-54411

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 16 Jul 2026 10:06:00 -0400

perl-base (built from perl) updated from 5.34.0-3ubuntu1.5 to 5.34.0-3ubuntu1.7:

  perl (5.34.0-3ubuntu1.7) jammy-security; urgency=high

    * SECURITY UPDATE: integer overflow in regular expression compiler
      - debian/patches/CVE-2026-8376_1.patch: accept quantifier limit error
        on 32-bit architectures where the quantifier limit catches the
        oversized pattern before the overflow guard
      - CVE-2026-8376

   -- Chrisa Oikonomou <chrisa.oikonomou@canonical.com>  Mon, 23 Jun 2026 11:11:00 +0300

  perl (5.34.0-3ubuntu1.6) jammy-security; urgency=high

    * SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction
      - debian/patches/CVE-2026-42496.patch: validate symlink and hardlink
        targets against absolute paths and directory traversal in
        cpan/Archive-Tar/lib/Archive/Tar.pm
      - CVE-2026-42496
    * SECURITY UPDATE: integer overflow in regular expression compiler
      - debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer
        overflow via quantified fixed-string regex in t/re/pat_psycho.t
      - debian/patches/CVE-2026-8376_2.patch: add overflow check before
        fixed-string buffer allocation in regcomp.c / regcomp_study.c
      - CVE-2026-8376

   -- Chrisa Oikonomou <chrisa.oikonomou@canonical.com>  Fri, 12 Jun 2026 16:42:26 +0300

libpolkit-agent-1-0:amd64, libpolkit-gobject-1-0:amd64, polkitd (built from policykit-1) updated from 0.105-33 to 0.105-33ubuntu0.1:

  policykit-1 (0.105-33ubuntu0.1) jammy-security; urgency=medium

    * SECURITY UPDATE: OOB write via nested elements in XML policy
      - debian/patches/CVE-2025-7519.patch: check depth in
        src/polkitbackend/polkitbackendactionpool.c.
      - CVE-2025-7519
    * SECURITY UPDATE: DoS via excessively long input
      - debian/patches/CVE-2026-4897.patch: fix getline() string overflow in
        src/polkitagent/polkitagenthelperprivate.c.
      - CVE-2026-4897

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 10 Apr 2026 06:59:20 -0400

python3-idna (built from python-idna) updated from 3.3-1ubuntu0.1 to 3.3-1ubuntu0.2:

  python-idna (3.3-1ubuntu0.2) jammy-security; urgency=medium

    * SECURITY UPDATE: DoS via specially crafted inputs to idna.encode()
      - debian/patches/CVE-2026-45409-1.patch: Reject oversized inputs up-front in
        idna/core.py, tests/test_idna.py.
      - debian/patches/CVE-2026-45409-2.patch: Use valid_string_length() for early
        oversized-input check in idna/core.py.
      - debian/patches/CVE-2026-45409-3.patch: Enforce early length limits in
        check_label in idna/core.py, tests/test_idna.py.
      - CVE-2026-45409

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 14 Jul 2026 13:21:34 -0400

python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.6 to 1.26.5-1~exp1ubuntu0.7:

  python-urllib3 (1.26.5-1~exp1ubuntu0.7) jammy-security; urgency=medium

    * SECURITY UPDATE: sensitive headers not stripped in cross-origin redirects
      - debian/patches/CVE-2026-44431.patch: remove sensitive headers in proxy
        pools too in src/urllib3/connectionpool.py,
        test/with_dummyserver/test_proxy_poolmanager.py.
      - CVE-2026-44431

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 22 May 2026 16:41:35 -0400

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.15 to 3.10.12-1~22.04.16:

  python3.10 (3.10.12-1~22.04.16) jammy-security; urgency=medium

    * SECURITY UPDATE: incorrect normalization in tarfile module
      - debian/patches/CVE-2025-13462.patch: Skip TarInfo DIRTYPE normalization
        during GNU long name handling in Lib/tarfile.py,
        Lib/test/test_tarfile.py.
      - CVE-2025-13462
    * SECURITY UPDATE: crash in Markdown parsing
      - debian/patches/CVE-2025-69534-1.patch: Fix comment parsing in HTMLParser
        according to the HTML5 standard in Lib/html/parser.py,
        Lib/test/test_htmlparser.py.
      - debian/patches/CVE-2025-69534-2.patch: Fix parsing start and end tags in
        HTMLParser according to the HTML5 standard in Lib/html/parser.py,
        Lib/test/support/__init__.py, Lib/test/test_htmlparser.py.
      - debian/patches/CVE-2025-69534-3.patch: Fix parsing attributes with
        whitespaces around the "=" separator in HTMLParser in Lib/html/parser.py,
        Lib/test/test_htmlparser.py.
      - debian/patches/CVE-2025-69534-4.patch: Fix support of elements "textarea"
        and "title" in HTMLParser in Lib/html/parser.py,
        Lib/test/test_htmlparser.py.
      - debian/patches/CVE-2025-69534-5.patch: Fix CDATA section parsing in
        HTMLParser in Lib/html/parser.py, Lib/test/test_htmlparser.py.
      - debian/patches/CVE-2025-69534-6.patch: Support more RAWTEXT and PLAINTEXT
        elements in HTMLParser in Doc/library/html.parser.rst, Lib/html/parser.py,
        Lib/test/test_htmlparser.py.
      - CVE-2025-69534
    * SECURITY UPDATE: incorrect newlines quoting in email module
      - debian/patches/CVE-2026-1299.patch: email: verify headers are sound in
        BytesGenerator in Lib/email/generator.py,
        Lib/test/test_email/test_generator.py, Lib/test/test_email/test_policy.py.
      - CVE-2026-1299
    * SECURITY UPDATE:HTTP proxy via "CONNECT" tunneling doesn't sanitize CR/LF
      - debian/patches/CVE-2026-1502.patch: Reject CR/LF in HTTP tunnel request
        headers in Lib/http/client.py, Lib/test/test_httplib.py.
      - CVE-2026-1502
    * SECURITY UPDATE: missing audit event for legacy *.pyc files
      - debian/patches/CVE-2026-2297.patch: Ensure SourcelessFileLoader uses
        io.open_code in Lib/importlib/_bootstrap_external.py.
      - CVE-2026-2297
    * SECURITY UPDATE: unicodedata.normalize() can take excessive CPU time
      - debian/patches/CVE-2026-3276.patch: Fix O(n^2) canonical ordering in
        unicodedata.normalize() in Lib/test/test_unicodedata.py,
        Modules/unicodedata.c.
      - CVE-2026-3276
    * SECURITY UPDATE: Incomplete fix for CVE-2026-0672
      - debian/patches/CVE-2026-3644.patch: Reject control characters in
        http.cookies.Morsel.update() in Lib/http/cookies.py,
        Lib/test/test_http_cookies.py.
      - CVE-2026-3644
    * SECURITY UPDATE: Overflow in Expat parser
      - debian/patches/CVE-2026-4224.patch: Avoid unbound C recursion in
        conv_content_model in pyexpat.c in Lib/test/test_pyexpat.py,
        Modules/pyexpat.c.
      - CVE-2026-4224
    * SECURITY UPDATE: leading dashes used as options in webbrowser.open()
      - debian/patches/CVE-2026-4519-1.patch: Reject leading dashes in webbrowser
        URLs in Lib/test/test_webbrowser.py, Lib/webbrowser.py.
      - debian/patches/CVE-2026-4519-2.patch: Tweak the exception message and
        increase test coverage in Lib/test/test_webbrowser.py, Lib/webbrowser.py.
      - CVE-2026-4519
    * SECURITY UPDATE: Mitgation of CVE-2026-4519 was incomplete
      - debian/patches/CVE-2026-4786.patch: Fix webbrowser `%action` substitution
        bypass of dash-prefix check in Lib/test/test_webbrowser.py,
        Lib/webbrowser.py.
      - CVE-2026-4786
    * SECURITY UPDATE: insufficient escaping in http.cookies.Morsel.js_output()
      - debian/patches/CVE-2026-6019-1.patch: Base64-encode cookie values
        embedded in JS in Lib/http/cookies.py, Lib/test/test_http_cookies.py.
      - debian/patches/CVE-2026-6019-2.patch: Use `decodeURIComponent()` for
        UTF-8 support in `js_output()` in Lib/http/cookies.py,
        Lib/test/test_http_cookies.py.
      - CVE-2026-6019
    * SECURITY UPDATE: use-after-free in lzma, bz2, gzip decoders
      - debian/patches/CVE-2026-6100.patch: Fix a possible UAF in
        `{LZMA,BZ2,_Zlib}Decompressor` in Modules/_bz2module.c,
        Modules/_lzmamodule.c.
      - CVE-2026-6100
    * SECURITY UPDATE: Incomplete fix for CVE-2021-4189
      - debian/patches/CVE-2026-8328.patch: Apply CVE-2021-4189 PASV fix to
        ftplib.ftpcp() (GH-149648) (#149795) in Lib/ftplib.py,
        Lib/test/test_ftplib.py.
      - CVE-2026-8328
    * SECURITY UPDATE: bz2.BZ2Decompressor object reuse after decompression error
      - debian/patches/CVE-2026-9669.patch: Prevent bz2 decompressor reuse after
        errors in Lib/test/test_bz2.py, Modules/_bz2module.c.
      - CVE-2026-9669

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 22 Jun 2026 14:55:27 -0400

sed (built from sed) updated from 4.8-1ubuntu2 to 4.8-1ubuntu2.1:

  sed (4.8-1ubuntu2.1) jammy-security; urgency=medium

    * SECURITY UPDATE: TOCTOU race in sed -i --follow-symlinks
      - debian/patches/CVE-2026-5958.patch: open the already-resolved path
        instead of re-traversing the symlink in sed/execute.c.
      - CVE-2026-5958

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 17 Apr 2026 14:02:54 -0400

libsqlite3-0:amd64 (built from sqlite3) updated from 3.37.2-2ubuntu0.5 to 3.37.2-2ubuntu0.7:

  sqlite3 (3.37.2-2ubuntu0.7) jammy-security; urgency=medium

    * SECURITY UPDATE: NULL pointer dereference in the SQLite Session Extension
      - debian/patches/CVE-2026-50812.patch: Fix a bug causing the session module
        to dereference a NULL pointer when applying a corrupt changeset. in
        ext/session/session9.test, ext/session/sqlite3session.c.
      - CVE-2026-50812
    * SECURITY UPDATE: sensitive information disclosure via the Session Extension
      - debian/patches/CVE-2026-50813.patch: Fix a buffer overread in the session
        module that could occur when processing a corrupt changeset. in
        ext/session/sessionC.test, ext/session/sqlite3session.c.
      - CVE-2026-50813

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 16 Jul 2026 13:13:10 -0400

  sqlite3 (3.37.2-2ubuntu0.6) jammy-security; urgency=medium

    * SECURITY UPDATE: security issues in FTS5 full-text search
      - debian/patches/CVE-2026-11822_4.patch: Fix logic in ext/fts5/fts5_index.c.
      - CVE-2026-11822
      - CVE-2026-11824

