| Current Path : /snap/core22/current/usr/share/doc/ |
| Current File : //snap/core22/current/usr/share/doc/ChangeLog |
24/08/2026, commit https://github.com/canonical/core-base/tree/3d5932d91cd499a5cae182f213776150953fa0b4
[ Changes in the core22 snap ]
JP Meijers (1):
hooks: create /usr/lib/wsl mount point (#435)
Mohit Chachada (2):
README: document where to find changelog (#451)
github: sync release-manual workflow to the latest state of action-rebuild-base (#458)
Valentin David (1):
patch/netplan-apply.diff: fix path
[ Changes in primed packages ]
netplan-generator (0.107.1-3ubuntu0.22.04.4): new primed package
python3-netplan (0.107.1-3ubuntu0.22.04.4): new primed package
ca-certificates (built from ca-certificates) updated from 20240203~22.04.1 to 20260601~22.04.1:
ca-certificates (20260601~22.04.1) jammy-security; urgency=medium
* Update Mozilla certificate authority bundle to version 2.86
(LP: #2156786)
The following certificate authority was added (+):
+ e-Szigno TLS Root CA 2023
The following certificate authorities were removed (-):
- QuoVadis Root CA 2
- QuoVadis Root CA 3
- DigiCert Assured ID Root CA
- DigiCert Global Root CA
- DigiCert High Assurance EV Root CA
- SwissSign Gold CA - G2
- SecureTrust CA
- Secure Global CA
- COMODO Certification Authority
- Certigna
- certSIGN ROOT CA
- AffirmTrust Commercial
- AffirmTrust Networking
- AffirmTrust Premium
- AffirmTrust Premium ECC
- TeliaSonera Root CA v1
- Entrust Root Certification Authority - G2
- Entrust Root Certification Authority - EC1
- Trustwave Global Certification Authority
- Trustwave Global ECC P256 Certification Authority
- Trustwave Global ECC P384 Certification Authority
- GLOBALTRUST 2020
- GTS Root R2
- FIRMAPROFESIONAL CA ROOT-A WEB
The following certificate authority was renamed (~):
~ "OISTE Server Root RSA G1" (removed leading space)
* Update Mozilla certificate authority bundle to version 2.82
The following certificate authorities were added (+):
+ TrustAsia TLS ECC Root CA
+ TrustAsia TLS RSA Root CA
+ SwissSign RSA TLS Root CA 2022 - 1
+ OISTE Server Root ECC G1
+ OISTE Server Root RSA G1
The following certificate authorities were removed (-):
- GlobalSign Root CA
- Entrust.net Premium 2048 Secure Server CA
- Baltimore CyberTrust Root (closes: #1121936)
- Comodo AAA Services root
- XRamp Global CA Root
- Go Daddy Class 2 CA
- Starfield Class 2 CA
- CommScope Public Trust ECC Root-01
- CommScope Public Trust ECC Root-02
- CommScope Public Trust RSA Root-01
- CommScope Public Trust RSA Root-02
* Update Mozilla certificate authority bundle to version 2.74.
The following certificate authorities were added (+):
+ D-TRUST BR Root CA 2 2023
+ D-TRUST EV Root CA 2 2023
The following certificate authorities were removed (-):
- Entrust Root Certification Authority - G4
- SecureSign RootCA11
- Security Communication RootCA3
- SwissSign Silver CA - G2
* Update Mozilla certificate authority bundle to version 2.70.
The following certificate authorities were added (+):
+ Telekom Security TLS ECC Root 2020
+ Telekom Security TLS RSA Root 2023
+ FIRMAPROFESIONAL CA ROOT-A WEB
+ TWCA CYBER Root CA
+ SecureSign Root CA12
+ SecureSign Root CA14
+ SecureSign Root CA15
The following certificate authorities were removed (-):
- Security Communication Root CA (closes: #1063093)
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 15 Jun 2026 12:17:29 -0400
cloud-init (built from cloud-init) updated from 25.3-0ubuntu1~22.04.1 to 26.1-0ubuntu1~22.04.1:
cloud-init (26.1-0ubuntu1~22.04.1) jammy; urgency=medium
* d/p/0001-Revert-fix-DNS-resolution-performance-regression-dur.patch revert Ec2 URL change
* d/p/0001-Revert-fix-support-bond-names-in-network_data.patch revert bond name change
* d/rules: provide PACKAGED_VERSION env var to force setuptools version to
match downstream DEB_VERSION
* refresh patches:
- d/p/no-nocloud-network.patch
- d/p/no-single-process.patch
- d/p/retain-ec2-default-net-update-events.patch
- d/p/retain-setuptools.patch. Read PACKAGED_VERSION environment variable
- d/p/revert-551f560d-cloud-config-after-snap-seeding.patch
- d/p/status-do-not-remove-duplicated-data.patch
- d/p/status-retain-recoverable-error-exit-code.patch
* Upstream snapshot based on upstream/main at 52ef4d17.
* Upstream snapshot based on 26.1. (LP: #2146833).
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/26.1/ChangeLog
-- Chad Smith <chad.smith@canonical.com> Mon, 30 Mar 2026 12:56:49 -0600
distro-info-data (built from distro-info-data) updated from 0.52ubuntu0.11 to 0.72-0ubuntu0.22.04.1:
distro-info-data (0.72-0ubuntu0.22.04.1) jammy; urgency=medium
* New data update release
- Add Ubuntu Legacy Support extension data (new eol-legacy column)
(LP: #2131678)
- Move forward the Debian bookworm EoL (hand-off to LTS)
* Convert source package from a native package to an upstream package to
make it easier to track differences in the data versus in the packaging.
-- Benjamin Drung <bdrung@ubuntu.com> Tue, 14 Jul 2026 13:29:47 +0200
distro-info-data (0.52ubuntu0.12) jammy; urgency=medium
* Add Ubuntu 26.10 "Stonking Stingray" (LP: #2150234)
-- Oliver Reiche <oliver.reiche@canonical.com> Tue, 28 Apr 2026 16:20:05 +0200
libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.13 to 2.35-0ubuntu3.14:
glibc (2.35-0ubuntu3.14) jammy-security; urgency=medium
* SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets
- debian/patches/CVE-2026-4046.patch: Use pending character state in
IBM1390, IBM1399 character sets in iconvdata/Makefile,
iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.
- CVE-2026-4046
* SECURITY UPDATE: out-of-bounds write in deprecated debugging function
- debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in
ns_sprintrrf in resolv/ns_print.c.
- CVE-2026-5435
* SECURITY UPDATE: one byte heap buffer overflow in scanf %mc
- debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in
scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-
bz34008.c, stdio-common/vfscanf-internal.c.
- CVE-2026-5450
* SECURITY UPDATE: crash or info disclosure in ungetwc function
- debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte
stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.
- CVE-2026-5928
* SECURITY UPDATE: crash in deprecated debugging functions
- debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,
__p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.
- debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf
formatting of class, type values in resolv/ns_print.c.
- debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of
unknown records in ns_sprintrrf in resolv/ns_print.c.
- debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop
failure in ns_sprintrrf in resolv/ns_print.c.
- debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in
ns_sprintrrf in resolv/ns_print.c.
- debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-
ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.
- CVE-2026-6238
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 24 Jul 2026 08:11:17 -0400
libgnutls30:amd64 (built from gnutls28) updated from 3.7.3-4ubuntu1.8 to 3.7.3-4ubuntu1.9:
gnutls28 (3.7.3-4ubuntu1.9) jammy-security; urgency=medium
* SECURITY UPDATE: buffer overflow in DTLS handshake fragment reassembly
- debian/patches/CVE-2026-33846-pre1.patch: buffers: shorten
merge_handshake_packet using recv_buf in lib/buffers.c.
- debian/patches/CVE-2026-33846.patch: buffers: add more checks to DTLS
reassembly in lib/buffers.c.
- CVE-2026-33846
* SECURITY UPDATE: DTLS packets sequence number ordering issue
- debian/patches/CVE-2026-42009-pre1.patch: buffers: match DTLS datagrams by
sequence number in lib/buffers.c.
- debian/patches/CVE-2026-42009-1.patch: lib/buffers: ensure packets have
differing sequence numbers in lib/buffers.c.
- debian/patches/CVE-2026-42009-2.patch: buffers: fix handshake_compare when
sequence numbers match in lib/buffers.c.
- CVE-2026-42009
* SECURITY UPDATE: OOB read via malformed fragments with zero length and
non-zero offset
- debian/patches/CVE-2026-33845-pre1.patch: buffers: rename a variable in
parse_handshake_header in lib/buffers.c.
- debian/patches/CVE-2026-33845.patch: buffers: switch from end_offset over
to frag_length in lib/buffers.c, lib/gnutls_int.h.
- debian/patches/CVE-2026-33845-2.patch: buffers: simplify and tighten
parse_handshake_header checks in lib/buffers.c.
- CVE-2026-33845
* SECURITY UPDATE: malformed OCSP response issue
- debian/patches/CVE-2026-3832-pre1.patch: iterate ocsp response records
for matching certificate in doc/examples/ex-ocsp-client.c,
lib/cert-session.c, lib/ocsp-api.c, src/ocsptool-common.c.
- debian/patches/CVE-2026-3832-pre2.patch: fix formatting in
doc/examples/ex-ocsp-client.c, lib/cert-session.c, lib/ocsp-api.c,
src/ocsptool-common.c.
- debian/patches/CVE-2026-3832.patch: cert-session: fix multi-entry OCSP
revocation bypass in lib/cert-session.c.
- CVE-2026-3832
* SECURITY UPDATE: policy bypass via x509 case-sensitive comparisons
- debian/patches/CVE-2026-3833.patch: x509/name-constraints: compare domain
names case-insensitive in lib/x509/name_constraints.c.
- CVE-2026-3833
* SECURITY UPDATE: permitted name constrains were incorrectly ignored
- debian/patches/CVE-2026-42011.patch: x509/name_constraints: fix
intersecting empty constraints in lib/x509/name_constraints.c.
- CVE-2026-42011
* SECURITY UPDATE:
- debian/patches/CVE-2026-42010.patch: lib/auth/rsa_psk: fix binary PSK
identity lookup in lib/auth/rsa_psk.c.
- CVE-2026-42010
* SECURITY UPDATE: incorrect username parsing with NUL characters
- debian/patches/CVE-2026-5260-1.patch: lib/auth/rsa: check that ciphertext
matches the modulus size in lib/auth/rsa.c, lib/auth/rsa_psk.c.
- debian/patches/CVE-2026-5260-2.patch: lib/pkcs11_privkey: guard against
overreading on short ciphertexts in lib/pkcs11_privkey.c.
- CVE-2026-5260
* SECURITY UPDATE:
- debian/patches/CVE-2026-42012-pre1.patch: x509/hostname-verify: refactor
and simplify CN fallback logic in lib/x509/hostname-verify.c.
- debian/patches/CVE-2026-42012-pre2.patch: Fix for #1132 in
lib/includes/gnutls/gnutls.h.in, lib/x509/common.h,
lib/x509/name_constraints.c, lib/x509/output.c, lib/x509/virt-san.c,
lib/x509/x509.c, tests/Makefile.am, tests/x509-upnconstraint.c.
- debian/patches/CVE-2026-42012-pre3.patch: x509: add bare-bones awareness
of SRV virtual SAN in lib/includes/gnutls/gnutls.h.in, lib/x509/common.h,
lib/x509/name_constraints.c, lib/x509/output.c, lib/x509/virt-san.c,
lib/x509/x509.c.