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 16 Jun 2026 13:53:33 -0400

libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.20 to 249.11-0ubuntu3.22:

  systemd (249.11-0ubuntu3.22) jammy-security; urgency=medium

    * SECURITY UPDATE: systemd: crash triggered by unprivileged users in various
      components via Varlink
      - GHSA-5rm9-cc37-35gq.patch
      - GHSA-5rm9-cc37-35gq
    * SECURITY UPDATE: udev: local root execution via malicious iscsi devices
      and unsanitized kernel output
      - GHSA-m8q3-73v4-wvg7.patch
      - GHSA-m8q3-73v4-wvg7
    * SECURITY UPDATE: crash triggered by unprivileged users in various
      components via D-Bus/Varlink
      - basic-strv-add-optimizable-version-of-strv_push-consume-e.patch
      - core-limit-the-number-of-units-that-can-be-requested-over.patch
      - dbus-limit-the-number-of-env-variables-to-something-reaso.patch
      - dbus-manager-limit-the-number-of-states-patterns-per-quer.patch
      - resolve-enforce-the-search-domain-limit-earlier.patch
      - resolve-limit-the-number-NTAs-to-something-sensible.patch
      - sd-bus-store-the-strv-size-when-extending-it.patch
      - sd-json-user-record-store-the-strv-size-when-extending-it.patch
      - GHSA-3jgj-3phh-hx5j

   -- Nick Rosbrook <enr0n@ubuntu.com>  Wed, 29 Jul 2026 09:41:27 -0400

  systemd (249.11-0ubuntu3.21) jammy-security; urgency=medium

    * SECURITY UPDATE: MITM via DNSSEC-signed domains with no signature
      - debian/patches/CVE-2023-7008.patch: resolved: actually check authenticated
        flag of SOA transaction in src/resolve/resolved-dns-transaction.c.
      - CVE-2023-7008
    * SECURITY UPDATE: escape-to-host via malformed optional config file
      - debian/patches/CVE-2026-40226-1.patch: nspawn: apply BindUser/Ephemeral
        from settings file only if trusted in src/nspawn/nspawn.c.
      - debian/patches/CVE-2026-40226-2.patch: nspawn: normalize pivot_root paths
        in src/nspawn/nspawn-mount.c.
      - CVE-2026-40226

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 05 Jun 2026 11:40:28 -0400

tar (built from tar) updated from 1.34+dfsg-1ubuntu0.1.22.04.2 to 1.34+dfsg-1ubuntu0.1.22.04.6:

  tar (1.34+dfsg-1ubuntu0.1.22.04.6) jammy-security; urgency=medium

    * SECURITY REGRESSION: Old archives with nonzero directory sizes
      failing to be extracted
      - debian/patches/CVE-2026-5704-5.patch: fix this by forcing
        the size to zero for DIRTYPE in read_header() in src/list.c
        (LP: #2161311).

   -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com>  Mon, 20 Jul 2026 11:42:36 -0300

  tar (1.34+dfsg-1ubuntu0.1.22.04.5) jammy-security; urgency=medium

    * SECURITY REGRESSION: Extract files issue
      - debian/patches/CVE-2026-5704-*.patch: address a regression
        that makes valid files not extract in src/list.c,
        tests/Makefile.am, tests/extrac32.at, tests/extrac34.at,
        test/testsuite.at, src/extract.c, tests/extract23,
        tests/extrac30.at (LP: #2160650).

   -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com>  Wed, 15 Jul 2026 11:39:01 -0300

  tar (1.34+dfsg-1ubuntu0.1.22.04.4) jammy-security; urgency=medium

    * SECURITY UPDATE: File overwrite via directory traversal
      - debian/patches/CVE-2025-45582-*.patch: Backport openat2 support in
        order to jailify the extraction directory.
      - CVE-2025-45582

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Sat, 27 Jun 2026 17:53:20 -0400

  tar (1.34+dfsg-1ubuntu0.1.22.04.3) jammy-security; urgency=medium

    * SECURITY UPDATE: file injection via crafted archive
      - debian/patches/CVE-2026-5704.patch: always call skip_member() after
        extraction in extract_archive(), remove conditional skip_member()
        from purge_directory(), skip directory data in skim_member(), and
        stop forcing LNKTYPE size to zero in read_header().
      - CVE-2026-5704

   -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com>  Fri, 19 Jun 2026 13:40:04 -0300

tzdata (built from tzdata) updated from 2026a-0ubuntu0.22.04.1 to 2026c-0ubuntu0.22.04.1:

  tzdata (2026c-0ubuntu0.22.04.1) jammy; urgency=medium

    * New upstream release (LP: #2161092):
      - Alberta moved to permanent -06 on 2026-06-18, so it will not fall back
        from -06 to -07 on 2026-11-01.
      - Morocco moves to permanent +00 on 2026-09-20.
    * Add autopkgtest test case for 2026c release
    * Update the ICU timezone data to 2026c
    * Add autopkgtest test case for ICU timezone data 2026c

   -- Benjamin Drung <bdrung@ubuntu.com>  Fri, 17 Jul 2026 14:52:00 +0200

  tzdata (2026b-0ubuntu0.22.04.1) jammy; urgency=medium

    * New upstream release (LP: #2157973):
      - British Columbia moved to permanent -07 on 2026-03-09, so it will not
        fall back from -07 to -08 on 2026-11-01.
    * Add autopkgtest test case for 2026b release
    * Update the ICU timezone data to 2026b
    * Add autopkgtest test case for ICU timezone data 2026b

   -- Benjamin Drung <bdrung@ubuntu.com>  Tue, 23 Jun 2026 14:44:01 +0200

vim-common, vim-tiny, xxd (built from vim) updated from 2:8.2.3995-1ubuntu2.26 to 2:8.2.3995-1ubuntu2.35:

  vim (2:8.2.3995-1ubuntu2.35) jammy-security; urgency=medium

    * SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785)
      - debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in
        runtime/autoload/netrw.vim
      - debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname
        in runtime/autoload/netrw.vim
    * SECURITY UPDATE: Use-after-free on json decode error.
      - debian/patches/CVE-2026-73071.patch: Report the position from the
        current reader in src/json.c.
      - CVE-2026-73071
    * SECURITY UPDATE: Heap buffer overflow in set_sofo().
      - debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in
        src/spellfile.c.
      - CVE-2026-73072
    * SECURITY UPDATE: Heap overflow when adding > 65535 text properties.
      - debian/patches/CVE-2026-73074.patch: Verify that the number of text
        properties falls within the limit in src/errors.h and src/textprop.c.
      - CVE-2026-73074
    * SECURITY UPDATE: Code execution via VimballRecord file.
      - debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix
        broken directory deletion code, and refactor code in
        runtime/autoload/vimball.vim
      - CVE-2026-73076
    * SECURITY UPDATE: Arbitrary code execution via keyword lookup.
      - debian/patches/CVE-2026-73077.patch: For powershell, quote the commands
        using single quotes, for zsh pass the argument as a separate list
        item to term_start()/system() in runtime/ftplugin/ps1.vim and
        ../zsh.vim.
      - CVE-2026-73077
    * SECURITY UPDATE: Code injection in netrw via bookmarks.
      - debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in
        runtime/autoload/netrw.vim.
      - CVE-2026-73078

   -- Kyle Kernick <kyle.kernick@canonical.com>  Tue, 18 Aug 2026 15:47:19 -0600

  vim (2:8.2.3995-1ubuntu2.34) jammy-security; urgency=medium

    * SECURITY UPDATE: Command execution in PHP omni-completion.
      - debian/patches/CVE-2026-59856.patch: Quote the class name before
        inserting it into the search() in runtime/autoload/phpcomplete.vim
      - CVE-2026-59856
    * SECURITY UPDATE: Stack out-of-bounds write in spell_soundfold_sal().
      - debian/patches/CVE-2026-59857.patch: Bound the single-byte SAL result
        writes in src/spell.c
      - CVE-2026-59857
    * SECURITY UPDATE: Arbitrary command execution during C omni-completion.
      - debian/patches/CVE-2026-59858.patch: Escape the type field before
        inserting it into pattern in runtime/autoload/ccomplete.vim
      - CVE-2026-59858

   -- Kyle Kernick <kyle.kernick@canonical.com>  Mon, 13 Jul 2026 13:08:21 -0600

  vim (2:8.2.3995-1ubuntu2.33) jammy-security; urgency=medium

    * SECURITY UPDATE: Path Traversal in zip.vim
      - debian/patches/CVE-2026-35177.patch: Detect malicious zip files before
        writing in runtime/autoload/zip.vim
      - CVE-2026-35177
    * SECURITY UPDATE: Out-of-bounds write.
      - debian/patches/CVE-2026-55693.patch: only descend while
        depth < MAXWLEN - 1 in src/spellfile.c.
      - debian/patches/CVE-2026-55892.patch: only descend while
        depth < MAXWLEN - 1 in src/spell.c.
      - CVE-2026-55693
      - CVE-2026-55892
    * SECURITY UPDATE: Code injection in local file deletion.
      - debian/patches/CVE-2026-55895.patch: Use fnameescape() to escape
        file name in runtime/autoload/netrw.vim.
      - CVE-2026-55895
    * SECURITY UPDATE: Out-of-bounds read with sodium encrypted files.
      - debian/patches/CVE-2026-57452.patch: Verify that there is enough space
        before function call in src/crypt.c.
      - CVE-2026-57452
    * SECURITY UPDATE: Out-of-bounds write with soundfold().
      - debian/patches/CVE-2026-57455.patch: Add an abort condition to validate
        buffer in src/spell.c.
      - CVE-2026-57455
    * SECURITY UPDATE: Code execution with python complete.
      - debian/patches/CVE-2026-57456.patch: Use repr() to quote the doc strings
        in runtime/autoload/python3complete.vim and ../pythoncomplete.vim.
      - CVE-2026-57456

   -- Kyle Kernick <kyle.kernick@canonical.com>  Tue, 30 Jun 2026 11:46:22 -0600

  vim (2:8.2.3995-1ubuntu2.32) jammy-security; urgency=medium

    * SECURITY UPDATE: Code injection via NetrwBookHistSave().
      - debian/patches/CVE-2026-47162.patch: Properly quote the directory name
        in runtime/autoload/netrw.vim.
      - CVE-2026-47162
    * SECURITY UPDATE: Code Injection in cucumber filetype plugin.
      - debian/patches/CVE-2026-47167.patch: Use rubys Regexp.new() in
        runtime/ftplugin/cucumber.vim.
      - CVE-2026-47167
    * SECURITY UPDATE: Code execution with python3complete.
      - debian/patches/CVE-2026-52858.patch: Disable execution of import/from
        statements in runtime/autoload/python3complete.vim and
        ../pythoncomplete.vim
      - debian/patches/CVE-2026-52860.patch: Strip default expressions and
        annotations in runtime/autoload/python3complete.vim and
        ../pythoncomplete.vim
      - CVE-2026-52858
      - CVE-2026-52860
    * SECURITY UPDATE: Out-of-bounds read in update_snapshot().
      - debian/patches/CVE-2026-52859.patch: Bound loop in handle_pushline() in
        src/terminal.c.
      - CVE-2026-52859