- debian/patches/CVE-2026-42012-pre4.patch: datum, mem, str: add helper
functions to steal pointers in lib/datum.h, lib/mem.h, lib/str.h.
- debian/patches/CVE-2026-42012.patch: x509/hostname-verify: make URI/SRV
SAN preclude CN fallback in lib/x509/hostname-verify.c.
- CVE-2026-42012
* SECURITY UPDATE: incorrect URI or SRV Subject Alternative Names checking
- debian/patches/CVE-2026-42013-pre1.patch: x509/email-verify: call
fallback DN fallback in lib/x509/email-verify.c.
- debian/patches/CVE-2026-42013.patch: x509: prevent fallback on oversized
SAN in lib/x509/email-verify.c, lib/x509/hostname-verify.c.
- CVE-2026-42013
* SECURITY UPDATE: UaF when changing the Security Officer PIN
- debian/patches/CVE-2026-42014.patch: pkcs11_write: fix UAF and leak in
gnutls_pkcs11_token_set_pin in lib/pkcs11_write.c.
- CVE-2026-42014
* SECURITY UPDATE: buffer overflow when appending to a PKCS#12 bag
- debian/patches/CVE-2026-42015.patch: x509/pkcs12_bag: fix off-by-one in
bag element bounds check in lib/x509/pkcs12_bag.c.
- CVE-2026-42015
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 08 May 2026 14:50:04 -0400
gzip (built from gzip) updated from 1.10-4ubuntu4.1 to 1.10-4ubuntu4.2:
gzip (1.10-4ubuntu4.2) jammy-security; urgency=medium
* SECURITY UPDATE: insecure temp file handling
- debian/patches/CVE-2026-41991.patch: gzexe: use -C if lacking mktemp in
gzexe.in, zdiff.in.
- CVE-2026-41991
* SECURITY UPDATE: overflow in LZH decompression logic
- debian/patches/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z
in unlzh.c.
- CVE-2026-41992
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 03 Jul 2026 07:55:53 -0400
iproute2 (built from iproute2) updated from 5.15.0-1ubuntu2 to 5.15.0-1ubuntu2.2:
iproute2 (5.15.0-1ubuntu2.2) jammy; urgency=medium
* Modify tc/tbf and tc/htb to allow 64 bit burst parameter (LP: #2147525)
- /d/p/lp2147525-1-tc-tbf-enable-64-bit-burst.patch
- /d/p/lp2147525-2-tc-htb-enable-64-bit-burst.patch
-- Ioana Lazea <ioana.lazea@canonical.com> Wed, 15 Apr 2026 10:15:26 +0300
iproute2 (5.15.0-1ubuntu2.1) jammy; urgency=medium
* Modify tc police to permit burst sizes up greater than 4GB (LP: #2125448)
- /d/p/2001-lib-Update-backend-of-print_size-to-accept-64-bit-si.patch
- /d/p/2002-tc-Add-get_size64-and-get_size64_and_cell.patch
- /d/p/2003-tc-Expand-tc_calc_xmittime-tc_calc_xmitsize-to-u64.patch
- /d/p/2004-tc-police-enable-use-of-64-bit-burst-parameter.patch
-- Jorge Merlino <jorge.merlino@canonical.com> Fri, 03 Oct 2025 10:53:16 -0300
kmod, libkmod2:amd64 (built from kmod) updated from 29-1ubuntu1 to 29-1ubuntu1.1:
kmod (29-1ubuntu1.1) jammy-security; urgency=medium
* Disable loading of algif_aead module to mitigate CVE-2026-31431
(LP: #2150743)
- debian/modprobe.d/disable-algif_aead.conf
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 30 Apr 2026 08:32:42 -0400
libgssapi-krb5-2:amd64, libk5crypto3:amd64, libkrb5-3:amd64, libkrb5support0:amd64 (built from krb5) updated from 1.19.2-2ubuntu0.7 to 1.19.2-2ubuntu0.8:
krb5 (1.19.2-2ubuntu0.8) jammy-security; urgency=medium
* SECURITY UPDATE: nteger underflow berval2tl_data()
- debian/patches/CVE-2026-11850.patch: Prevent read overrun in libkdb_ldap
in src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c.
- CVE-2026-11850
* SECURITY UPDATE: security issues in the NegoEx mechanism
- debian/patches/CVE-2026-4035x.patch: Fix two NegoEx parsing
vulnerabilities in src/lib/gssapi/spnego/negoex_util.c.
- CVE-2026-40355
- CVE-2026-40356
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 15 Jul 2026 14:26:34 -0400
libcap2-bin, libcap2:amd64 (built from libcap2) updated from 1:2.44-1ubuntu0.22.04.2 to 1:2.44-1ubuntu0.22.04.3:
libcap2 (1:2.44-1ubuntu0.22.04.3) jammy-security; urgency=medium
* SECURITY UPDATE: potential TOCTOU race condition in cap_set_file()
- debian/patches/CVE-2026-4878.patch: fix race in libcap/cap_file.c,
progs/quicktest.sh.
- CVE-2026-4878
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 09 Apr 2026 11:04:48 -0400
libgcrypt20:amd64 (built from libgcrypt20) updated from 1.9.4-3ubuntu3 to 1.9.4-3ubuntu3.2:
libgcrypt20 (1.9.4-3ubuntu3.2) jammy-security; urgency=medium
* SECURITY UPDATE: Heap-based buffer overflow via crafted ECDH ciphertext
- debian/patches/CVE-2026-41989.patch: cipher:ecc: Fix decoding a point on
Montgomery curve. in cipher/ecc-misc.c.
- CVE-2026-41989
* This package does _not_ contain the changes from 1.9.4-3ubuntu3.1 in
jammy-proposed.
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 12 May 2026 14:17:54 +0200
libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3ubuntu0.4 to 1.6.37-3ubuntu0.6:
libpng1.6 (1.6.37-3ubuntu0.6) jammy-security; urgency=medium
* SECURITY UPDATE: Interpretation conflict in APNG parser
paths.
- debian/patches/CVE-2026-40930.patch: Restructure the trailing-fdAT
path in pngpread.c
- debian/patches/CVE-2026-40930-post1.patch: Fix hardcoded length in
png_ensure_sequence_number in pngpread.c
- CVE-2026-40930
-- Kyle Kernick <kyle.kernick@canonical.com> Thu, 13 Aug 2026 10:20:26 -0600
libpng1.6 (1.6.37-3ubuntu0.5) jammy-security; urgency=medium
* SECURITY UPDATE: use-after-free via shared buffers
- debian/patches/CVE-2026-33416-pre1.patch: Fix a memory leak in
png_set_tRNS in pngset.c.
- debian/patches/CVE-2026-33416-pre2.patch: Avoid a memory leak when
allocation of a pCAL buffer fails in pngset.c.
- debian/patches/CVE-2026-33416-1.patch: fix: Resolve use-after-free on
`png_ptr->trans_alpha` in pngread.c, pngrutil.c, pngset.c, pngwrite.c.
- debian/patches/CVE-2026-33416-2.patch: fix: Resolve use-after-free on
`png_ptr->palette` in pngread.c, pngrtran.c, pngrutil.c, pngset.c,
pngwrite.c.
- debian/patches/CVE-2026-33416-3.patch: fix: Initialize tail bytes in
`trans_alpha` buffers in pngset.c.
- debian/patches/CVE-2026-33416-4.patch: fix: Sync `info_ptr->palette` after
in-place transforms in pngrtran.c.
- debian/patches/CVE-2026-33416-5.patch: fix: Sync `info_ptr->palette`
unconditionally after in-place transforms in pngrtran.c.
- CVE-2026-33416
* SECURITY UPDATE: out-of-bounds access in ARM palette expansion path
- debian/patches/CVE-2026-33636.patch: fix(arm): Resolve out-of-bounds
read/write in NEON palette expansion in arm/palette_neon_intrinsics.c.
- CVE-2026-33636
* SECURITY UPDATE: getter-to-setter aliasing issues
- debian/patches/CVE-2026-34757-1.patch: fix: Handle self-referencing
pointers in getter-to-setter aliasing in CMakeLists.txt, Makefile.am,
contrib/libtests/pnggetset.c, pngset.c, tests/pnggetset.
- debian/patches/CVE-2026-34757-2.patch: fix: Handle getter-to-setter
aliasing in append-style chunk setters in contrib/libtests/pnggetset.c,
pngset.c.
- debian/rules: set exec permissions on tests/pnggetset.
- CVE-2026-34757
* SECURITY UPDATE: integer overflow in rowbytes computation
- debian/patches/rowbytes_overflow.patch: fix: Prevent integer overflow in
rowbytes computation in pngrtran.c.
- No CVE number
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 05 May 2026 15:14:16 -0400
libncurses6:amd64, libncursesw6:amd64, libtinfo6:amd64, ncurses-base, ncurses-bin (built from ncurses) updated from 6.3-2ubuntu0.1 to 6.3-2ubuntu0.2:
ncurses (6.3-2ubuntu0.2) jammy-security; urgency=medium
* SECURITY UPDATE: stack-based buffer overflow in infocmp
- debian/patches/CVE-2025-69720.patch: clamp length to
MAX_TERMINFO_LENGTH before copying into buf2 in analyze_string.
- CVE-2025-69720
-- Paulo Flabiano Smorigo <pfsmorigo@canonical.com> Tue, 30 Jun 2026 21:25:30 +0000
libnetplan0:amd64, netplan.io (built from netplan.io) updated from 0.106.1-7ubuntu0.22.04.4 to 0.107.1-3ubuntu0.22.04.4:
netplan.io (0.107.1-3ubuntu0.22.04.4) jammy; urgency=medium
* d/p/lp2076319-fix-dir-permissions.patch:
Change default umask when creating dirctories (LP: #2076319)
-- Robert Malz <robert.malz@canonical.com> Wed, 23 Apr 2026 14:17:38 +0100
netplan.io (0.107.1-3ubuntu0.22.04.3) jammy; urgency=medium
* debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:
execute udev rules before starting sriov apply service (LP: #2139598)
-- Robert Malz <robert.malz@canonical.com> Tue, 03 Mar 2026 12:18:29 +0100
netplan.io (0.107.1-3ubuntu0.22.04.2) jammy; urgency=medium
* debian/patches/lp1988018: VF-LAG activation
Fixes the order in which SR-IOV configuration is performed and
cooperates with VF-LAG activation (LP: #1988018).
* debian/patches/lp2020409:
Enables setting the embedded-switch mode without having to define
virtual functions (LP: #2020409).
* debian/libnetplan0.symbols: New symbol _netplan_netdef_get_bond_mode.
-- Danilo Egea Gondolfo <danilo.egea.gondolfo@canonical.com> Mon, 07 Oct 2024 10:57:38 +0100
netplan.io (0.107.1-3ubuntu0.22.04.1) jammy; urgency=medium
* Backport netplan.io 0.107.1-3 to 22.04 (LP: #2058031):
- Support for "dummy" (`dummy-devices`) interfaces (LP: 1774203) (!361)
- Support for "veth" (`virtual-ethernets`) interfaces (!368)
- Add Python bindings for libnetplan (!385)
- netplan: Handle command exceptions (!334)
- WPA3 (personal) support (LP: 2023238) (!369)
- Add all the commands to the bash completion file (LP: 1749869) (!326)
- New submodule for state manipulation (!379)
- commands/status: show routes from all routing tables (!390)
- cli:status: Make rich pretty printing optional (!388)
- libnetplan: expose dhcp4 and dhcp6 properties (!394)
- Expose macaddress and DNS configuration from the netdef (!395)
- libnetplan: expose the routes list in the netdef (!397)
- NetworkManager: Wireguard private key flag support (!371)
- Add a netplan_parser_load_keyfile() Python binding (!351)
- keyfile parser: add support for all tunnel types (LP: 2016473) (!360)
- parse-nm:wg: add support for reading the listen-port property (!372)
- parse-nm: add support for VRF devices (!398)
- Vlan keyfile parser support (!370)
- Netplan docs rework (!333 & !337)
- docs: Add a short netplan-everywhere howto (!325)
- doc: make us of sphinx copybutton plugin (!354)
- doc: Add Ubuntu Code of Conduct 2.0 (!355)
- doc: Explanation about 00-network-manager-all.yaml (!378)
- wifi: add support for WPA3-Enterprise (LP: 2029876) (!402)
- wifi: support WPA2 and WPA3 Personal simultaneously (!404)
- added mii-monitor-interval example (!411)
- docs: Add "Contribute Documentation" how-to
- auth: add support for LEAP and EAP-PWD (!415)
- tests: Add autopkgtest for (LP: 1959570) (!419)
- wifi: make it possible to have a psk and an eap password simultaneously
(!416)
- doc: Set-up some basic Doxygen project (!423)
- doc: Make Sphinx to handle autodoxygen project, using breathe (!423)
- doc: create libnetplan apidoc structure (!423)
- inc: Start documenting public API (!423)
- doc: Update 'Netplan everywhere' for 23.10 (!418)
SECURITY UPDATE: weak permissions on secret files, command injection
- d/p/lp2065738/0014-libnetplan-use-more-restrictive-file-permissions.patch:
Use more restrictive file permissions to prevent unprivileged users to
read sensitive data from back end files (LP: 2065738, 1987842)
- CVE-2022-4968
- d/p/lp2066258/0015-libnetplan-escape-control-characters.patch:
Escape control characters in the parser and double quotes in backend
files.
- d/p/lp2066258/0016-backends-escape-file-paths.patch:
Escape special characters in file paths.
- d/p/lp2066258/0017-backends-escape-semicolons-in-service-units.patch:
Escape isolated semicolons in systemd service units. (LP: 2066258)
- debian/netplan-generator.postinst: Add a postinst maintainer script to
call the generator. It's needed so the file permissions fixes will be
applied automatically.
Bug fixes:
- Fix FTBFS on Fedora and refresh RPM packaging (!323)
- parser: validate lacp-rate properly (LP: 1745648) (!324)
- use meson-make-symlink.sh helper instead of install_symlink() (!327)
- netplan: cli: fix typo from 'unkown' to 'unknown' (!328)
- Handle duplication during parser second pass (LP: 2007682) (!329)
- parse:ovs: Ignore deprecated OpenFlow1.6 protocol (LP: 1963735) (!332)
- dbus: Build the copy path correctly (!331)
- tests: add new spread based snapd integration test (!330)
- Use controlled execution environment, to avoid failure if PATH is unset
(LP: 1959570) (!336)
- Some refactoring (!338)
- netplan: adjust the maximum buffer size to 1MB (!340)
- parse: use "--" with systemd-escape (!347)
- docs: fix bridge parameters types and add examples (!346)
- vrfs: skip policies parsing if list is NULL (LP: 2016427) (!341)
- networkd: plug a memory leak (!344)
- libnetplan: don't try to read from a NULL file (!342)
- nm: return if write_routes() fails (!345)
- parse: plug a memory leak (!348)
- parse: set the backend on nm-devices to NM (!349)
- parse: don't point to the wrong node on validation (!343)
- rtd: set the OS and Python versions explicitly (!357)
- Fix 8021x eap method parsing (LP: 2016625) (!358)
- CI: update canonical/setup-lxd to v0.1.1 (!359)
- CI: fix dch after adding the new 0.106.1 tag (!364)
- Provide frequency to wpa_supplicant in adhoc mode (LP: 2020754) (!363)
- Improve the coverage of the memory leak tests (!365)
- Fix keyfile parsing of wireguard config (!366)
- routes: fix metric rendering (LP: 2023681) (!367)
- CI: add DebCI integration test (!362)
- CI: initial NetworkManager autopkgtests (!374)
- parse-nm: handle cloned-mac-address special cases (LP: 2026230) (!376)
- Improve autopkgtest stability with systemd 253 & iproute 6.4 (!377)
- Fixes for minor issues (!380)
- tests:integration: Adopt for systemd v254 (Closes: #1041310) (!381)
- parse: Downgrade NM passthrough warning to debug (!384)
- Don't drop files with just global values (LP: 2027584) (!382)
- Fixing Coverity issues (!383)
- CLI: Refactoring to avoid namespace clash with public bindings (!387)
- tests: fix test coverage report with newer python-coverage (!389)
- github: add a scheduled action to run Coverity (!391)
- github: only run the coverity workflow on our repository (!392)
- Addressing a few issues found (!393)
- Wireguard fixes (!352)
- Fix a memory leak, an assert and an error message (!350)
- ovs: don't allow peers with the same name (!353)
- CI: make use of the canonical/setup-lxd action (!356)
- test:ovs: Avoid NetworkManager taking contol, breaking a test
- parse: allow COMMON_LINK_HANDLERS for VRFs (!401)
- util: don't return a placeholder netdef in the iterator (!406)
- tunnels/validation: do not error out if "local" is not defined (!407)
- tests: add some integration tests without the local address (!407)
- wireguard: ignore empty endpoints (LP: 2038811) (!414)
- parse: improve the parsing of access-points (LP: 1809994) (!413)
- wifi: replace the previously defined AP with the new one (!413)
- doc: spelling check improvements (!417)
- Fix permissions on folder '/run/NetworkManager/' (!422)
- cli:try: avoid linting error for type hints (Closes: #1058524) (!422)
- nm-parse: always read the PSK into the new psk variable (!416)
- networkd: fix formatting (!424)
- networkd: replace deprecated CriticalConnection= by KeepConfiguration=
(!424)
- networkd: move KeepConfiguration= into [Network] section
- apply: bring "lo" back up if it's managed by NM (!408)
- apply: don't assume the NM loopback connection is called "lo" (!408)
Packaging restructuring:
- Split netplan-generator into separate package to make the Python
dependency optional.
- Split python3-netplan bindings into a separate package
* Add patches for bug fixes from netplan.io 1.0-1 and 1.0.1-1:
- debian/patches/lp2041727:
Check if ovsdb-server.service is active before displaying warning
(LP: 2041727) (!421)
- d/p/0004-tests-assert-generated-.service-files-in-assert_srio.patch,
d/p/0005-tests-sriov-test-if-the-generated-netplan-rebind-ser.patch,
d/p/0006-sriov-don-t-generate-duplicate-entries-in-the-rebind.patch:
Don't generate duplicate entries in the netplan-sriov-rebind.service
(!437)
- d/p/0017-emitter-allow-unicode-characters-in-the-emitter.patch.
Allow non-ascii characters in the YAML emitter (LP: 2071652) (!485).
- d/p/0018-parse-do-not-escape-all-non-ascii-bytes.patch.
Don't escape all non-ascii bytes (!486).
* Drop patches not required for 22.04:
- debian/patches/python-limited-stable-api.patch
- d/p/sru-compat/0013-Keep-old-file-permission-for-backwards-compatibility.patch.
From now on we want libnetplan to create files with tight permissions.
* Add patches for SRU backwards compatibility:
- 0014-Demote-lacp-rate-validation-error-to-warning-for-bac.patch:
Convert the error to a warning in a new validation for the option
'lacp-rate' to prevent breaking existing setups
* debian/control:
- Drop python3-rich dependency to Suggests
- Drop build dependency on systemd-dev
* debian/netplan.io.preinst:
- This preinst script is intended to cleanup the .pyc files from
share/netplan/netplan. This directory is supposed to be removed after
the upgrade from netplan.io 0.106.1 to 0.107.1, as the Python code
was moved to it's own python3-netplan package, but it's left behind
due to Python cached files.
* Drop changes related to usr-merge and not required for 22.04
- debian/netplan-generator.install
- debian/netplan-generator.dirs
- debian/netplan-generator.postinst
- debian/netplan-generator.preinst
* d/netplan-generator.lintian-overrides, d/netplan.io.lintian-overrides:
- Drop overrides file. It wasn't really silencing any lintian warnings.
-- Danilo Egea Gondolfo <danilo.egea.gondolfo@canonical.com> Fri, 16 Aug 2024 17:59:32 +0100
openssh-client, openssh-server, openssh-sftp-server (built from openssh) updated from 1:8.9p1-3ubuntu0.14 to 1:8.9p1-3ubuntu0.16:
openssh (1:8.9p1-3ubuntu0.16) jammy-security; urgency=medium
* SECURITY UPDATE: sftp downloaded files location issue
- debian/patches/CVE-2026-59995.patch: upstream: avoid download to server-
controlled path when performing in sftp.c.
- CVE-2026-59995
* SECURITY UPDATE: scp parent directory issue
- debian/patches/CVE-2026-59996.patch: upstream: resist that return ".." via
remote glob during in scp.c.
- CVE-2026-59996
* SECURITY UPDATE: internal-sftp ignores more than 9 commandline args
- debian/patches/CVE-2026-59997.patch: upstream: pass >9 commandline
arguments to the internal-sftp server, in session.c.
- CVE-2026-59997
* SECURITY UPDATE: undocumented GSSAPIStrictAcceptorCheck behaviour
- debian/patches/CVE-2026-59998.patch: upstream: mention a caveat regarding
GSSAPIStrictAcceptorCheck in in sshd_config.5.
- CVE-2026-59998
* SECURITY UPDATE: DisableForwarding=yes not taking proper precedence
- debian/patches/CVE-2026-59999.patch: upstream: DisableForwarding=yes
didn't override PermitTunnel=yes in serverloop.c.
- CVE-2026-59999
* SECURITY UPDATE: DoS via MaxAuthTries mishandling
- debian/patches/CVE-2026-60000-1.patch: upstream: Fix multiple RFC 4462
(GSSAPIAuthentication) compliance in auth2-gss.c.
- debian/patches/CVE-2026-60000-2.patch: upstream: unused variables in
auth2-gss.c.
- CVE-2026-60000
* SECURITY UPDATE: minimum authentication delay not always honoured
- debian/patches/CVE-2026-60001.patch: upstream: Fix cases in GSSAPI and
keyboard-interactive in auth.h, auth2-chall.c, auth2-gss.c, auth2.c.
- CVE-2026-60001
* SECURITY UPDATE: Use-after-free during a key re-exchange
- debian/patches/CVE-2026-60002.patch: upstream: fix ownership and lifetime
of several bits of client in ssh.c, sshconnect.c, sshconnect.h,
sshconnect2.c.
- CVE-2026-60002
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 09 Jul 2026 14:38:00 -0400
openssh (1:8.9p1-3ubuntu0.15) jammy-security; urgency=medium
* SECURITY UPDATE: unexpected scp setuid and setgid
- debian/patches/CVE-2026-35385.patch: clear setuid/setgid bits from
downloaded files in scp.c.
- CVE-2026-35385
* SECURITY UPDATE: command execution via shell metacharacters in username
- debian/patches/CVE-2026-35386-pre1.patch: apply validity rules on
ProxyJump usernames and hostnames in readconf.c, readconf.h, ssh.c.