   -- Kyle Kernick <kyle.kernick@canonical.com>  Mon, 15 Jun 2026 16:18:48 -0600

  vim (2:8.2.3995-1ubuntu2.31) jammy-security; urgency=medium

    * SECURITY UPDATE: Command injection in tar plugin.
      - debian/patches/CVE-2026-46483.patch: Use the correct shell-escape in
        runtime/autoload/tar.vim.
      - CVE-2026-46483
    * SECURITY UPDATE: Code injection via mf command.
      - debian/patches/CVE-2026-43961.patch: Avoid string concatenation for
        filter commands in runtime/autoload/netrw.vim.
      - CVE-2026-43961

   -- Kyle Kernick <kyle.kernick@canonical.com>  Wed, 03 Jun 2026 10:41:25 -0600

  vim (2:8.2.3995-1ubuntu2.30) jammy-security; urgency=medium

    * SECURITY UPDATE: Command injection in netrw plugin.
      - debian/patches/CVE-2026-42307.patch: Escape file names and harden regex
        patterns in runtime/autoload/netrw.vim
      - CVE-2026-42307
    * SECURITY UPDATE: Shell execution in completion.
      - debian/patches/CVE-2026-44656.patch: Skip path entries containing
        backticks and add P_SECURE option in src/findfile.c and src/optiondefs.h
      - CVE-2026-44656
    * SECURITY UPDATE: Heap overflow in spellfile.
      - debian/patches/CVE-2026-45130.patch: Enforce a maximum compound length
        in src/spellfile.c
      - CVE-2026-45130

   -- Kyle Kernick <kyle.kernick@canonical.com>  Wed, 20 May 2026 15:28:11 -0600

  vim (2:8.2.3995-1ubuntu2.29) jammy-security; urgency=medium

    * SECURITY UPDATE: Command injection via backtick expansion in tag files
      - debian/patches/CVE-2026-41411.patch: Disallow backticks before attempting
        to expand filenames
      - CVE-2026-41411

   -- Federico Quattrin <federico.quattrin@canonical.com>  Wed, 06 May 2026 13:56:18 -0300

  vim (2:8.2.3995-1ubuntu2.28) jammy-security; urgency=medium

    * SECURITY UPDATE: Command Injection in netbeans
      - debian/patches/CVE-2026-39881.patch: Validate typename, fg, and bg
        before passing to coloncmd in src/netbeans.c
      - CVE-2026-39881

   -- Kyle Kernick <kyle.kernick@canonical.com>  Wed, 22 Apr 2026 12:21:19 -0600

  vim (2:8.2.3995-1ubuntu2.27) jammy-security; urgency=medium

    * SECURITY UPDATE: Command injection in glob.
      - debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
        src/os_unix.c.
      - CVE-2026-33412
    * SECURITY UPDATE: Security bypass in modeline.
      - debian/patches/CVE-2026-34982.patch: Disallow modeset while in secure
         mode in src/optiondefs.h.
      - CVE-2026-34982

   -- Kyle Kernick <kyle.kernick@canonical.com>  Mon, 06 Apr 2026 14:13:36 -0600

liblzma5:amd64 (built from xz-utils) updated from 5.2.5-2ubuntu1 to 5.2.5-2ubuntu1.1:

  xz-utils (5.2.5-2ubuntu1.1) jammy-security; urgency=medium

    * SECURITY UPDATE: heap buffer overflow
      - debian/patches/CVE-2026-34743.patch: adds a check to
        lzma_index_prealloc() to default to a safe size when decoding empty
        indexes in src/liblzma/common/index.c.
      - CVE-2026-34743

   -- Ian Constantin <ian.constantin@canonical.com>  Thu, 28 May 2026 19:06:40 +0300

10/04/2026, commit https://github.com/canonical/core-base/tree/afed2422f81dbe3b315be43b4b5e122a43e98d85

[ Changes in the core22 snap ]

Andrew Phelps (1):
      tools: do not use python3.12 feature since this builds with python3.10 (#428)

Philip Meulengracht (1):
      tools/generate-changelog: port changes from core24 to handle missing packages (#413)

[ Changes in primed packages ]

coreutils (built from coreutils) updated from 8.32-4.1ubuntu1.2 to 8.32-4.1ubuntu1.3:

  coreutils (8.32-4.1ubuntu1.3) jammy; urgency=medium

    * Fix slow performance of 'du' on large directories (>= 10K files)
      on Lustre filesystems by skipping inode sorting. The default
      behaviour of sorting dirents by inode numbers negatively impacts
      performance on Lustre because it interferes with Lustre's ability
      to prefetch file metadata via statahead. (LP: #2137373)
      - d/p/lp2137373-skip-dirent-inode-sorting-for-lustre.patch

   -- Munir Siddiqui <munir.siddiqui@canonical.com>  Fri, 23 Jan 2026 15:51:17 +0500

libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.6 to 0.9.6-2ubuntu0.22.04.7:

  libssh (0.9.6-2ubuntu0.22.04.7) jammy-security; urgency=medium

    * SECURITY UPDATE: out-of-bound read
      - debian/patches/CVE-2026-3731.patch: correct bounds checks when querying
        for an SFTP extension name or data in src/sftp.c.
      - CVE-2026-3731

   -- Ian Constantin <ian.constantin@canonical.com>  Wed, 11 Mar 2026 12:19:27 +0200

openssh-client, openssh-server, openssh-sftp-server (built from openssh) updated from 1:8.9p1-3ubuntu0.13 to 1:8.9p1-3ubuntu0.14:

  openssh (1:8.9p1-3ubuntu0.14) jammy-security; urgency=medium

    * SECURITY UPDATE: GSSAPI Key Exchange issue
      - debian/patches/gssapi.patch: replace incorrect use of
        sshpkt_disconnect() with ssh_packet_disconnect() and properly
        initialize some vars.
      - CVE-2026-3497
    * SECURITY UPDATE: Untrusted control characters in usernames
      - debian/patches/CVE-2025-61984.patch: refuse usernames that include
        control characters in ssh.c.
      - CVE-2025-61984
    * SECURITY UPDATE: Code execution in ProxyCommand via NULL character
      - debian/patches/CVE-2025-61985.patch: don't allow 0 characters in
        url-encoded strings in misc.c.
      - CVE-2025-61985

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 04 Mar 2026 12:55:04 -0500

libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.21 to 3.0.2-0ubuntu1.23:

  openssl (3.0.2-0ubuntu1.23) jammy-security; urgency=medium

    * SECURITY UPDATE: NULL pointer dereference when processing an OCSP
      response
      - debian/patches/CVE-2026-28387.patch: dane_match_cert() should
        X509_free() on ->mcert instead of OPENSSL_free() in
        crypto/x509/x509_vfy.c.
      - CVE-2026-28387
    * SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL
      - debian/patches/CVE-2026-28388-1.patch: fix NULL Dereference When
        Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c.
      - debian/patches/CVE-2026-28388-2.patch: Added test in test/*.
      - CVE-2026-28388
    * SECURITY UPDATE: Possible NULL dereference when processing CMS
      KeyAgreeRecipientInfo
      - debian/patches/CVE-2026-28389.patch: Fix NULL deref in
        [ec]dh_cms_set_shared_info in crypto/cms/cms_dh.c,
        crypto/cms/cms_ec.c.
      - CVE-2026-28389
    * SECURITY UPDATE: Possible NULL Dereference When Processing CMS
      KeyTransportRecipientInfo
      - debian/patches/CVE-2026-28390.patch: Fix NULL deref in
        rsa_cms_decrypt in crypto/cms/cms_rsa.c.
      - CVE-2026-28390
    * SECURITY UPDATE: Heap buffer overflow in hexadecimal conversion
      - debian/patches/CVE-2026-31789.patch: avoid possible buffer overflow
        in buf2hex conversion in crypto/o_str.c.
      - CVE-2026-31789
    * SECURITY UPDATE: Incorrect failure handling in RSA KEM RSASVE
      encapsulation
      - debian/patches/CVE-2026-31790-1.patch: validate RSA_public_encrypt()
        result in RSASVE in providers/implementations/kem/rsa_kem.c.
      - debian/patches/CVE-2026-31790-2.patch: test RSA_public_encrypt()
        result in RSASVE in test/evp_extra_test.c.
      - CVE-2026-31790

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 07 Apr 2026 08:05:56 -0400

python3-jwt (built from pyjwt) updated from 2.3.0-1ubuntu0.2 to 2.3.0-1ubuntu0.3:

  pyjwt (2.3.0-1ubuntu0.3) jammy-security; urgency=medium

    * SECURITY UPDATE: Incorrect authorization of invalid JWS token.
      - debian/patches/CVE-2026-32597.patch: Add _supported_crit and checks
        for valid crit header in jwt/api_jws.py. Add tests in
        tests/test_api_jws.py and tests/test_api_jwt.py.
      - CVE-2026-32597

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Thu, 26 Mar 2026 14:58:14 -0230

python3-cryptography (built from python-cryptography) updated from 3.4.8-1ubuntu2.2 to 3.4.8-1ubuntu2.4:

  python-cryptography (3.4.8-1ubuntu2.4) jammy-security; urgency=medium

    * SECURITY REGRESSION: ecc support regression (LP: #2144373)
      - debian/patches/CVE-2026-26007.patch: updated to remove problematic
        deprecation warning code which is causing a regression with ansible.

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Sat, 14 Mar 2026 08:22:06 -0400

  python-cryptography (3.4.8-1ubuntu2.3) jammy-security; urgency=medium

    * SECURITY UPDATE: Subgroup Attack Due to Missing Subgroup Validation for
      SECT Curves
      - debian/patches/CVE-2026-26007-pre1.patch: check if public keys are at
        infinity earlier in src/cryptography/hazmat/backends/openssl/ec.py,
        tests/hazmat/primitives/test_ec.py.
      - debian/patches/CVE-2026-26007.patch: EC check key on cofactor > 1 in
        src/cryptography/hazmat/primitives/asymmetric/ec.py,
        src/cryptography/utils.py, tests/hazmat/primitives/test_ec.py,
        src/_cffi_src/openssl/ec.py,
        src/cryptography/hazmat/backends/openssl/ec.py.
      - CVE-2026-26007

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 20 Feb 2026 10:14:37 -0500

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.14 to 3.10.12-1~22.04.15:

  python3.10 (3.10.12-1~22.04.15) jammy-security; urgency=medium

    * SECURITY REGRESSION: Revert patch for CVE-2025-15366
      - debian/patches/CVE-2025-15366.patch: Reverted. Patch breaks RFC
        9051 IMAP conformance and introduces behavior regressions avoided
        by upstream.
      - CVE-2025-15366
    * SECURITY REGRESSION: Revert patch for CVE-2025-15367
      - debian/patches/CVE-2025-15367.patch: Reverted to prevent behavior
        regressions, aligning with upstream backporting decisions.
      - CVE-2025-15367
    * SECURITY REGRESSION: Allow HTAB in wsgiref header values
      - debian/patches/CVE-2026-0865-2.patch: Permit HTAB in header values
        (excluding names) in Lib/wsgiref/headers.py, add test coverage.
      - CVE-2026-0865