- debian/patches/CVE-2026-35386.patch: move username check earlier in
ssh.c.
- CVE-2026-35386
* SECURITY UPDATE: use of unintended ECDSA algorithms
- debian/patches/CVE-2026-35387_35414.patch: correctly match ECDSA
signature algorithms against algorithm allowlists in
auth2-hostbased.c, auth2-pubkey.c, sshconnect2.c.
- CVE-2026-35387
* SECURITY UPDATE: missing connection multiplexing confirmation
- debian/patches/CVE-2026-35388.patch: add missing askpass check in
mux.c.
- CVE-2026-35388
* SECURITY UPDATE: authorized_keys principals option mishandling
- debian/patches/CVE-2026-35387_35414.patch: check for commas in
auth2-pubkey.c.
- CVE-2026-35414
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 27 Apr 2026 20:38:10 -0400
libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.23 to 3.0.2-0ubuntu1.26:
openssl (3.0.2-0ubuntu1.26) jammy-security; urgency=medium
* SECURITY UPDATE: HollowByte Denial of Service issue (LP: #2161371)
- debian/patches/lp2161371.patch: Grow the init_buf incrementally as we
receive data in ssl/statem/statem.c, ssl/statem/statem_lib.c.
- No CVE number
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 29 Jul 2026 12:56:04 -0400
openssl (3.0.2-0ubuntu1.25) jammy-security; urgency=medium
* SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing
- debian/patches/CVE-2026-34180.patch: Avoid length truncation in
ASN1_STRING_set in crypto/asn1/tasn_dec.c.
- CVE-2026-34180
* SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages
- debian/patches/CVE-2026-34182-pre1.patch: Ensure
ossl_cms_EncryptedContent_init_bio() reports an error on no OID in
crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt,
include/openssl/cmserr.h.
- debian/patches/CVE-2026-34182-1.patch: CMS: Produce error when AEAD
algorithms are used in enveloped data in crypto/cms/cms_enc.c,
crypto/cms/cms_env.c, crypto/cms/cms_err.c, crypto/cms/cms_local.h,
crypto/err/openssl.txt, include/openssl/cmserr.h, test/cms-msg/enveloped-
content-type-for-aes-gcm.pem, test/cmsapitest.c,
test/recipes/80-test_cms.t.
- debian/patches/CVE-2026-34182-2.patch: Reject potentially forged encrypted
CMS AuthEnvelopedData messages in crypto/cms/cms_enc.c.
- debian/patches/CVE-2026-34182-3.patch: Add tests for CVE-2026-34182 in
test/cmsapitest.c.
- CVE-2026-34182
* SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption
- debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference
processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c.
- CVE-2026-42766
* SECURITY UPDATE: NULL Pointer Dereference in CRMF EncryptedValue Decryption
- debian/patches/CVE-2026-42767.patch: Fix potential NULL dereference in
OSSL_CRMF_ENCRYPTEDVALUE_decrypt() in crypto/crmf/crmf_lib.c.
- CVE-2026-42767
* SECURITY UPDATE: FFC-DH Peer Validation Uses Attacker-Supplied q
- debian/patches/CVE-2026-42770.patch: Match the local q DHX parameter
against the peer's q in providers/implementations/exchange/dh_exch.c.
- CVE-2026-42770
* SECURITY UPDATE: AES-OCB IV Ignored on EVP_Cipher() Path
- debian/patches/CVE-2026-45445.patch: Apply the buffered IV on the AES-OCB
EVP_Cipher() path in providers/implementations/ciphers/cipher_aes_ocb.c,
test/evp_extra_test.c.
- CVE-2026-45445
* SECURITY UPDATE: Incorrect Tag Processing for Empty Messages in
AES-GCM-SIV and AES-SIV modes
- debian/patches/CVE-2026-45446.patch: Fix handling of empty-ciphertext
messages in AES-SIV in providers/implementations/ciphers/cipher_aes_siv.c,
test/evp_extra_test.c.
- CVE-2026-45446
* SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify()
- debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary
PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in
OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in
PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty-
digest-set.eml.
- CVE-2026-45447
* SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String
Conversion
- debian/patches/CVE-2026-7383.patch: Reject oversized inputs in
ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c.
- CVE-2026-7383
* SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption
- debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds
read in check-byte validation in crypto/cms/cms_pwri.c.
- CVE-2026-9076
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 02 Jun 2026 15:33:25 -0400
libpam-modules-bin, libpam-modules:amd64, libpam-runtime, libpam0g:amd64 (built from pam) updated from 1.4.0-11ubuntu2.6 to 1.4.0-11ubuntu2.7:
pam (1.4.0-11ubuntu2.7) jammy-security; urgency=medium
* SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb
module string comparisons
- debian/patches/CVE-2026-54411-pre1.patch: libpam: add helper to compare
strings in constant time in libpam/include/pam_inline.h.
- debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison
timing leak in libpam/include/pam_inline.h,
modules/pam_userdb/pam_userdb.c.
- CVE-2026-54411
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 16 Jul 2026 10:06:00 -0400
perl-base (built from perl) updated from 5.34.0-3ubuntu1.5 to 5.34.0-3ubuntu1.7:
perl (5.34.0-3ubuntu1.7) jammy-security; urgency=high
* SECURITY UPDATE: integer overflow in regular expression compiler
- debian/patches/CVE-2026-8376_1.patch: accept quantifier limit error
on 32-bit architectures where the quantifier limit catches the
oversized pattern before the overflow guard
- CVE-2026-8376
-- Chrisa Oikonomou <chrisa.oikonomou@canonical.com> Mon, 23 Jun 2026 11:11:00 +0300
perl (5.34.0-3ubuntu1.6) jammy-security; urgency=high
* SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction
- debian/patches/CVE-2026-42496.patch: validate symlink and hardlink
targets against absolute paths and directory traversal in
cpan/Archive-Tar/lib/Archive/Tar.pm
- CVE-2026-42496
* SECURITY UPDATE: integer overflow in regular expression compiler
- debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer
overflow via quantified fixed-string regex in t/re/pat_psycho.t
- debian/patches/CVE-2026-8376_2.patch: add overflow check before
fixed-string buffer allocation in regcomp.c / regcomp_study.c
- CVE-2026-8376
-- Chrisa Oikonomou <chrisa.oikonomou@canonical.com> Fri, 12 Jun 2026 16:42:26 +0300
libpolkit-agent-1-0:amd64, libpolkit-gobject-1-0:amd64, polkitd (built from policykit-1) updated from 0.105-33 to 0.105-33ubuntu0.1:
policykit-1 (0.105-33ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: OOB write via nested elements in XML policy
- debian/patches/CVE-2025-7519.patch: check depth in
src/polkitbackend/polkitbackendactionpool.c.
- CVE-2025-7519
* SECURITY UPDATE: DoS via excessively long input
- debian/patches/CVE-2026-4897.patch: fix getline() string overflow in
src/polkitagent/polkitagenthelperprivate.c.
- CVE-2026-4897
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 10 Apr 2026 06:59:20 -0400
python3-idna (built from python-idna) updated from 3.3-1ubuntu0.1 to 3.3-1ubuntu0.2:
python-idna (3.3-1ubuntu0.2) jammy-security; urgency=medium
* SECURITY UPDATE: DoS via specially crafted inputs to idna.encode()
- debian/patches/CVE-2026-45409-1.patch: Reject oversized inputs up-front in
idna/core.py, tests/test_idna.py.
- debian/patches/CVE-2026-45409-2.patch: Use valid_string_length() for early
oversized-input check in idna/core.py.
- debian/patches/CVE-2026-45409-3.patch: Enforce early length limits in
check_label in idna/core.py, tests/test_idna.py.
- CVE-2026-45409
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 14 Jul 2026 13:21:34 -0400
python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.6 to 1.26.5-1~exp1ubuntu0.7:
python-urllib3 (1.26.5-1~exp1ubuntu0.7) jammy-security; urgency=medium
* SECURITY UPDATE: sensitive headers not stripped in cross-origin redirects
- debian/patches/CVE-2026-44431.patch: remove sensitive headers in proxy
pools too in src/urllib3/connectionpool.py,
test/with_dummyserver/test_proxy_poolmanager.py.
- CVE-2026-44431
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 22 May 2026 16:41:35 -0400
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.15 to 3.10.12-1~22.04.16:
python3.10 (3.10.12-1~22.04.16) jammy-security; urgency=medium
* SECURITY UPDATE: incorrect normalization in tarfile module
- debian/patches/CVE-2025-13462.patch: Skip TarInfo DIRTYPE normalization
during GNU long name handling in Lib/tarfile.py,
Lib/test/test_tarfile.py.
- CVE-2025-13462
* SECURITY UPDATE: crash in Markdown parsing
- debian/patches/CVE-2025-69534-1.patch: Fix comment parsing in HTMLParser
according to the HTML5 standard in Lib/html/parser.py,
Lib/test/test_htmlparser.py.
- debian/patches/CVE-2025-69534-2.patch: Fix parsing start and end tags in
HTMLParser according to the HTML5 standard in Lib/html/parser.py,
Lib/test/support/__init__.py, Lib/test/test_htmlparser.py.
- debian/patches/CVE-2025-69534-3.patch: Fix parsing attributes with
whitespaces around the "=" separator in HTMLParser in Lib/html/parser.py,
Lib/test/test_htmlparser.py.
- debian/patches/CVE-2025-69534-4.patch: Fix support of elements "textarea"
and "title" in HTMLParser in Lib/html/parser.py,
Lib/test/test_htmlparser.py.
- debian/patches/CVE-2025-69534-5.patch: Fix CDATA section parsing in
HTMLParser in Lib/html/parser.py, Lib/test/test_htmlparser.py.
- debian/patches/CVE-2025-69534-6.patch: Support more RAWTEXT and PLAINTEXT
elements in HTMLParser in Doc/library/html.parser.rst, Lib/html/parser.py,
Lib/test/test_htmlparser.py.
- CVE-2025-69534
* SECURITY UPDATE: incorrect newlines quoting in email module
- debian/patches/CVE-2026-1299.patch: email: verify headers are sound in
BytesGenerator in Lib/email/generator.py,
Lib/test/test_email/test_generator.py, Lib/test/test_email/test_policy.py.
- CVE-2026-1299
* SECURITY UPDATE:HTTP proxy via "CONNECT" tunneling doesn't sanitize CR/LF
- debian/patches/CVE-2026-1502.patch: Reject CR/LF in HTTP tunnel request
headers in Lib/http/client.py, Lib/test/test_httplib.py.
- CVE-2026-1502
* SECURITY UPDATE: missing audit event for legacy *.pyc files
- debian/patches/CVE-2026-2297.patch: Ensure SourcelessFileLoader uses
io.open_code in Lib/importlib/_bootstrap_external.py.
- CVE-2026-2297
* SECURITY UPDATE: unicodedata.normalize() can take excessive CPU time
- debian/patches/CVE-2026-3276.patch: Fix O(n^2) canonical ordering in
unicodedata.normalize() in Lib/test/test_unicodedata.py,
Modules/unicodedata.c.
- CVE-2026-3276
* SECURITY UPDATE: Incomplete fix for CVE-2026-0672
- debian/patches/CVE-2026-3644.patch: Reject control characters in
http.cookies.Morsel.update() in Lib/http/cookies.py,
Lib/test/test_http_cookies.py.
- CVE-2026-3644
* SECURITY UPDATE: Overflow in Expat parser
- debian/patches/CVE-2026-4224.patch: Avoid unbound C recursion in
conv_content_model in pyexpat.c in Lib/test/test_pyexpat.py,
Modules/pyexpat.c.
- CVE-2026-4224
* SECURITY UPDATE: leading dashes used as options in webbrowser.open()
- debian/patches/CVE-2026-4519-1.patch: Reject leading dashes in webbrowser
URLs in Lib/test/test_webbrowser.py, Lib/webbrowser.py.
- debian/patches/CVE-2026-4519-2.patch: Tweak the exception message and
increase test coverage in Lib/test/test_webbrowser.py, Lib/webbrowser.py.
- CVE-2026-4519
* SECURITY UPDATE: Mitgation of CVE-2026-4519 was incomplete
- debian/patches/CVE-2026-4786.patch: Fix webbrowser `%action` substitution
bypass of dash-prefix check in Lib/test/test_webbrowser.py,
Lib/webbrowser.py.
- CVE-2026-4786
* SECURITY UPDATE: insufficient escaping in http.cookies.Morsel.js_output()
- debian/patches/CVE-2026-6019-1.patch: Base64-encode cookie values
embedded in JS in Lib/http/cookies.py, Lib/test/test_http_cookies.py.
- debian/patches/CVE-2026-6019-2.patch: Use `decodeURIComponent()` for
UTF-8 support in `js_output()` in Lib/http/cookies.py,
Lib/test/test_http_cookies.py.
- CVE-2026-6019
* SECURITY UPDATE: use-after-free in lzma, bz2, gzip decoders
- debian/patches/CVE-2026-6100.patch: Fix a possible UAF in
`{LZMA,BZ2,_Zlib}Decompressor` in Modules/_bz2module.c,
Modules/_lzmamodule.c.
- CVE-2026-6100
* SECURITY UPDATE: Incomplete fix for CVE-2021-4189
- debian/patches/CVE-2026-8328.patch: Apply CVE-2021-4189 PASV fix to
ftplib.ftpcp() (GH-149648) (#149795) in Lib/ftplib.py,
Lib/test/test_ftplib.py.
- CVE-2026-8328
* SECURITY UPDATE: bz2.BZ2Decompressor object reuse after decompression error
- debian/patches/CVE-2026-9669.patch: Prevent bz2 decompressor reuse after
errors in Lib/test/test_bz2.py, Modules/_bz2module.c.
- CVE-2026-9669
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 22 Jun 2026 14:55:27 -0400
sed (built from sed) updated from 4.8-1ubuntu2 to 4.8-1ubuntu2.1:
sed (4.8-1ubuntu2.1) jammy-security; urgency=medium
* SECURITY UPDATE: TOCTOU race in sed -i --follow-symlinks
- debian/patches/CVE-2026-5958.patch: open the already-resolved path
instead of re-traversing the symlink in sed/execute.c.
- CVE-2026-5958
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 17 Apr 2026 14:02:54 -0400
libsqlite3-0:amd64 (built from sqlite3) updated from 3.37.2-2ubuntu0.5 to 3.37.2-2ubuntu0.7:
sqlite3 (3.37.2-2ubuntu0.7) jammy-security; urgency=medium
* SECURITY UPDATE: NULL pointer dereference in the SQLite Session Extension
- debian/patches/CVE-2026-50812.patch: Fix a bug causing the session module
to dereference a NULL pointer when applying a corrupt changeset. in
ext/session/session9.test, ext/session/sqlite3session.c.
- CVE-2026-50812
* SECURITY UPDATE: sensitive information disclosure via the Session Extension
- debian/patches/CVE-2026-50813.patch: Fix a buffer overread in the session
module that could occur when processing a corrupt changeset. in
ext/session/sessionC.test, ext/session/sqlite3session.c.
- CVE-2026-50813
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 16 Jul 2026 13:13:10 -0400
sqlite3 (3.37.2-2ubuntu0.6) jammy-security; urgency=medium
* SECURITY UPDATE: security issues in FTS5 full-text search
- debian/patches/CVE-2026-11822_4.patch: Fix logic in ext/fts5/fts5_index.c.
- CVE-2026-11822
- CVE-2026-11824
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 16 Jun 2026 13:53:33 -0400
libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.20 to 249.11-0ubuntu3.22:
systemd (249.11-0ubuntu3.22) jammy-security; urgency=medium
* SECURITY UPDATE: systemd: crash triggered by unprivileged users in various
components via Varlink
- GHSA-5rm9-cc37-35gq.patch
- GHSA-5rm9-cc37-35gq
* SECURITY UPDATE: udev: local root execution via malicious iscsi devices
and unsanitized kernel output
- GHSA-m8q3-73v4-wvg7.patch
- GHSA-m8q3-73v4-wvg7
* SECURITY UPDATE: crash triggered by unprivileged users in various
components via D-Bus/Varlink
- basic-strv-add-optimizable-version-of-strv_push-consume-e.patch
- core-limit-the-number-of-units-that-can-be-requested-over.patch
- dbus-limit-the-number-of-env-variables-to-something-reaso.patch
- dbus-manager-limit-the-number-of-states-patterns-per-quer.patch
- resolve-enforce-the-search-domain-limit-earlier.patch
- resolve-limit-the-number-NTAs-to-something-sensible.patch
- sd-bus-store-the-strv-size-when-extending-it.patch
- sd-json-user-record-store-the-strv-size-when-extending-it.patch
- GHSA-3jgj-3phh-hx5j
-- Nick Rosbrook <enr0n@ubuntu.com> Wed, 29 Jul 2026 09:41:27 -0400
systemd (249.11-0ubuntu3.21) jammy-security; urgency=medium
* SECURITY UPDATE: MITM via DNSSEC-signed domains with no signature
- debian/patches/CVE-2023-7008.patch: resolved: actually check authenticated
flag of SOA transaction in src/resolve/resolved-dns-transaction.c.
- CVE-2023-7008
* SECURITY UPDATE: escape-to-host via malformed optional config file
- debian/patches/CVE-2026-40226-1.patch: nspawn: apply BindUser/Ephemeral
from settings file only if trusted in src/nspawn/nspawn.c.
- debian/patches/CVE-2026-40226-2.patch: nspawn: normalize pivot_root paths
in src/nspawn/nspawn-mount.c.
- CVE-2026-40226
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 05 Jun 2026 11:40:28 -0400
tar (built from tar) updated from 1.34+dfsg-1ubuntu0.1.22.04.2 to 1.34+dfsg-1ubuntu0.1.22.04.6:
tar (1.34+dfsg-1ubuntu0.1.22.04.6) jammy-security; urgency=medium
* SECURITY REGRESSION: Old archives with nonzero directory sizes
failing to be extracted
- debian/patches/CVE-2026-5704-5.patch: fix this by forcing
the size to zero for DIRTYPE in read_header() in src/list.c
(LP: #2161311).
-- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Mon, 20 Jul 2026 11:42:36 -0300
tar (1.34+dfsg-1ubuntu0.1.22.04.5) jammy-security; urgency=medium
* SECURITY REGRESSION: Extract files issue
- debian/patches/CVE-2026-5704-*.patch: address a regression
that makes valid files not extract in src/list.c,
tests/Makefile.am, tests/extrac32.at, tests/extrac34.at,
test/testsuite.at, src/extract.c, tests/extract23,
tests/extrac30.at (LP: #2160650).
-- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Wed, 15 Jul 2026 11:39:01 -0300
tar (1.34+dfsg-1ubuntu0.1.22.04.4) jammy-security; urgency=medium
* SECURITY UPDATE: File overwrite via directory traversal
- debian/patches/CVE-2025-45582-*.patch: Backport openat2 support in
order to jailify the extraction directory.
- CVE-2025-45582
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Sat, 27 Jun 2026 17:53:20 -0400
tar (1.34+dfsg-1ubuntu0.1.22.04.3) jammy-security; urgency=medium
* SECURITY UPDATE: file injection via crafted archive
- debian/patches/CVE-2026-5704.patch: always call skip_member() after
extraction in extract_archive(), remove conditional skip_member()
from purge_directory(), skip directory data in skim_member(), and
stop forcing LNKTYPE size to zero in read_header().
- CVE-2026-5704
-- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Fri, 19 Jun 2026 13:40:04 -0300
tzdata (built from tzdata) updated from 2026a-0ubuntu0.22.04.1 to 2026c-0ubuntu0.22.04.1:
tzdata (2026c-0ubuntu0.22.04.1) jammy; urgency=medium
* New upstream release (LP: #2161092):
- Alberta moved to permanent -06 on 2026-06-18, so it will not fall back
from -06 to -07 on 2026-11-01.
- Morocco moves to permanent +00 on 2026-09-20.
* Add autopkgtest test case for 2026c release
* Update the ICU timezone data to 2026c
* Add autopkgtest test case for ICU timezone data 2026c
-- Benjamin Drung <bdrung@ubuntu.com> Fri, 17 Jul 2026 14:52:00 +0200
tzdata (2026b-0ubuntu0.22.04.1) jammy; urgency=medium
* New upstream release (LP: #2157973):
- British Columbia moved to permanent -07 on 2026-03-09, so it will not
fall back from -07 to -08 on 2026-11-01.
* Add autopkgtest test case for 2026b release
* Update the ICU timezone data to 2026b
* Add autopkgtest test case for ICU timezone data 2026b
-- Benjamin Drung <bdrung@ubuntu.com> Tue, 23 Jun 2026 14:44:01 +0200
vim-common, vim-tiny, xxd (built from vim) updated from 2:8.2.3995-1ubuntu2.26 to 2:8.2.3995-1ubuntu2.35:
vim (2:8.2.3995-1ubuntu2.35) jammy-security; urgency=medium
* SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785)
- debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in
runtime/autoload/netrw.vim
- debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname
in runtime/autoload/netrw.vim
* SECURITY UPDATE: Use-after-free on json decode error.
- debian/patches/CVE-2026-73071.patch: Report the position from the
current reader in src/json.c.
- CVE-2026-73071
* SECURITY UPDATE: Heap buffer overflow in set_sofo().
- debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in
src/spellfile.c.
- CVE-2026-73072
* SECURITY UPDATE: Heap overflow when adding > 65535 text properties.
- debian/patches/CVE-2026-73074.patch: Verify that the number of text
properties falls within the limit in src/errors.h and src/textprop.c.
- CVE-2026-73074
* SECURITY UPDATE: Code execution via VimballRecord file.
- debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix
broken directory deletion code, and refactor code in
runtime/autoload/vimball.vim
- CVE-2026-73076
* SECURITY UPDATE: Arbitrary code execution via keyword lookup.
- debian/patches/CVE-2026-73077.patch: For powershell, quote the commands
using single quotes, for zsh pass the argument as a separate list
item to term_start()/system() in runtime/ftplugin/ps1.vim and
../zsh.vim.
- CVE-2026-73077
* SECURITY UPDATE: Code injection in netrw via bookmarks.
- debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in
runtime/autoload/netrw.vim.
- CVE-2026-73078
-- Kyle Kernick <kyle.kernick@canonical.com> Tue, 18 Aug 2026 15:47:19 -0600
vim (2:8.2.3995-1ubuntu2.34) jammy-security; urgency=medium
* SECURITY UPDATE: Command execution in PHP omni-completion.