   -- Vyom Yadav <vyom.yadav@canonical.com>  Tue, 03 Mar 2026 17:26:32 +0530

sudo (built from sudo) updated from 1.9.9-1ubuntu2.5 to 1.9.9-1ubuntu2.6:

  sudo (1.9.9-1ubuntu2.6) jammy-security; urgency=medium

    * SECURITY UPDATE: exec_mailer gid issue (LP: #2143042)
      - debian/patches/lp2143042.patch: set group as well as uid when running
        the mailer and make a setuid(), setgid() or setgroups() failure fatal
        in include/sudo_eventlog.h, lib/eventlog/eventlog.c,
        lib/eventlog/eventlog_conf.c, plugins/sudoers/logging.c,
        plugins/sudoers/policy.c.
      - No CVE number

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 02 Mar 2026 08:08:06 -0500

libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.17 to 249.11-0ubuntu3.20:

  systemd (249.11-0ubuntu3.20) jammy; urgency=medium

    * net_id: depending on new udev prop, include/exclude PCI domain from netif names
      (LP: #2134334)
    * network: support ID_NET_MANAGED_BY udev property
      (LP: #2133220)

   -- Robert Malz <robert.malz@canonical.com>  Tue, 24 Mar 2026 09:52:29 -0400

  systemd (249.11-0ubuntu3.19) jammy-security; urgency=medium

    * SECURITY UPDATE: Local unprivileged user can overwrite stack in systemd
      - d/p/CVE-2026-29111-1.patch: path-util: backport path_startswith_full
      - d/p/CVE-2026-29111-2.patch: core/cgroup: avoid one unnecessary strjoina()
      - d/p/CVE-2026-29111-3.patch: core: validate input cgroup path more prudently
    * SECURITY UPDATE: Local root execution via malicious hardware devices
      - d/p/udev-check-for-invalid-chars-in-various-fields-received-f.patch
      - d/p/udev-fix-review-mixup.patch
      - No CVE number

   -- Nick Rosbrook <enr0n@ubuntu.com>  Fri, 13 Mar 2026 12:47:41 -0400

tzdata (built from tzdata) updated from 2025b-0ubuntu0.22.04.1 to 2026a-0ubuntu0.22.04.1:

  tzdata (2026a-0ubuntu0.22.04.1) jammy; urgency=medium

    * New upstream release (LP: #2143355):
      - No leap second on 2026-06-30
      - Moldova has used EU transition times since 2022
    * Add autopkgtest test case for 2025c and 2026a release
    * Update the ICU timezone data to 2026a
    * Add autopkgtest test case for ICU timezone data 2026a

   -- Nadzeya Hutsko <nadzeya.hutsko@canonical.com>  Thu, 19 Mar 2026 15:04:40 +0100

bsdutils, fdisk, libblkid1:amd64, libfdisk1:amd64, libmount1:amd64, libsmartcols1:amd64, libuuid1:amd64, mount, rfkill, util-linux (built from util-linux) updated from 1:2.37.2-4ubuntu3.4 to 1:2.37.2-4ubuntu3.5:

vim-common, vim-tiny, xxd (built from vim) updated from 2:8.2.3995-1ubuntu2.24 to 2:8.2.3995-1ubuntu2.26:

  vim (2:8.2.3995-1ubuntu2.26) jammy-security; urgency=medium

    * SECURITY UPDATE: Buffer Overflow
      - debian/patches/CVE-2026-26269.patch: Limit writing to max KEYBUFLEN
        bytes to prevent writing out of bounds.
      - debian/patches/CVE-2026-28420.patch: Use VTERM_MAX_CHARS_PER_CELL * 4
        for ga_grow() to ensure sufficient space. Add a boundary check to the
        character loop to prevent index out-of-bounds access.
      - debian/patches/CVE-2026-28422.patch: Update the size check to account
        for the byte length of the fill character (using MB_CHAR2LEN).
      - debian/patches/CVE-2026-25749.patch: Limit strncpy to the length
        of the buffer (MAXPATHL)
      - CVE-2026-26269
      - CVE-2026-28420
      - CVE-2026-28422
      - CVE-2026-25749
    * SECURITY UPDATE: Command Injection
      - debian/patches/CVE-2026-28417.patch: Implement stricter RFC1123
        hostname and IP validation. Use shellescape() for the provided
        hostname and port.
      - CVE-2026-28417
    * SECURITY UPDATE: Out of Bounds Read
      - debian/patches/CVE-2026-28418.patch: Check for end of buffer
        and return early.
      - CVE-2026-28418
    * SECURITY UPDATE: Buffer Underflow
      - debian/patches/CVE-2026-28419.patch: Add a check to ensure the
        delimiter (p_7f) is not at the start of the buffer (lbuf) before
        attempting to isolate the tag name.
      - CVE-2026-28419
    * SECURITY UPDATE: Denial of Service
      - debian/patches/CVE-2026-28421.patch: Add bounds checks on
        pe_page_count and pe_bnum against mf_blocknr_max before descending
        into the block tree, and validate pe_old_lnum >= 1 and
        pe_line_count > 0 before calling readfile().
      - CVE-2026-28421

   -- Bruce Cable <bruce.cable@canonical.com>  Wed, 11 Mar 2026 10:44:44 +1100

wpasupplicant (built from wpa) updated from 2:2.10-6ubuntu2.3 to 2:2.10-6ubuntu2.4:

  wpa (2:2.10-6ubuntu2.4) jammy; urgency=medium

    * Add SaePasswordMismatch signal handling (LP: #2125203)

   -- Mitchell Augustin <mitchell.augustin@canonical.com>  Wed, 04 Feb 2026 17:33:00 -0600

25/02/2026, commit https://github.com/canonical/core-base/tree/35ba5381ea78d6904d4e5d475e1aee78f7b61172

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

cloud-init (built from cloud-init) updated from 25.2-0ubuntu1~22.04.1 to 25.3-0ubuntu1~22.04.1:

  cloud-init (25.3-0ubuntu1~22.04.1) jammy; urgency=medium

    * d/p/retain-setuptools.patch: void upstream switch to meson build backend.
    * refresh patches:
      - d/p/cli-retain-file-argument-as-main-cmd-arg.patch
      - d/p/grub-dpkg-support.patch
      - d/p/no-nocloud-network.patch
      - d/p/no-single-process.patch
    * Upstream snapshot based on 25.3. (LP: #2131604).
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/25.3/ChangeLog

   -- Chad Smith <chad.smith@canonical.com>  Sat, 15 Nov 2025 11:11:25 -0700

libexpat1:amd64 (built from expat) updated from 2.4.7-1ubuntu0.6 to 2.4.7-1ubuntu0.7:

  expat (2.4.7-1ubuntu0.7) jammy-security; urgency=medium

    * SECURITY UPDATE: NULL pointer dereference
      - debian/patches/CVE-2026-24515.patch: updates
        XML_ExternalEntityParserCreate to copy unknown encoding handler user
        data in expat/lib/xmlparse.c.
      - CVE-2026-24515
    * SECURITY UPDATE: integer overflow
      - debian/patches/CVE-2026-25210*.patch: adds an integer overflow check for
        tag buffer reallocation in the doContent function of
        expat/lib/xmlparse.c.
      - CVE-2026-25210

   -- Ian Constantin <ian.constantin@canonical.com>  Wed, 04 Feb 2026 17:24:04 +0200

gcc-12-base:amd64, gcc-12-base:i386, libgcc-s1:amd64, libgcc-s1:i386, libstdc++6:amd64 (built from gcc-12) updated from 12.3.0-1ubuntu1~22.04.2 to 12.3.0-1ubuntu1~22.04.3:

  gcc-12 (12.3.0-1ubuntu1~22.04.3) jammy; urgency=medium

    * d/p/pr118976.diff: Fix memory corruption when executing 256-bit
      Scalable Vector Extensions code on 128-bit CPUs (LP: #2101084).

   -- Vladimir Petko <vladimir.petko@canonical.com>  Sat, 20 Dec 2025 10:52:06 +1300

libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.8 to 2.72.4-0ubuntu2.9:

  glib2.0 (2.72.4-0ubuntu2.9) jammy-security; urgency=medium

    * SECURITY UPDATE: integer overflow in Base64 encoding
      - debian/patches/CVE-2026-1484-1.patch: use gsize to prevent potential
        overflow in glib/gbase64.c.
      - debian/patches/CVE-2026-1484-2.patch: ensure that the out value is
        within allocated size in glib/gbase64.c.
      - CVE-2026-1484
    * SECURITY UPDATE: buffer underflow via header length
      - debian/patches/CVE-2026-1485.patch: do not overflow if header is
        longer than MAXINT in gio/gcontenttype.c.
      - CVE-2026-1485
    * SECURITY UPDATE: integer overflow via Unicode case conversion
      - debian/patches/CVE-2026-1489-1.patch: use size_t for output_marks
        length in glib/guniprop.c.
      - debian/patches/CVE-2026-1489-2.patch: do not convert size_t to gint
        in glib/guniprop.c.
      - debian/patches/CVE-2026-1489-3.patch: ensure we do not overflow size
        in glib/guniprop.c.
      - debian/patches/CVE-2026-1489-4.patch: add test debug information when
        parsing input files in glib/tests/unicode.c.
      - CVE-2026-1489

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 28 Jan 2026 12:57:54 -0500

libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.12 to 2.35-0ubuntu3.13:

  glibc (2.35-0ubuntu3.13) jammy-security; urgency=medium

    * SECURITY UPDATE: use-after-free in wordexp_t fields
      - debian/patches/CVE-2025-15281.patch: posix: Reset wordexp_t fields
        with WRDE_REUSE
      - CVE-2025-15281
    * SECURITY UPDATE: integer overflow in memalign
      - debian/patches/CVE-2026-0861.patch: memalign: reinstate alignment
        overflow check
      - CVE-2026-0861
    * SECURITY UPDATE: memory leak in NSS DNS
      - debian/patches/CVE-2026-0915.patch: resolv: Fix NSS DNS backend for
        getnetbyaddr
      - CVE-2026-0915

   -- Nishit Majithia <nishit.majithia@canonical.com>  Fri, 30 Jan 2026 13:50:56 +0530

gnutls-bin, libgnutls30:amd64 (built from gnutls28) updated from 3.7.3-4ubuntu1.7 to 3.7.3-4ubuntu1.8:

  gnutls28 (3.7.3-4ubuntu1.8) jammy-security; urgency=medium

    * SECURITY UPDATE: DoS via malicious certificates
      - debian/patches/CVE-2025-14831-*.patch: rework processing algorithms
        to exhibit better performance characteristics in
        lib/x509/name_constraints.c, tests/name-constraints-ip.c.
      - CVE-2025-14831
    * SECURITY UPDATE: stack overflow via long token label
      - debian/patches/CVE-2025-9820.patch: avoid stack overwrite when
        initializing a token in lib/pkcs11_write.c, tests/Makefile.am,
        tests/pkcs11/long-label.c.
      - CVE-2025-9820