- debian/patches/CVE-2026-59856.patch: Quote the class name before
inserting it into the search() in runtime/autoload/phpcomplete.vim
- CVE-2026-59856
* SECURITY UPDATE: Stack out-of-bounds write in spell_soundfold_sal().
- debian/patches/CVE-2026-59857.patch: Bound the single-byte SAL result
writes in src/spell.c
- CVE-2026-59857
* SECURITY UPDATE: Arbitrary command execution during C omni-completion.
- debian/patches/CVE-2026-59858.patch: Escape the type field before
inserting it into pattern in runtime/autoload/ccomplete.vim
- CVE-2026-59858
-- Kyle Kernick <kyle.kernick@canonical.com> Mon, 13 Jul 2026 13:08:21 -0600
vim (2:8.2.3995-1ubuntu2.33) jammy-security; urgency=medium
* SECURITY UPDATE: Path Traversal in zip.vim
- debian/patches/CVE-2026-35177.patch: Detect malicious zip files before
writing in runtime/autoload/zip.vim
- CVE-2026-35177
* SECURITY UPDATE: Out-of-bounds write.
- debian/patches/CVE-2026-55693.patch: only descend while
depth < MAXWLEN - 1 in src/spellfile.c.
- debian/patches/CVE-2026-55892.patch: only descend while
depth < MAXWLEN - 1 in src/spell.c.
- CVE-2026-55693
- CVE-2026-55892
* SECURITY UPDATE: Code injection in local file deletion.
- debian/patches/CVE-2026-55895.patch: Use fnameescape() to escape
file name in runtime/autoload/netrw.vim.
- CVE-2026-55895
* SECURITY UPDATE: Out-of-bounds read with sodium encrypted files.
- debian/patches/CVE-2026-57452.patch: Verify that there is enough space
before function call in src/crypt.c.
- CVE-2026-57452
* SECURITY UPDATE: Out-of-bounds write with soundfold().
- debian/patches/CVE-2026-57455.patch: Add an abort condition to validate
buffer in src/spell.c.
- CVE-2026-57455
* SECURITY UPDATE: Code execution with python complete.
- debian/patches/CVE-2026-57456.patch: Use repr() to quote the doc strings
in runtime/autoload/python3complete.vim and ../pythoncomplete.vim.
- CVE-2026-57456
-- Kyle Kernick <kyle.kernick@canonical.com> Tue, 30 Jun 2026 11:46:22 -0600
vim (2:8.2.3995-1ubuntu2.32) jammy-security; urgency=medium
* SECURITY UPDATE: Code injection via NetrwBookHistSave().
- debian/patches/CVE-2026-47162.patch: Properly quote the directory name
in runtime/autoload/netrw.vim.
- CVE-2026-47162
* SECURITY UPDATE: Code Injection in cucumber filetype plugin.
- debian/patches/CVE-2026-47167.patch: Use rubys Regexp.new() in
runtime/ftplugin/cucumber.vim.
- CVE-2026-47167
* SECURITY UPDATE: Code execution with python3complete.
- debian/patches/CVE-2026-52858.patch: Disable execution of import/from
statements in runtime/autoload/python3complete.vim and
../pythoncomplete.vim
- debian/patches/CVE-2026-52860.patch: Strip default expressions and
annotations in runtime/autoload/python3complete.vim and
../pythoncomplete.vim
- CVE-2026-52858
- CVE-2026-52860
* SECURITY UPDATE: Out-of-bounds read in update_snapshot().
- debian/patches/CVE-2026-52859.patch: Bound loop in handle_pushline() in
src/terminal.c.
- CVE-2026-52859
-- Kyle Kernick <kyle.kernick@canonical.com> Mon, 15 Jun 2026 16:18:48 -0600
vim (2:8.2.3995-1ubuntu2.31) jammy-security; urgency=medium
* SECURITY UPDATE: Command injection in tar plugin.
- debian/patches/CVE-2026-46483.patch: Use the correct shell-escape in
runtime/autoload/tar.vim.
- CVE-2026-46483
* SECURITY UPDATE: Code injection via mf command.
- debian/patches/CVE-2026-43961.patch: Avoid string concatenation for
filter commands in runtime/autoload/netrw.vim.
- CVE-2026-43961
-- Kyle Kernick <kyle.kernick@canonical.com> Wed, 03 Jun 2026 10:41:25 -0600
vim (2:8.2.3995-1ubuntu2.30) jammy-security; urgency=medium
* SECURITY UPDATE: Command injection in netrw plugin.
- debian/patches/CVE-2026-42307.patch: Escape file names and harden regex
patterns in runtime/autoload/netrw.vim
- CVE-2026-42307
* SECURITY UPDATE: Shell execution in completion.
- debian/patches/CVE-2026-44656.patch: Skip path entries containing
backticks and add P_SECURE option in src/findfile.c and src/optiondefs.h
- CVE-2026-44656
* SECURITY UPDATE: Heap overflow in spellfile.
- debian/patches/CVE-2026-45130.patch: Enforce a maximum compound length
in src/spellfile.c
- CVE-2026-45130
-- Kyle Kernick <kyle.kernick@canonical.com> Wed, 20 May 2026 15:28:11 -0600
vim (2:8.2.3995-1ubuntu2.29) jammy-security; urgency=medium
* SECURITY UPDATE: Command injection via backtick expansion in tag files
- debian/patches/CVE-2026-41411.patch: Disallow backticks before attempting
to expand filenames
- CVE-2026-41411
-- Federico Quattrin <federico.quattrin@canonical.com> Wed, 06 May 2026 13:56:18 -0300
vim (2:8.2.3995-1ubuntu2.28) jammy-security; urgency=medium
* SECURITY UPDATE: Command Injection in netbeans
- debian/patches/CVE-2026-39881.patch: Validate typename, fg, and bg
before passing to coloncmd in src/netbeans.c
- CVE-2026-39881
-- Kyle Kernick <kyle.kernick@canonical.com> Wed, 22 Apr 2026 12:21:19 -0600
vim (2:8.2.3995-1ubuntu2.27) jammy-security; urgency=medium
* SECURITY UPDATE: Command injection in glob.
- debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
src/os_unix.c.
- CVE-2026-33412
* SECURITY UPDATE: Security bypass in modeline.
- debian/patches/CVE-2026-34982.patch: Disallow modeset while in secure
mode in src/optiondefs.h.
- CVE-2026-34982
-- Kyle Kernick <kyle.kernick@canonical.com> Mon, 06 Apr 2026 14:13:36 -0600
liblzma5:amd64 (built from xz-utils) updated from 5.2.5-2ubuntu1 to 5.2.5-2ubuntu1.1:
xz-utils (5.2.5-2ubuntu1.1) jammy-security; urgency=medium
* SECURITY UPDATE: heap buffer overflow
- debian/patches/CVE-2026-34743.patch: adds a check to
lzma_index_prealloc() to default to a safe size when decoding empty
indexes in src/liblzma/common/index.c.
- CVE-2026-34743
-- Ian Constantin <ian.constantin@canonical.com> Thu, 28 May 2026 19:06:40 +0300
10/04/2026, commit https://github.com/canonical/core-base/tree/afed2422f81dbe3b315be43b4b5e122a43e98d85
[ Changes in the core22 snap ]
Andrew Phelps (1):
tools: do not use python3.12 feature since this builds with python3.10 (#428)
Philip Meulengracht (1):
tools/generate-changelog: port changes from core24 to handle missing packages (#413)
[ Changes in primed packages ]
coreutils (built from coreutils) updated from 8.32-4.1ubuntu1.2 to 8.32-4.1ubuntu1.3:
coreutils (8.32-4.1ubuntu1.3) jammy; urgency=medium
* Fix slow performance of 'du' on large directories (>= 10K files)
on Lustre filesystems by skipping inode sorting. The default
behaviour of sorting dirents by inode numbers negatively impacts
performance on Lustre because it interferes with Lustre's ability
to prefetch file metadata via statahead. (LP: #2137373)
- d/p/lp2137373-skip-dirent-inode-sorting-for-lustre.patch
-- Munir Siddiqui <munir.siddiqui@canonical.com> Fri, 23 Jan 2026 15:51:17 +0500
libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.6 to 0.9.6-2ubuntu0.22.04.7:
libssh (0.9.6-2ubuntu0.22.04.7) jammy-security; urgency=medium
* SECURITY UPDATE: out-of-bound read
- debian/patches/CVE-2026-3731.patch: correct bounds checks when querying
for an SFTP extension name or data in src/sftp.c.
- CVE-2026-3731
-- Ian Constantin <ian.constantin@canonical.com> Wed, 11 Mar 2026 12:19:27 +0200
openssh-client, openssh-server, openssh-sftp-server (built from openssh) updated from 1:8.9p1-3ubuntu0.13 to 1:8.9p1-3ubuntu0.14:
openssh (1:8.9p1-3ubuntu0.14) jammy-security; urgency=medium
* SECURITY UPDATE: GSSAPI Key Exchange issue
- debian/patches/gssapi.patch: replace incorrect use of
sshpkt_disconnect() with ssh_packet_disconnect() and properly
initialize some vars.
- CVE-2026-3497
* SECURITY UPDATE: Untrusted control characters in usernames
- debian/patches/CVE-2025-61984.patch: refuse usernames that include
control characters in ssh.c.
- CVE-2025-61984
* SECURITY UPDATE: Code execution in ProxyCommand via NULL character
- debian/patches/CVE-2025-61985.patch: don't allow 0 characters in
url-encoded strings in misc.c.
- CVE-2025-61985
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 04 Mar 2026 12:55:04 -0500
libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.21 to 3.0.2-0ubuntu1.23:
openssl (3.0.2-0ubuntu1.23) jammy-security; urgency=medium
* SECURITY UPDATE: NULL pointer dereference when processing an OCSP
response
- debian/patches/CVE-2026-28387.patch: dane_match_cert() should
X509_free() on ->mcert instead of OPENSSL_free() in
crypto/x509/x509_vfy.c.
- CVE-2026-28387
* SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL
- debian/patches/CVE-2026-28388-1.patch: fix NULL Dereference When
Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c.
- debian/patches/CVE-2026-28388-2.patch: Added test in test/*.
- CVE-2026-28388
* SECURITY UPDATE: Possible NULL dereference when processing CMS
KeyAgreeRecipientInfo
- debian/patches/CVE-2026-28389.patch: Fix NULL deref in
[ec]dh_cms_set_shared_info in crypto/cms/cms_dh.c,
crypto/cms/cms_ec.c.
- CVE-2026-28389
* SECURITY UPDATE: Possible NULL Dereference When Processing CMS
KeyTransportRecipientInfo
- debian/patches/CVE-2026-28390.patch: Fix NULL deref in
rsa_cms_decrypt in crypto/cms/cms_rsa.c.
- CVE-2026-28390
* SECURITY UPDATE: Heap buffer overflow in hexadecimal conversion
- debian/patches/CVE-2026-31789.patch: avoid possible buffer overflow
in buf2hex conversion in crypto/o_str.c.
- CVE-2026-31789
* SECURITY UPDATE: Incorrect failure handling in RSA KEM RSASVE
encapsulation
- debian/patches/CVE-2026-31790-1.patch: validate RSA_public_encrypt()
result in RSASVE in providers/implementations/kem/rsa_kem.c.
- debian/patches/CVE-2026-31790-2.patch: test RSA_public_encrypt()
result in RSASVE in test/evp_extra_test.c.