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 10 Feb 2026 12:28:21 -0500

libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3ubuntu0.3 to 1.6.37-3ubuntu0.4:

  libpng1.6 (1.6.37-3ubuntu0.4) jammy-security; urgency=medium

    * SECURITY UPDATE: OOB read in png_set_quantize()
      - debian/patches/CVE-2026-25646.patch: fix a heap buffer overflow in
        pngrtran.c.
      - CVE-2026-25646

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 11 Feb 2026 09:27:33 -0500

libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.5 to 0.9.6-2ubuntu0.22.04.6:

  libssh (0.9.6-2ubuntu0.22.04.6) jammy-security; urgency=medium

    * SECURITY UPDATE: memory leak in key exchange
      - debian/patches/CVE-2025-8277-1.patch: adjust packet filter to work
        when DH-GEX is guessed wrongly in src/packet.c.
      - debian/patches/CVE-2025-8277-2.patch: fix memory leak of unused
        ephemeral key pair after client's wrong KEX guess in src/dh_crypto.c,
        src/dh_key.c, src/ecdh_crypto.c, src/ecdh_gcrypt.c,
        src/ecdh_mbedcrypto.c.
      - debian/patches/CVE-2025-8277-3.patch: free previously allocated
        pubkeys in src/ecdh_crypto.c, src/ecdh_gcrypt.c.
      - debian/patches/CVE-2025-8277-4.patch: avoid leaking ecdh keys in
        src/ecdh_mbedcrypto.c, src/wrapper.c.
      - CVE-2025-8277
    * SECURITY UPDATE: Improper sanitation of paths received from SCP servers
      - debian/patches/CVE-2026-0964.patch: reject invalid paths received
        through scp in src/scp.c.
      - CVE-2026-0964
    * SECURITY UPDATE: DoS via improper configuration file handling
      - debian/patches/CVE-2026-0965.patch: do not attempt to read
        non-regular and too large configuration files in
        include/libssh/misc.h, include/libssh/priv.h, src/bind_config.c,
        src/config.c, src/dh-gex.c, src/known_hosts.c, src/knownhosts.c,
        src/misc.c, tests/unittests/torture_config.c.
      - CVE-2026-0965
    * SECURITY UPDATE: Buffer underflow in ssh_get_hexa() on invalid input
      - debian/patches/CVE-2026-0966-1.patch: avoid heap buffer underflow in
        ssh_get_hexa in src/misc.c.
      - debian/patches/CVE-2026-0966-2.patch: test coverage for ssh_get_hexa
        in tests/unittests/torture_misc.c.
      - debian/patches/CVE-2026-0966-3.patch: update guided tour to use
        SHA256 fingerprints in doc/guided_tour.dox.
      - CVE-2026-0966
    * SECURITY UPDATE: DoS via inefficient regular expression processing
      - debian/patches/CVE-2026-0967.patch: avoid recursive matching (ReDoS)
        in src/match.c, tests/unittests/torture_config.c.
      - CVE-2026-0967
    * SECURITY UPDATE: DoS due to malformed SFTP message
      - debian/patches/CVE-2026-0968-1.patch: sanitize input handling in
        sftp_parse_longname() in src/sftp.c.
      - debian/patches/CVE-2026-0968-2.patch: reproducer for invalid longname
        data in tests/unittests/CMakeLists.txt,
        tests/unittests/torture_unit_sftp.c.
      - CVE-2026-0968

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 13 Feb 2026 10:22:49 -0500

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.13 to 3.10.12-1~22.04.14:

  python3.10 (3.10.12-1~22.04.14) jammy-security; urgency=medium

    * SECURITY UPDATE: Header injection in email messages where addresses are not
      sanitized.
      - debian/patches/CVE-2025-11468.patch: Add escape parentheses and backslash
        in Lib/email/_header_value_parser.py. Add test in
        Lib/test/test_email/test__header_value_parser.py.
      - CVE-2025-11468
    * SECURITY UPDATE: Quadratic algorithm when building excessively nested XML
      documents.
      - debian/patches/CVE-2025-12084-*.patch: Remove _in_document and replace
        with node.ownerDocument in Lib/xml/dom/minidom.py. Set self.ownerDocument
        to None in Lib/xml/dom/minidom.py. Add test in Lib/test/test_minidom.py.
      - CVE-2025-12084
    * SECURITY UPDATE: OOM and denial of service when opening malicious plist
      file.
      - debian/patches/CVE-2025-13837.patch: Add _MIN_READ_BUF_SIZE and _read
        with checks in Lib/plistlib.py. Add test in Lib/test/test_plistlib.py.
      - CVE-2025-13837
    * SECURITY UPDATE: Header injection in user controlled data URLs in urllib.
      - debian/patches/CVE-2025-15282.patch: Add control character checks in
        Lib/urllib/request.py. Add test in Lib/test/test_urllib.py.
    * SECURITY UPDATE: Command injection through user controlled commands in
      imaplib.
      - debian/patches/CVE-2025-15366.patch: Add _control_chars and checks in
        Lib/imaplib.py. Add test in Lib/test/test_imaplib.py.
    * SECURITY UPDATE: Command injection through user controlled commands in
      poplib.
      - debian/patches/CVE-2025-15367.patch: Add control character regex check
        in Lib/poplib.py. Add test in Lib/test/test_poplib.py.
      - CVE-2025-15367
    * SECURITY UPDATE: HTTP header injection in user controlled cookie values.
      - debian/patches/CVE-2026-0672.patch: Add _control_characters_re and
        checks in Lib/http/cookies.py. Add test in Lib/test/test_http_cookies.py.
      - CVE-2026-0672
    * SECURITY UPDATE: HTTP header injection in user controlled headers and
      values with newlines.
      - debian/patches/CVE-2026-0865.patch: Add _control_chars_re and check in
        Lib/wsgiref/headers.py. Add test in Lib/test/support/__init__.py and
        Lib/test/test_wsgiref.py.
      - CVE-2026-0865

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Mon, 26 Jan 2026 11:25:28 -0330

28/01/2026, commit https://github.com/canonical/core-base/tree/35ba5381ea78d6904d4e5d475e1aee78f7b61172

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.7 to 2.72.4-0ubuntu2.8:

  glib2.0 (2.72.4-0ubuntu2.8) jammy-security; urgency=medium

    * SECURITY UPDATE: Integer overflow in g_buffered_input_stream_peek()
      - debian/patches/CVE-2026-0988.patch: fix a potential integer overflow
        in peek() in gio/gbufferedinputstream.c,
        gio/tests/buffered-input-stream.c.
      - CVE-2026-0988

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 20 Jan 2026 08:55:03 -0500

libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.11 to 2.35-0ubuntu3.12:

  glibc (2.35-0ubuntu3.12) jammy; urgency=medium

    * d/p/lp2089789-*.patch: fix malloc performance regression (LP: #2089789)

   -- Simon Chopin <schopin@ubuntu.com>  Tue, 15 Jul 2025 11:40:00 +0200

libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3ubuntu0.1 to 1.6.37-3ubuntu0.3:

  libpng1.6 (1.6.37-3ubuntu0.3) jammy-security; urgency=medium

    * SECURITY UPDATE: OOB in png_image_read_composite
      - debian/patches/CVE-2025-66293-1.patch: validate component size in
        pngread.c.
      - debian/patches/CVE-2025-66293-2.patch: improve fix in pngread.c.
      - CVE-2025-66293
    * SECURITY UPDATE: Heap buffer over-read in png_image_read_direct_scaled
      - debian/patches/CVE-2026-22695.patch: fix memcpy size in pngread.c.
      - CVE-2026-22695
    * SECURITY UPDATE: Integer truncation causing heap buffer over-read
      - debian/patches/CVE-2026-22801.patch: remove incorrect truncation
        casts in CMakeLists.txt, contrib/libtests/pngstest.c, pngwrite.c,
        tests/pngstest-large-stride.
      - CVE-2026-22801

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 12 Jan 2026 13:14:59 -0500

libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.20 to 3.0.2-0ubuntu1.21:

  openssl (3.0.2-0ubuntu1.21) jammy-security; urgency=medium

    * SECURITY UPDATE: Stack buffer overflow in CMS AuthEnvelopedData parsing
      - debian/patches/CVE-2025-15467-1.patch: correct handling of
        AEAD-encrypted CMS with inadmissibly long IV in crypto/evp/evp_lib.c.
      - debian/patches/CVE-2025-15467-2.patch: some comments to clarify
        functions usage in crypto/asn1/evp_asn1.c.
      - debian/patches/CVE-2025-15467-3.patch: test for handling of
        AEAD-encrypted CMS with inadmissibly long IV in test/cmsapitest.c,
        test/recipes/80-test_cmsapi.t,
        test/recipes/80-test_cmsapi_data/encDataWithTooLongIV.pem.
      - CVE-2025-15467
    * SECURITY UPDATE: Heap out-of-bounds write in BIO_f_linebuffer on short
      writes
      - debian/patches/CVE-2025-68160.patch: fix heap buffer overflow in
        BIO_f_linebuffer in crypto/bio/bf_lbuf.c.
      - CVE-2025-68160
    * SECURITY UPDATE: Unauthenticated/unencrypted trailing bytes with
      low-level OCB function calls
      - debian/patches/CVE-2025-69418.patch: fix OCB AES-NI/HW stream path
        unauthenticated/unencrypted trailing bytes in crypto/modes/ocb128.c.
      - CVE-2025-69418
    * SECURITY UPDATE: Out of bounds write in PKCS12_get_friendlyname() UTF-8
      conversion
      - debian/patches/CVE-2025-69419.patch: check return code of UTF8_putc
        in crypto/asn1/a_strex.c, crypto/pkcs12/p12_utl.c.
      - CVE-2025-69419
    * SECURITY UPDATE: Missing ASN1_TYPE validation in
      TS_RESP_verify_response() function
      - debian/patches/CVE-2025-69420.patch: verify ASN1 object's types
        before attempting to access them as a particular type in
        crypto/ts/ts_rsp_verify.c.
      - CVE-2025-69420
    * SECURITY UPDATE: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex
      - debian/patches/CVE-2025-69421.patch: add NULL check in
        crypto/pkcs12/p12_decr.c.
      - CVE-2025-69421
    * SECURITY UPDATE: ASN1_TYPE missing validation and type confusion
      - debian/patches/CVE-2026-2279x.patch: ensure ASN1 types are checked
        before use in apps/s_client.c, crypto/pkcs12/p12_kiss.c,
        crypto/pkcs7/pk7_doit.c.
      - CVE-2026-22795
      - CVE-2026-22796

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 26 Jan 2026 07:32:08 -0500

python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.5 to 1.26.5-1~exp1ubuntu0.6:

  python-urllib3 (1.26.5-1~exp1ubuntu0.6) jammy-security; urgency=medium

    * SECURITY REGRESSION: Missing _has_decoded_content from CVE-2026-21441
      (LP: #2138420)
      - debian/patches/CVE-2026-21441-fix1.patch: Implement _has_decoded_content
        and decoded checks in src/urllib3/response.py. Add tests in
        test/test_response.py.