- CVE-2026-31790
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 07 Apr 2026 08:05:56 -0400
python3-jwt (built from pyjwt) updated from 2.3.0-1ubuntu0.2 to 2.3.0-1ubuntu0.3:
pyjwt (2.3.0-1ubuntu0.3) jammy-security; urgency=medium
* SECURITY UPDATE: Incorrect authorization of invalid JWS token.
- debian/patches/CVE-2026-32597.patch: Add _supported_crit and checks
for valid crit header in jwt/api_jws.py. Add tests in
tests/test_api_jws.py and tests/test_api_jwt.py.
- CVE-2026-32597
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Thu, 26 Mar 2026 14:58:14 -0230
python3-cryptography (built from python-cryptography) updated from 3.4.8-1ubuntu2.2 to 3.4.8-1ubuntu2.4:
python-cryptography (3.4.8-1ubuntu2.4) jammy-security; urgency=medium
* SECURITY REGRESSION: ecc support regression (LP: #2144373)
- debian/patches/CVE-2026-26007.patch: updated to remove problematic
deprecation warning code which is causing a regression with ansible.
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Sat, 14 Mar 2026 08:22:06 -0400
python-cryptography (3.4.8-1ubuntu2.3) jammy-security; urgency=medium
* SECURITY UPDATE: Subgroup Attack Due to Missing Subgroup Validation for
SECT Curves
- debian/patches/CVE-2026-26007-pre1.patch: check if public keys are at
infinity earlier in src/cryptography/hazmat/backends/openssl/ec.py,
tests/hazmat/primitives/test_ec.py.
- debian/patches/CVE-2026-26007.patch: EC check key on cofactor > 1 in
src/cryptography/hazmat/primitives/asymmetric/ec.py,
src/cryptography/utils.py, tests/hazmat/primitives/test_ec.py,
src/_cffi_src/openssl/ec.py,
src/cryptography/hazmat/backends/openssl/ec.py.
- CVE-2026-26007
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 20 Feb 2026 10:14:37 -0500
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.14 to 3.10.12-1~22.04.15:
python3.10 (3.10.12-1~22.04.15) jammy-security; urgency=medium
* SECURITY REGRESSION: Revert patch for CVE-2025-15366
- debian/patches/CVE-2025-15366.patch: Reverted. Patch breaks RFC
9051 IMAP conformance and introduces behavior regressions avoided
by upstream.
- CVE-2025-15366
* SECURITY REGRESSION: Revert patch for CVE-2025-15367
- debian/patches/CVE-2025-15367.patch: Reverted to prevent behavior
regressions, aligning with upstream backporting decisions.
- CVE-2025-15367
* SECURITY REGRESSION: Allow HTAB in wsgiref header values
- debian/patches/CVE-2026-0865-2.patch: Permit HTAB in header values
(excluding names) in Lib/wsgiref/headers.py, add test coverage.
- CVE-2026-0865
-- Vyom Yadav <vyom.yadav@canonical.com> Tue, 03 Mar 2026 17:26:32 +0530
sudo (built from sudo) updated from 1.9.9-1ubuntu2.5 to 1.9.9-1ubuntu2.6:
sudo (1.9.9-1ubuntu2.6) jammy-security; urgency=medium
* SECURITY UPDATE: exec_mailer gid issue (LP: #2143042)
- debian/patches/lp2143042.patch: set group as well as uid when running
the mailer and make a setuid(), setgid() or setgroups() failure fatal
in include/sudo_eventlog.h, lib/eventlog/eventlog.c,
lib/eventlog/eventlog_conf.c, plugins/sudoers/logging.c,
plugins/sudoers/policy.c.
- No CVE number
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 02 Mar 2026 08:08:06 -0500
libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.17 to 249.11-0ubuntu3.20:
systemd (249.11-0ubuntu3.20) jammy; urgency=medium
* net_id: depending on new udev prop, include/exclude PCI domain from netif names
(LP: #2134334)
* network: support ID_NET_MANAGED_BY udev property
(LP: #2133220)
-- Robert Malz <robert.malz@canonical.com> Tue, 24 Mar 2026 09:52:29 -0400
systemd (249.11-0ubuntu3.19) jammy-security; urgency=medium
* SECURITY UPDATE: Local unprivileged user can overwrite stack in systemd
- d/p/CVE-2026-29111-1.patch: path-util: backport path_startswith_full
- d/p/CVE-2026-29111-2.patch: core/cgroup: avoid one unnecessary strjoina()
- d/p/CVE-2026-29111-3.patch: core: validate input cgroup path more prudently
* SECURITY UPDATE: Local root execution via malicious hardware devices
- d/p/udev-check-for-invalid-chars-in-various-fields-received-f.patch
- d/p/udev-fix-review-mixup.patch
- No CVE number
-- Nick Rosbrook <enr0n@ubuntu.com> Fri, 13 Mar 2026 12:47:41 -0400
tzdata (built from tzdata) updated from 2025b-0ubuntu0.22.04.1 to 2026a-0ubuntu0.22.04.1:
tzdata (2026a-0ubuntu0.22.04.1) jammy; urgency=medium
* New upstream release (LP: #2143355):
- No leap second on 2026-06-30
- Moldova has used EU transition times since 2022
* Add autopkgtest test case for 2025c and 2026a release
* Update the ICU timezone data to 2026a
* Add autopkgtest test case for ICU timezone data 2026a
-- Nadzeya Hutsko <nadzeya.hutsko@canonical.com> Thu, 19 Mar 2026 15:04:40 +0100
bsdutils, fdisk, libblkid1:amd64, libfdisk1:amd64, libmount1:amd64, libsmartcols1:amd64, libuuid1:amd64, mount, rfkill, util-linux (built from util-linux) updated from 1:2.37.2-4ubuntu3.4 to 1:2.37.2-4ubuntu3.5:
vim-common, vim-tiny, xxd (built from vim) updated from 2:8.2.3995-1ubuntu2.24 to 2:8.2.3995-1ubuntu2.26:
vim (2:8.2.3995-1ubuntu2.26) jammy-security; urgency=medium
* SECURITY UPDATE: Buffer Overflow
- debian/patches/CVE-2026-26269.patch: Limit writing to max KEYBUFLEN
bytes to prevent writing out of bounds.
- debian/patches/CVE-2026-28420.patch: Use VTERM_MAX_CHARS_PER_CELL * 4
for ga_grow() to ensure sufficient space. Add a boundary check to the
character loop to prevent index out-of-bounds access.
- debian/patches/CVE-2026-28422.patch: Update the size check to account
for the byte length of the fill character (using MB_CHAR2LEN).
- debian/patches/CVE-2026-25749.patch: Limit strncpy to the length
of the buffer (MAXPATHL)
- CVE-2026-26269
- CVE-2026-28420
- CVE-2026-28422
- CVE-2026-25749
* SECURITY UPDATE: Command Injection
- debian/patches/CVE-2026-28417.patch: Implement stricter RFC1123
hostname and IP validation. Use shellescape() for the provided
hostname and port.
- CVE-2026-28417
* SECURITY UPDATE: Out of Bounds Read
- debian/patches/CVE-2026-28418.patch: Check for end of buffer
and return early.
- CVE-2026-28418
* SECURITY UPDATE: Buffer Underflow
- debian/patches/CVE-2026-28419.patch: Add a check to ensure the
delimiter (p_7f) is not at the start of the buffer (lbuf) before
attempting to isolate the tag name.
- CVE-2026-28419
* SECURITY UPDATE: Denial of Service
- debian/patches/CVE-2026-28421.patch: Add bounds checks on
pe_page_count and pe_bnum against mf_blocknr_max before descending
into the block tree, and validate pe_old_lnum >= 1 and
pe_line_count > 0 before calling readfile().
- CVE-2026-28421
-- Bruce Cable <bruce.cable@canonical.com> Wed, 11 Mar 2026 10:44:44 +1100
wpasupplicant (built from wpa) updated from 2:2.10-6ubuntu2.3 to 2:2.10-6ubuntu2.4:
wpa (2:2.10-6ubuntu2.4) jammy; urgency=medium
* Add SaePasswordMismatch signal handling (LP: #2125203)
-- Mitchell Augustin <mitchell.augustin@canonical.com> Wed, 04 Feb 2026 17:33:00 -0600
25/02/2026, commit https://github.com/canonical/core-base/tree/35ba5381ea78d6904d4e5d475e1aee78f7b61172
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
cloud-init (built from cloud-init) updated from 25.2-0ubuntu1~22.04.1 to 25.3-0ubuntu1~22.04.1:
cloud-init (25.3-0ubuntu1~22.04.1) jammy; urgency=medium
* d/p/retain-setuptools.patch: void upstream switch to meson build backend.
* refresh patches:
- d/p/cli-retain-file-argument-as-main-cmd-arg.patch
- d/p/grub-dpkg-support.patch
- d/p/no-nocloud-network.patch
- d/p/no-single-process.patch
* Upstream snapshot based on 25.3. (LP: #2131604).
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/25.3/ChangeLog
-- Chad Smith <chad.smith@canonical.com> Sat, 15 Nov 2025 11:11:25 -0700
libexpat1:amd64 (built from expat) updated from 2.4.7-1ubuntu0.6 to 2.4.7-1ubuntu0.7:
expat (2.4.7-1ubuntu0.7) jammy-security; urgency=medium
* SECURITY UPDATE: NULL pointer dereference
- debian/patches/CVE-2026-24515.patch: updates
XML_ExternalEntityParserCreate to copy unknown encoding handler user
data in expat/lib/xmlparse.c.
- CVE-2026-24515
* SECURITY UPDATE: integer overflow
- debian/patches/CVE-2026-25210*.patch: adds an integer overflow check for
tag buffer reallocation in the doContent function of
expat/lib/xmlparse.c.
- CVE-2026-25210
-- Ian Constantin <ian.constantin@canonical.com> Wed, 04 Feb 2026 17:24:04 +0200
gcc-12-base:amd64, gcc-12-base:i386, libgcc-s1:amd64, libgcc-s1:i386, libstdc++6:amd64 (built from gcc-12) updated from 12.3.0-1ubuntu1~22.04.2 to 12.3.0-1ubuntu1~22.04.3:
gcc-12 (12.3.0-1ubuntu1~22.04.3) jammy; urgency=medium
* d/p/pr118976.diff: Fix memory corruption when executing 256-bit
Scalable Vector Extensions code on 128-bit CPUs (LP: #2101084).
-- Vladimir Petko <vladimir.petko@canonical.com> Sat, 20 Dec 2025 10:52:06 +1300
libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.8 to 2.72.4-0ubuntu2.9:
glib2.0 (2.72.4-0ubuntu2.9) jammy-security; urgency=medium
* SECURITY UPDATE: integer overflow in Base64 encoding
- debian/patches/CVE-2026-1484-1.patch: use gsize to prevent potential
overflow in glib/gbase64.c.
- debian/patches/CVE-2026-1484-2.patch: ensure that the out value is
within allocated size in glib/gbase64.c.
- CVE-2026-1484
* SECURITY UPDATE: buffer underflow via header length
- debian/patches/CVE-2026-1485.patch: do not overflow if header is
longer than MAXINT in gio/gcontenttype.c.
- CVE-2026-1485
* SECURITY UPDATE: integer overflow via Unicode case conversion
- debian/patches/CVE-2026-1489-1.patch: use size_t for output_marks
length in glib/guniprop.c.
- debian/patches/CVE-2026-1489-2.patch: do not convert size_t to gint
in glib/guniprop.c.