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Fri, 16 Jan 2026 19:39:26 -0330

13/01/2026, commit https://github.com/canonical/core-base/tree/35ba5381ea78d6904d4e5d475e1aee78f7b61172

[ Changes in the core22 snap ]

Philip Meulengracht (1):
      static: add snapd.conf to tmpfiles.d (#383)

[ Changes in primed packages ]

apparmor, libapparmor1:amd64 (built from apparmor) updated from 3.0.4-2ubuntu2.4 to 3.0.4-2ubuntu2.5:

  apparmor (3.0.4-2ubuntu2.5) jammy; urgency=medium

    * profiles: make /sys/devices PCI paths hex-aware (LP: #2115234)

   -- Keifer Snedeker <keifer.snedeker@canonical.com>  Fri, 15 Aug 2025 13:17:13 +0100

libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.6 to 2.72.4-0ubuntu2.7:

  glib2.0 (2.72.4-0ubuntu2.7) jammy-security; urgency=medium

    * SECURITY UPDATE: overflow via long invalid ISO 8601 timestamp
      - debian/patches/CVE-2025-3360-1.patch: fix integer overflow when
        parsing very long ISO8601 inputs in glib/gdatetime.c.
      - debian/patches/CVE-2025-3360-2.patch: fix potential integer overflow
        in timezone offset handling in glib/gdatetime.c.
      - debian/patches/CVE-2025-3360-3.patch: track timezone length as an
        unsigned size_t in glib/gdatetime.c.
      - debian/patches/CVE-2025-3360-4.patch: factor out some string pointer
        arithmetic in glib/gdatetime.c.
      - debian/patches/CVE-2025-3360-5.patch: factor out an undersized
        variable in glib/gdatetime.c.
      - debian/patches/CVE-2025-3360-6.patch: add some missing GDateTime
        ISO8601 parsing tests in glib/tests/gdatetime.c.
      - CVE-2025-3360
    * SECURITY UPDATE: GString overflow
      - debian/patches/CVE-2025-6052.patch: fix overflow check when expanding
        the string in glib/gstring.c.
      - CVE-2025-6052
    * SECURITY UPDATE: integer overflow in temp file creation
      - debian/patches/CVE-2025-7039.patch: fix computation of temporary file
        name in glib/gfileutils.c.
      - CVE-2025-7039
    * SECURITY UPDATE: heap overflow in g_escape_uri_string()
      - debian/patches/CVE-2025-13601.patch: add overflow check in
        glib/gconvert.c.
      - CVE-2025-13601
    * SECURITY UPDATE: buffer underflow through glib/gvariant
      - debian/patches/CVE-2025-14087-1.patch: fix potential integer overflow
        parsing (byte)strings in glib/gvariant-parser.c.
      - debian/patches/CVE-2025-14087-2.patch: use size_t to count numbers of
        child elements in glib/gvariant-parser.c.
      - debian/patches/CVE-2025-14087-3.patch: convert error handling code to
        use size_t in glib/gvariant-parser.c.
      - CVE-2025-14087
    * SECURITY UPDATE: integer overflow in gfileattribute
      - debian/patches/gfileattribute-overflow.patch: add overflow check in
        gio/gfileattribute.c.
      - No CVE number

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 10 Dec 2025 11:09:12 -0500

gpgv (built from gnupg2) updated from 2.2.27-3ubuntu2.4 to 2.2.27-3ubuntu2.5:

  gnupg2 (2.2.27-3ubuntu2.5) jammy-security; urgency=medium

    * SECURITY UPDATE: Remote Code Execution
      - debian/patches/CVE-2025-68973.patch: gpg: Fix possible memory
      corruption in the armor parser.
      - CVE-2025-68973

   -- Allen Huang <allen.huang@canonical.com>  Mon, 05 Jan 2026 22:14:39 +0000

libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3build5 to 1.6.37-3ubuntu0.1:

  libpng1.6 (1.6.37-3ubuntu0.1) jammy-security; urgency=medium

    * SECURITY UPDATE: buffer overflow issue
      - debian/patches/CVE-2025-64505.patch: Fix a buffer overflow in
        png_do_quantize
      - debian/patches/CVE-2025-64506.patch: Fix a heap buffer overflow in
        png_write_image_8bit
      - debian/patches/CVE-2025-64720.patch: Fix a buffer overflow in
        png_init_read_transformations
      - debian/patches/CVE-2025-65018.patch: Fix a heap buffer overflow in
        png_image_finish_read
      - CVE-2025-64505
      - CVE-2025-64506
      - CVE-2025-64720
      - CVE-2025-65018

   -- Nishit Majithia <nishit.majithia@canonical.com>  Tue, 09 Dec 2025 17:35:45 +0530

libtasn1-6:amd64 (built from libtasn1-6) updated from 4.18.0-4ubuntu0.1 to 4.18.0-4ubuntu0.2:

  libtasn1-6 (4.18.0-4ubuntu0.2) jammy-security; urgency=medium

    * SECURITY UPDATE: ETYPE_OK off-by-one array size check
      - debian/patches/CVE-2021-46848.patch: fix size check in lib/int.h.
      - CVE-2021-46848
    * SECURITY UPDATE: Stack-based buffer overflow
      - debian/patches/CVE-2025-13151.patch: fix asn1_expand_octet_string
        buffer size in lib/decoding.c.
      - CVE-2025-13151

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 08 Jan 2026 12:27:15 -0500

python3-attr (built from python-attrs) updated from 21.2.0-1 to 21.2.0-1ubuntu1:

  python-attrs (21.2.0-1ubuntu1) jammy; urgency=medium

    * d/p/0005-Rework-linecache-handling-828.patch: Cherry-pick upstream PR 826 
      - Fix memory leak when creating many identical classes (Fixes LP: #2121607)

   -- Zachary Raines <zachary.raines@canonical.com>  Mon, 06 Oct 2025 15:28:54 +0000

python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.3 to 1.26.5-1~exp1ubuntu0.5:

  python-urllib3 (1.26.5-1~exp1ubuntu0.5) jammy-security; urgency=medium

    * SECURITY UPDATE: Decompression bomb in HTTP redirect responses.
      - debian/patches/CVE-2026-21441.patch: Add decode_content to self.read()
        in src/urllib3/response.py. Add tests in
        test/with_dummyserver/test_connectionpool.py.
      - CVE-2026-21441

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Thu, 08 Jan 2026 16:06:10 -0330

  python-urllib3 (1.26.5-1~exp1ubuntu0.4) jammy-security; urgency=medium

    * SECURITY UPDATE: Denial of service due to unbounded decompression chain.
      - debian/patches/CVE-2025-66418.patch: Add max_decode_links limit and
        checks in src/urllib3/response.py. Add test in test/test_response.py.
      - CVE-2025-66418

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Wed, 10 Dec 2025 17:29:42 -0330

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.12 to 3.10.12-1~22.04.13:

  python3.10 (3.10.12-1~22.04.13) jammy-security; urgency=medium

    * SECURITY UPDATE: HTTP Content-Length denial of service
      - debian/patches/CVE-2025-13836.patch: Read large data in chunks with
        geometric reads in Lib/http/client.py and add tests in 
        Lib/test/test_httplib.py
      - CVE-2025-13836

   -- Vyom Yadav <vyom.yadav@canonical.com>  Thu, 08 Jan 2026 12:22:19 +0530

02/12/2025, commit https://github.com/canonical/core-base/tree/e66d98a0d2aa893b0907dd3bbe9db09c3d274c5d

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.11 to 3.10.12-1~22.04.12:

  python3.10 (3.10.12-1~22.04.12) jammy-security; urgency=medium

    * SECURITY UPDATE: Possible payload obfuscation
      - debian/patches/CVE-2025-8291.patch: check consistency of
        the zip64 end of central dir record in Lib/zipfile.py,
        Lib/test/test_zipfile.py.
      - CVE-2025-8291
    * SECURITY UPDATE: Performance degradation
      - debian/patches/CVE-2025-6075.patch: fix quadratic complexity
        in os.path.expandvars() in Lib/ntpatch.py, Lib/posixpath.py,
        Lib/test/test_genericpatch.py, Lib/test/test_npath.py.
      - CVE-2025-6075

   -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com>  Tue, 04 Nov 2025 05:48:33 -0300

05/11/2025, commit https://github.com/canonical/core-base/tree/e66d98a0d2aa893b0907dd3bbe9db09c3d274c5d

[ Changes in the core22 snap ]

Philip Meulengracht (1):
      github: add fips release builds (#378)

[ Changes in primed packages ]

distro-info-data (built from distro-info-data) updated from 0.52ubuntu0.9 to 0.52ubuntu0.11:

  distro-info-data (0.52ubuntu0.11) jammy; urgency=medium

    * ubuntu.csv: remove eol-legacy field from resolute
      This version of distro-info does not know about eol-legacy.

   -- Nick Rosbrook <enr0n@ubuntu.com>  Fri, 10 Oct 2025 11:59:51 -0400

  distro-info-data (0.52ubuntu0.10) jammy; urgency=medium

    * Add Ubuntu 26.04 LTS "Resolute Raccoon" (LP: #2126961)
    * Correct date for forky
    * Correct estimation for trixie ELTS EoL to 10 years total support.
    * Update the bookworm EoL

   -- Florent 'Skia' Jacquet <florent.jacquet@canonical.com>  Fri, 10 Oct 2025 11:33:51 +0100

libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.4 to 0.9.6-2ubuntu0.22.04.5:

  libssh (0.9.6-2ubuntu0.22.04.5) jammy-security; urgency=medium

    * SECURITY UPDATE: NULL pointer dereference
      - debian/patches/CVE-2025-8114.patch: sets rc to SSH_ERROR prior to goto
        error in ssh_make_sessionid() of src/kex.c.
      - CVE-2025-8114

   -- Ian Constantin <ian.constantin@canonical.com>  Wed, 29 Oct 2025 14:58:26 +0200

09/10/2025, commit https://github.com/canonical/core-base/tree/6174ae97e09857c5e7e38f2a0599c7d2940acddf

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

cloud-init (built from cloud-init) updated from 25.1.4-0ubuntu0~22.04.1 to 25.2-0ubuntu1~22.04.1:

  cloud-init (25.2-0ubuntu1~22.04.1) jammy; urgency=medium

    * refresh patches
      - d/p/cli-retain-file-argument-as-main-cmd-arg.patch
      - d/p/deprecation-version-boundary.patch
      - d/p/grub-dpkg-support.patch
      - d/p/keep-dhclient-as-priority-client.patch
      - d/p/no-nocloud-network.patch
      - d/p/no-remove-networkd-online.patch
      - d/p/no-single-process.patch
      - d/p/retain-ec2-default-net-update-events.patch
      - d/p/retain-old-groups.patch
      - d/p/revert-551f560d-cloud-config-after-snap-seeding.patch
    * add d/p/strip-invalid-mtu.patch
      - Provides backwards compatibility for an other invalid
        MTU in a netplan config. (GH-6239)
    * Upstream snapshot based on 25.2. (LP: #2120495).
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/25.2/ChangeLog

   -- James Falcon <james.falcon@canonical.com>  Tue, 12 Aug 2025 14:48:04 -0500

dpkg (built from dpkg) updated from 1.21.1ubuntu2.3 to 1.21.1ubuntu2.6:

  dpkg (1.21.1ubuntu2.6) jammy-security; urgency=medium

    [ Joy Latten ]
    * SECURITY UPDATE:
    - Fix cleanup for control member with restricted directories. LP: #2122053
    - Fixes CVE-2025-6297

   -- Serge Hallyn <serge.hallyn@ubuntu.com>  Tue, 09 Sep 2025 15:09:16 -0500

libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.19 to 3.0.2-0ubuntu1.20:

  openssl (3.0.2-0ubuntu1.20) jammy-security; urgency=medium

    * SECURITY UPDATE: Out-of-bounds read & write in RFC 3211 KEK Unwrap
      - debian/patches/CVE-2025-9230.patch: fix incorrect check of unwrapped
        key size in crypto/cms/cms_pwri.c.
      - CVE-2025-9230

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 18 Sep 2025 08:06:16 -0400

libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.16 to 249.11-0ubuntu3.17:

  systemd (249.11-0ubuntu3.17) jammy; urgency=medium

    [ Nick Rosbrook ]
    * initramfs-tools: copy hwdb.bin to initramfs (LP: #2112237)
    * d/t/tests-in-lxd: drop patching workaround (LP: #2115263)
      - d/t/control: add Depends: dnsmasq-base
        (Revealed by test progressing past previous failure)

    [ Chengen Du ]
    * core/device: fix devlink handling (LP: #2100252)

   -- Nick Rosbrook <enr0n@ubuntu.com>  Tue, 26 Aug 2025 11:23:06 -0400

wpasupplicant (built from wpa) updated from 2:2.10-6ubuntu2.2 to 2:2.10-6ubuntu2.3:

  wpa (2:2.10-6ubuntu2.3) jammy; urgency=medium

    * Bump DEFAULT_BSS_MAX_COUNT to 1000 (LP: #2117180)

   -- Mitchell Augustin <mitchell.augustin@canonical.com>  Mon, 21 Jul 2025 18:13:31 -0500

23/09/2025, commit https://github.com/canonical/core-base/tree/6174ae97e09857c5e7e38f2a0599c7d2940acddf

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.10 to 2.35-0ubuntu3.11:

  glibc (2.35-0ubuntu3.11) jammy-security; urgency=medium

    * SECURITY UPDATE: double-free in regcomp function
      - debian/patches/any/CVE-2025-8058.patch: fix double-free after
        allocation failure in regcomp in posix/Makefile, posix/regcomp.c,
        posix/tst-regcomp-bracket-free.c.
      - CVE-2025-8058

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 17 Sep 2025 11:26:08 -0400

22/08/2025, commit https://github.com/canonical/core-base/tree/6174ae97e09857c5e7e38f2a0599c7d2940acddf

[ Changes in the core22 snap ]

Alfonso Sánchez-Beato (3):
      .github/workflows: add release-manual action
      .github/workflows/tests.yaml: make sure to run on spread-enabled runners
      many: ser snap version from date tag if present

[ Changes in primed packages ]

gcc-12-base:amd64, gcc-12-base:i386, libgcc-s1:amd64, libgcc-s1:i386, libstdc++6:amd64 (built from gcc-12) updated from 12.3.0-1ubuntu1~22.04 to 12.3.0-1ubuntu1~22.04.2:

  gcc-12 (12.3.0-1ubuntu1~22.04.2) jammy-security; urgency=medium

    * SECURITY UPDATE: A missed hardening option in -fstack-protector for AArch64
      can lead to buffer overflows for dynamically allocated local variables 
      not being detected. (LP: #2054343)
      - d/p/CVE-2023-4039.diff: Address stack protector and stack clash
        protection weaknesses on AArch64. Taken from the gcc-12 branch. 
      - CVE-2023-4039
    * Move allocator base to avoid conflict with high-entropy ASLR for x86-64
      Linux. Patch taken from LLVM. Fixes ftbfs. (LP: #2107313)
      - d/p/lp2107313-asan-allocator-base.diff
    * aarch64: Fix loose ldpstp check. (LP: #2116909)
      - d/p/lp2116909-aarch64-fix-loose-ldpstp-check.diff

   -- Gerald Yang <gerald.yang@canonical.com>  Tue, 15 Jul 2025 03:45:40 +0000

libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.5 to 2.72.4-0ubuntu2.6:

  glib2.0 (2.72.4-0ubuntu2.6) jammy; urgency=medium

    * Fix crash due to infinite recursion in MIME subclassing (LP: #2097496)

   -- Alessandro Astone <alessandro.astone@canonical.com>  Fri, 20 Jun 2025 15:38:50 +0200

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.10 to 3.10.12-1~22.04.11:

  python3.10 (3.10.12-1~22.04.11) jammy-security; urgency=medium

    * SECURITY UPDATE: Regular expression denial of service.
      - debian/patches/CVE-2025-6069.patch: Improve regex parsing in
        Lib/html/parser.py.
      - CVE-2025-6069
    * SECURITY UPDATE: Infinite loop when parsing tar archives.
      - debian/patches/CVE-2025-8194.patch: Raise exception when count < 0 in
        Lib/tarfile.py.
      - CVE-2025-8194

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Fri, 15 Aug 2025 12:02:43 -0230

30/07/2025, commit https://git.launchpad.net/snap-core22/tree/5915fa29307f6839820c681cf666367c164d1088

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

cloud-init (built from cloud-init) updated from 25.1.2-0ubuntu0~22.04.2 to 25.1.4-0ubuntu0~22.04.1:

  cloud-init (25.1.4-0ubuntu0~22.04.1) jammy-security; urgency=medium

    * refresh patches:
      - d/p/revert-usr-lib-systemd-units.patch
    * Upstream snapshot based on 25.1.4.
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/25.1.4/ChangeLog
      - Bugs fixed in this snapshot:
        + fix: disable cloud-init when non-x86 environments have no DMI-data
          and no strict datasources detected (LP: #2069607) (CVE-2024-6174)

   -- Chad Smith <chad.smith@canonical.com>  Tue, 24 Jun 2025 15:15:25 -0600

  cloud-init (25.1.3-0ubuntu0~22.04.1) jammy-security; urgency=medium

    * d/cloud-init-base.postinst: move existing hotplug-cmd fifo to root-only
      share dir (CVE-2024-11584)
    * Upstream security bugfix release based on 25.1.3.
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/25.1.3/ChangeLog
      - Bugs fixed in this snapshot:
      - security: make hotplug socket only writable by root (LP: #2114229)
        (CVE-2024-11584)
      - security: make ds-identify behavior strict datasource discovery on
        non-x86 platforms without DMI data (LP: #2069607) (CVE-2024-6174)

   -- Chad Smith <chad.smith@canonical.com>  Thu, 12 Jun 2025 20:28:18 -0600

gnutls-bin, libgnutls30:amd64 (built from gnutls28) updated from 3.7.3-4ubuntu1.6 to 3.7.3-4ubuntu1.7:

  gnutls28 (3.7.3-4ubuntu1.7) jammy-security; urgency=medium

    * SECURITY UPDATE: double-free via otherName in the SAN
      - debian/patches/CVE-2025-32988.patch: avoid double free when exporting
        othernames in SAN in lib/x509/extensions.c.
      - CVE-2025-32988
    * SECURITY UPDATE: OOB read via malformed length field in SCT extension
      - debian/patches/CVE-2025-32989.patch: fix read buffer overrun in SCT
        timestamps in lib/x509/x509_ext.c.
      - CVE-2025-32989
    * SECURITY UPDATE: heap write overflow in certtool via invalid template
      - debian/patches/CVE-2025-32990.patch: avoid 1-byte write buffer
        overrun when parsing template in src/certtool-cfg.c,
        tests/cert-tests/Makefile.am, tests/cert-tests/template-test.sh,
        tests/cert-tests/templates/template-too-many-othernames.tmpl.
      - CVE-2025-32990
    * SECURITY UPDATE: NULL deref via missing PSK in TLS 1.3 handshake
      - debian/patches/CVE-2025-6395.patch: clear HSK_PSK_SELECTED when
        resetting binders in lib/handshake.c, lib/state.c, tests/Makefile.am,
        tests/tls13/hello_retry_request_psk.c.
      - CVE-2025-6395

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 11 Jul 2025 09:13:17 -0400

iputils-ping (built from iputils) updated from 3:20211215-1 to 3:20211215-1ubuntu0.1:

  iputils (3:20211215-1ubuntu0.1) jammy-security; urgency=medium

    * SECURITY UPDATE: DoS via crafted ICMP Echo Reply packet
      - debian/patches/CVE-2025-47268: fix signed 64-bit integer overflow in
        RTT calculation in iputils_common.h, ping/ping_common.c.
      - debian/patches/CVE-2025-48964.patch: fix moving average rtt
        calculation in iputils_common.h, ping/ping.h, ping/ping_common.c.
      - CVE-2025-47268
      - CVE-2025-48964

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 24 Jul 2025 07:51:44 -0400

perl-base (built from perl) updated from 5.34.0-3ubuntu1.4 to 5.34.0-3ubuntu1.5:

  perl (5.34.0-3ubuntu1.5) jammy-security; urgency=medium

    * SECURITY UPDATE: threads race condition in file operations
      - debian/patches/fixes/CVE-2025-40909-metaconfig.diff: check for
        fdopendir in regen-configure/U/perl/d_fdopendir.U.
      - debian/patches/fixes/CVE-2025-40909-1.diff: clone dirhandles without
        fchdir in Configure, Cross/config.sh-arm-linux,
        Cross/config.sh-arm-linux-n770, Porting/Glossary, Porting/config.sh,
        config_h.SH, configure.com, plan9/config_sh.sample, sv.c,
        t/op/threads-dirh.t, win32/config.gc, win32/config.vc.
      - debian/patches/fixes/CVE-2025-40909-2.diff: minor corrections in
        Cross/config.sh-arm-linux, Cross/config.sh-arm-linux-n770,
        config_h.SH,plan9/config_sh.sample.
      - debian/patches/fixes/CVE-2025-40909-3.diff: use PerlLIO_dup_cloexec
        in Perl_dirp_dup to set O_CLOEXEC in sv.c.
      - debian/patches/fixes/CVE-2025-40909-metaconfig-reorder.diff: slightly
        reorder Configure and config_h.SH to match metaconfig output in
        Configure, config_h.SH.
      - debian/patches/fixes/CVE-2025-40909-generated.diff: update generated
        files and checksums in uconfig.sh, uconfig64.sh, uconfig.h,
        NetWare/config.wc.
      - CVE-2025-40909

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 25 Jul 2025 13:26:40 -0400

libsqlite3-0:amd64 (built from sqlite3) updated from 3.37.2-2ubuntu0.4 to 3.37.2-2ubuntu0.5:

  sqlite3 (3.37.2-2ubuntu0.5) jammy-security; urgency=medium

    * SECURITY UPDATE: Memory corruption via number of aggregate terms
      - debian/patches/CVE-2025-6965.patch: raise an error right away if the
        number of aggregate terms in a query exceeds the maximum number of
        columns in src/expr.c, src/sqliteInt.h.
      - CVE-2025-6965

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Fri, 18 Jul 2025 11:17:24 -0400

08/07/2025, commit https://git.launchpad.net/snap-core22/tree/5915fa29307f6839820c681cf666367c164d1088

[ Changes in the core22 snap ]

Philip Meulengracht (1):
      tools: aggregate old changelogs

[ Changes in primed packages ]

gpgv (built from gnupg2) updated from 2.2.27-3ubuntu2.3 to 2.2.27-3ubuntu2.4:

  gnupg2 (2.2.27-3ubuntu2.4) jammy-security; urgency=medium

    * debian/patches/fix-key-validity-regression-due-to-CVE-2025-
      30258.patch:
      - Fix a key validity regression following patches for CVE-2025-30258,
        causing trusted "certify-only" primary keys to be ignored when checking
        signature on user IDs and computing key validity. This regression makes
        imported keys signed by a trusted "certify-only" key have an unknown
        validity (LP: #2114775).

   -- dcpi <dcpi@u22vm>  Wed, 25 Jun 2025 13:54:28 +0000

libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.3 to 0.9.6-2ubuntu0.22.04.4:

  libssh (0.9.6-2ubuntu0.22.04.4) jammy-security; urgency=medium

    * SECURITY UPDATE: Write beyond bounds in binary to base64 conversion
      functions
      - debian/patches/CVE-2025-4877.patch: prevent integer overflow and
        potential OOB.
      - CVE-2025-4877
    * SECURITY UPDATE: Use of uninitialized variable in
      privatekey_from_file()
      - debian/patches/CVE-2025-4878-1.patch: initialize pointers where
        possible.
      - debian/patches/CVE-2025-4878-2.patch: properly check return value to
        avoid NULL pointer dereference.
      - CVE-2025-4878
    * SECURITY UPDATE: OOB read in sftp_handle function
      - debian/patches/CVE-2025-5318.patch: fix possible buffer overrun.
      - CVE-2025-5318
    * SECURITY UPDATE: ssh_kdf() returns a success code on certain failures
      - debian/patches/CVE-2025-5372-pre1.patch: Reformat ssh_kdf().
      - debian/patches/CVE-2025-5372.patch: simplify error checking and
        handling of return codes in ssh_kdf().
      - CVE-2025-5372
    * SECURITY UPDATE: Missing packet filter may expose to variant of
      Terrapin attack
      - debian/patches/missing_packet_filter.patch: implement missing packet
        filter for DH GEX.
      - No CVE number

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 02 Jul 2025 14:48:47 -0400

libpam-modules-bin, libpam-modules:amd64, libpam-runtime, libpam0g:amd64 (built from pam) updated from 1.4.0-11ubuntu2.5 to 1.4.0-11ubuntu2.6:

  pam (1.4.0-11ubuntu2.6) jammy-security; urgency=medium

    * SECURITY UPDATE: privilege escalation via pam_namespace
      - debian/patches-applied/pam_namespace_170.patch: sync pam_namespace
        module to version 1.7.0.
      - debian/patches-applied/pam_namespace_post170-*.patch: add post-1.7.0
        changes from upstream git tree.
      - debian/patches-applied/pam_namespace_revert_abi.patch: revert ABI
        change to prevent unintended issues in running daemons.
      - debian/patches-applied/CVE-2025-6020-1.patch: fix potential privilege
        escalation.
      - debian/patches-applied/CVE-2025-6020-2.patch: add flags to indicate
        path safety.
      - debian/patches-applied/CVE-2025-6020-3.patch: secure_opendir: do not
        look at the group ownership.
      - debian/patches-applied/CVE-2024-22365.patch: removed, included in
        patch cluster above.
      - CVE-2025-6020

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 12 Jun 2025 10:45:28 -0400

python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.2 to 1.26.5-1~exp1ubuntu0.3:

  python-urllib3 (1.26.5-1~exp1ubuntu0.3) jammy-security; urgency=medium

    * SECURITY UPDATE: Information disclosure through improperly disabled
      redirects.
      - debian/patches/CVE-2025-50181.patch: Add "retries" check and set retries
        to Retry.from_int(retries, redirect=False) as well as set
        raise_on_redirect in ./src/urllib3/poolmanager.py.
      - CVE-2025-50181

   -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>  Mon, 23 Jun 2025 17:07:25 -0230

libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.9 to 3.10.12-1~22.04.10:

  python3.10 (3.10.12-1~22.04.10) jammy-security; urgency=medium

    * SECURITY UPDATE: incorrect address list folding
      - debian/patches/CVE-2025-1795-1.patch: don't encode list separators in
        Lib/email/_header_value_parser.py,
        Lib/test/test_email/test__header_value_parser.py.
      - debian/patches/CVE-2025-1795-2.patch: fix AttributeError in the email
        module in Lib/email/_header_value_parser.py,
        Lib/test/test_email/test__header_value_parser.py.
      - CVE-2025-1795
    * SECURITY UPDATE: DoS via bytes.decode with unicode_escape
      - debian/patches/CVE-2025-4516.patch: fix use-after-free in the
        unicode-escape decoder with an error handler in
        Include/cpython/bytesobject.h, Include/cpython/unicodeobject.h,
        Lib/test/test_codeccallbacks.py, Lib/test/test_codecs.py,
        Objects/bytesobject.c, Objects/unicodeobject.c,
        Parser/string_parser.c.
      - CVE-2025-4516

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 27 May 2025 13:12:29 -0400

python3-requests (built from requests) updated from 2.25.1+dfsg-2ubuntu0.1 to 2.25.1+dfsg-2ubuntu0.3:

  requests (2.25.1+dfsg-2ubuntu0.3) jammy-security; urgency=medium

    * SECURITY UPDATE: Information Leak
      - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
        lookup instead of netloc
      - CVE-2024-47081

   -- Bruce Cable <bruce.cable@canonical.com>  Wed, 11 Jun 2025 13:27:31 +1000

sudo (built from sudo) updated from 1.9.9-1ubuntu2.4 to 1.9.9-1ubuntu2.5:

  sudo (1.9.9-1ubuntu2.5) jammy-security; urgency=medium

    * SECURITY UPDATE: Local Privilege Escalation via host option
      - debian/patches/CVE-2025-32462.patch: only allow specifying a host
        when listing privileges.
      - CVE-2025-32462

   -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 25 Jun 2025 08:48:23 -0400

12/06/2025, commit https://git.launchpad.net/snap-core22/tree/7c3b8a59559a1d01f35830501a6ef478213ae767

[ Changes in the core22 snap ]

No detected changes for the core22 snap

[ Changes in primed packages ]

libapt-pkg6.0:amd64 (built from apt) updated from 2.4.13 to 2.4.14:

  apt (2.4.14) jammy; urgency=medium

    * Fix buffer overflow, stack overflow, exponential complexity in
      apt-ftparchive Contents generation (LP: #2083697)
      - ftparchive: Mystrdup: Add safety check and bump buffer size
      - ftparchive: contents: Avoid exponential complexity and overflows
      - test framework: Improve valgrind support
      - test: Check that apt-ftparchive handles deep paths
      - increase valgrind cleanliness to make the tests pass
        - pkgcachegen: Use placement new to construct header
        - Workaround valgrind "invalid read" in ExtractTar::Go by moving large
          buffer from stack to heap. The large buffer triggered some bugs in
          valgrind stack clash protection handling.

   -- Julian Andres Klode <juliank@ubuntu.com>  Tue, 22 Oct 2024 15:09:58 +0200

cloud-init (built from cloud-init) updated from 24.4.1-0ubuntu0~22.04.2 to 25.1.2-0ubuntu0~22.04.2:

  cloud-init (25.1.2-0ubuntu0~22.04.2) jammy; urgency=medium

    * New bugfix release. (LP: #2113797)
      - Revert relocation of systemd units and service files from /usr/lib
        back to /lib so debhelper correctly enables cloud-init services in
        postinst

   -- Chad Smith <chad.smith@canonical.com>  Mon, 09 Jun 2025 17:00:37 -0600

  cloud-init (25.1.2-0ubuntu0~22.04.1) jammy; urgency=medium

    * Upstream snapshot based on 25.1.2. (LP: #2104165).
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/25.1.2/ChangeLog

   -- James Falcon <james.falcon@canonical.com>  Fri, 02 May 2025 12:47:51 -0500

  cloud-init (25.1.1-0ubuntu1~22.04.1) jammy; urgency=medium

    * Drop cpicks which are now upstream:
      - d/p/cpick-d75840be-fix-retry-AWS-hotplug-for-async-IMDS-5995
      - d/p/cpick-84806336-chore-Add-feature-flag-for-manual-network-waiting
      - d/p/cpick-c60771d8-test-pytestify-test_url_helper.py
      - d/p/cpick-8810a2dc-test-Remove-CiTestCase-from-test_url_helper.py
      - d/p/cpick-582f16c1-test-add-OauthUrlHelper-tests
      - d/p/cpick-9311e066-fix-Update-OauthUrlHelper-to-use-readurl-exception_cb
    * refresh patches
      - d/p/deprecation-version-boundary.patch
      - d/p/no-single-process.patch
      - d/p/retain-ec2-default-net-update-events.patch
      - d/p/revert-551f560d-cloud-config-after-snap-seeding.patch
    * sort hunks within all patches (--sort on quilt refresh)
    * d/cloud-init.templates:
      - Move VMware before OVF. See GH-4030
      - Enable CloudCIX by default
    * Upstream snapshot based on 25.1.1.
      List of changes from upstream can be found at
      https://raw.githubusercontent.com/canonical/cloud-init/25.1.1/ChangeLog

   -- Chad Smith <chad.smith@canonical.com>  Tue, 25 Mar 2025 10:33:28 -0600

python3-pkg-resources, python3-setuptools (built from setuptools) updated from 59.6.0-1.2ubuntu0.22.04.2 to 59.6.0-1.2ubuntu0.22.04.3:

  setuptools (59.6.0-1.2ubuntu0.22.04.3) jammy-security; urgency=medium

    * SECURITY UPDATE: path traversal vulnerability
      - debian/patches/CVE-2025-47273-pre1.patch: Extract
        _resolve_download_filename with test.
      - debian/patches/CVE-2025-47273.patch: Add a check to ensure the name
        resolves relative to the tmpdir.
      - CVE-2025-47273

   -- Fabian Toepfer <fabian.toepfer@canonical.com>  Wed, 28 May 2025 19:13:58 +0200

libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.15 to 249.11-0ubuntu3.16:

  systemd (249.11-0ubuntu3.16) jammy-security; urgency=medium

    * SECURITY UPDATE: race condition in systemd-coredump
      - debian/patches/CVE_2025_4598_1.patch: coredump: get rid of
        _META_MANDATORY_MAX.
      - debian/patches/CVE_2025_4598_2.patch: coredump: use %d in kernel core
        pattern.
      - debian/patches/CVE_2025_4598_3.patch: coredump: get rid of a bogus
        assertion.
      - CVE-2025-4598

   -- Octavio Galland <octavio.galland@canonical.com>  Wed, 04 Jun 2025 11:17:43 -0300