- debian/patches/CVE-2026-1489-3.patch: ensure we do not overflow size
in glib/guniprop.c.
- debian/patches/CVE-2026-1489-4.patch: add test debug information when
parsing input files in glib/tests/unicode.c.
- CVE-2026-1489
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 28 Jan 2026 12:57:54 -0500
libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.12 to 2.35-0ubuntu3.13:
glibc (2.35-0ubuntu3.13) jammy-security; urgency=medium
* SECURITY UPDATE: use-after-free in wordexp_t fields
- debian/patches/CVE-2025-15281.patch: posix: Reset wordexp_t fields
with WRDE_REUSE
- CVE-2025-15281
* SECURITY UPDATE: integer overflow in memalign
- debian/patches/CVE-2026-0861.patch: memalign: reinstate alignment
overflow check
- CVE-2026-0861
* SECURITY UPDATE: memory leak in NSS DNS
- debian/patches/CVE-2026-0915.patch: resolv: Fix NSS DNS backend for
getnetbyaddr
- CVE-2026-0915
-- Nishit Majithia <nishit.majithia@canonical.com> Fri, 30 Jan 2026 13:50:56 +0530
gnutls-bin, libgnutls30:amd64 (built from gnutls28) updated from 3.7.3-4ubuntu1.7 to 3.7.3-4ubuntu1.8:
gnutls28 (3.7.3-4ubuntu1.8) jammy-security; urgency=medium
* SECURITY UPDATE: DoS via malicious certificates
- debian/patches/CVE-2025-14831-*.patch: rework processing algorithms
to exhibit better performance characteristics in
lib/x509/name_constraints.c, tests/name-constraints-ip.c.
- CVE-2025-14831
* SECURITY UPDATE: stack overflow via long token label
- debian/patches/CVE-2025-9820.patch: avoid stack overwrite when
initializing a token in lib/pkcs11_write.c, tests/Makefile.am,
tests/pkcs11/long-label.c.
- CVE-2025-9820
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 10 Feb 2026 12:28:21 -0500
libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3ubuntu0.3 to 1.6.37-3ubuntu0.4:
libpng1.6 (1.6.37-3ubuntu0.4) jammy-security; urgency=medium
* SECURITY UPDATE: OOB read in png_set_quantize()
- debian/patches/CVE-2026-25646.patch: fix a heap buffer overflow in
pngrtran.c.
- CVE-2026-25646
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 11 Feb 2026 09:27:33 -0500
libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.5 to 0.9.6-2ubuntu0.22.04.6:
libssh (0.9.6-2ubuntu0.22.04.6) jammy-security; urgency=medium
* SECURITY UPDATE: memory leak in key exchange
- debian/patches/CVE-2025-8277-1.patch: adjust packet filter to work
when DH-GEX is guessed wrongly in src/packet.c.
- debian/patches/CVE-2025-8277-2.patch: fix memory leak of unused
ephemeral key pair after client's wrong KEX guess in src/dh_crypto.c,
src/dh_key.c, src/ecdh_crypto.c, src/ecdh_gcrypt.c,
src/ecdh_mbedcrypto.c.
- debian/patches/CVE-2025-8277-3.patch: free previously allocated
pubkeys in src/ecdh_crypto.c, src/ecdh_gcrypt.c.
- debian/patches/CVE-2025-8277-4.patch: avoid leaking ecdh keys in
src/ecdh_mbedcrypto.c, src/wrapper.c.
- CVE-2025-8277
* SECURITY UPDATE: Improper sanitation of paths received from SCP servers
- debian/patches/CVE-2026-0964.patch: reject invalid paths received
through scp in src/scp.c.
- CVE-2026-0964
* SECURITY UPDATE: DoS via improper configuration file handling
- debian/patches/CVE-2026-0965.patch: do not attempt to read
non-regular and too large configuration files in
include/libssh/misc.h, include/libssh/priv.h, src/bind_config.c,
src/config.c, src/dh-gex.c, src/known_hosts.c, src/knownhosts.c,
src/misc.c, tests/unittests/torture_config.c.
- CVE-2026-0965
* SECURITY UPDATE: Buffer underflow in ssh_get_hexa() on invalid input
- debian/patches/CVE-2026-0966-1.patch: avoid heap buffer underflow in
ssh_get_hexa in src/misc.c.
- debian/patches/CVE-2026-0966-2.patch: test coverage for ssh_get_hexa
in tests/unittests/torture_misc.c.
- debian/patches/CVE-2026-0966-3.patch: update guided tour to use
SHA256 fingerprints in doc/guided_tour.dox.
- CVE-2026-0966
* SECURITY UPDATE: DoS via inefficient regular expression processing
- debian/patches/CVE-2026-0967.patch: avoid recursive matching (ReDoS)
in src/match.c, tests/unittests/torture_config.c.
- CVE-2026-0967
* SECURITY UPDATE: DoS due to malformed SFTP message
- debian/patches/CVE-2026-0968-1.patch: sanitize input handling in
sftp_parse_longname() in src/sftp.c.
- debian/patches/CVE-2026-0968-2.patch: reproducer for invalid longname
data in tests/unittests/CMakeLists.txt,
tests/unittests/torture_unit_sftp.c.
- CVE-2026-0968
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 13 Feb 2026 10:22:49 -0500
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.13 to 3.10.12-1~22.04.14:
python3.10 (3.10.12-1~22.04.14) jammy-security; urgency=medium
* SECURITY UPDATE: Header injection in email messages where addresses are not
sanitized.
- debian/patches/CVE-2025-11468.patch: Add escape parentheses and backslash
in Lib/email/_header_value_parser.py. Add test in
Lib/test/test_email/test__header_value_parser.py.
- CVE-2025-11468
* SECURITY UPDATE: Quadratic algorithm when building excessively nested XML
documents.
- debian/patches/CVE-2025-12084-*.patch: Remove _in_document and replace
with node.ownerDocument in Lib/xml/dom/minidom.py. Set self.ownerDocument
to None in Lib/xml/dom/minidom.py. Add test in Lib/test/test_minidom.py.
- CVE-2025-12084
* SECURITY UPDATE: OOM and denial of service when opening malicious plist
file.
- debian/patches/CVE-2025-13837.patch: Add _MIN_READ_BUF_SIZE and _read
with checks in Lib/plistlib.py. Add test in Lib/test/test_plistlib.py.
- CVE-2025-13837
* SECURITY UPDATE: Header injection in user controlled data URLs in urllib.
- debian/patches/CVE-2025-15282.patch: Add control character checks in
Lib/urllib/request.py. Add test in Lib/test/test_urllib.py.
* SECURITY UPDATE: Command injection through user controlled commands in
imaplib.
- debian/patches/CVE-2025-15366.patch: Add _control_chars and checks in
Lib/imaplib.py. Add test in Lib/test/test_imaplib.py.
* SECURITY UPDATE: Command injection through user controlled commands in
poplib.
- debian/patches/CVE-2025-15367.patch: Add control character regex check
in Lib/poplib.py. Add test in Lib/test/test_poplib.py.
- CVE-2025-15367
* SECURITY UPDATE: HTTP header injection in user controlled cookie values.
- debian/patches/CVE-2026-0672.patch: Add _control_characters_re and
checks in Lib/http/cookies.py. Add test in Lib/test/test_http_cookies.py.
- CVE-2026-0672
* SECURITY UPDATE: HTTP header injection in user controlled headers and
values with newlines.
- debian/patches/CVE-2026-0865.patch: Add _control_chars_re and check in
Lib/wsgiref/headers.py. Add test in Lib/test/support/__init__.py and
Lib/test/test_wsgiref.py.
- CVE-2026-0865
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Mon, 26 Jan 2026 11:25:28 -0330
28/01/2026, commit https://github.com/canonical/core-base/tree/35ba5381ea78d6904d4e5d475e1aee78f7b61172
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.7 to 2.72.4-0ubuntu2.8:
glib2.0 (2.72.4-0ubuntu2.8) jammy-security; urgency=medium
* SECURITY UPDATE: Integer overflow in g_buffered_input_stream_peek()
- debian/patches/CVE-2026-0988.patch: fix a potential integer overflow
in peek() in gio/gbufferedinputstream.c,
gio/tests/buffered-input-stream.c.
- CVE-2026-0988
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 20 Jan 2026 08:55:03 -0500
libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.11 to 2.35-0ubuntu3.12:
glibc (2.35-0ubuntu3.12) jammy; urgency=medium
* d/p/lp2089789-*.patch: fix malloc performance regression (LP: #2089789)
-- Simon Chopin <schopin@ubuntu.com> Tue, 15 Jul 2025 11:40:00 +0200
libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3ubuntu0.1 to 1.6.37-3ubuntu0.3:
libpng1.6 (1.6.37-3ubuntu0.3) jammy-security; urgency=medium
* SECURITY UPDATE: OOB in png_image_read_composite
- debian/patches/CVE-2025-66293-1.patch: validate component size in
pngread.c.
- debian/patches/CVE-2025-66293-2.patch: improve fix in pngread.c.
- CVE-2025-66293
* SECURITY UPDATE: Heap buffer over-read in png_image_read_direct_scaled
- debian/patches/CVE-2026-22695.patch: fix memcpy size in pngread.c.
- CVE-2026-22695
* SECURITY UPDATE: Integer truncation causing heap buffer over-read
- debian/patches/CVE-2026-22801.patch: remove incorrect truncation
casts in CMakeLists.txt, contrib/libtests/pngstest.c, pngwrite.c,
tests/pngstest-large-stride.
- CVE-2026-22801
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 12 Jan 2026 13:14:59 -0500
libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.20 to 3.0.2-0ubuntu1.21:
openssl (3.0.2-0ubuntu1.21) jammy-security; urgency=medium
* SECURITY UPDATE: Stack buffer overflow in CMS AuthEnvelopedData parsing
- debian/patches/CVE-2025-15467-1.patch: correct handling of
AEAD-encrypted CMS with inadmissibly long IV in crypto/evp/evp_lib.c.
- debian/patches/CVE-2025-15467-2.patch: some comments to clarify
functions usage in crypto/asn1/evp_asn1.c.
- debian/patches/CVE-2025-15467-3.patch: test for handling of
AEAD-encrypted CMS with inadmissibly long IV in test/cmsapitest.c,
test/recipes/80-test_cmsapi.t,
test/recipes/80-test_cmsapi_data/encDataWithTooLongIV.pem.
- CVE-2025-15467
* SECURITY UPDATE: Heap out-of-bounds write in BIO_f_linebuffer on short
writes
- debian/patches/CVE-2025-68160.patch: fix heap buffer overflow in
BIO_f_linebuffer in crypto/bio/bf_lbuf.c.
- CVE-2025-68160
* SECURITY UPDATE: Unauthenticated/unencrypted trailing bytes with
low-level OCB function calls
- debian/patches/CVE-2025-69418.patch: fix OCB AES-NI/HW stream path
unauthenticated/unencrypted trailing bytes in crypto/modes/ocb128.c.
- CVE-2025-69418
* SECURITY UPDATE: Out of bounds write in PKCS12_get_friendlyname() UTF-8
conversion
- debian/patches/CVE-2025-69419.patch: check return code of UTF8_putc
in crypto/asn1/a_strex.c, crypto/pkcs12/p12_utl.c.
- CVE-2025-69419
* SECURITY UPDATE: Missing ASN1_TYPE validation in
TS_RESP_verify_response() function
- debian/patches/CVE-2025-69420.patch: verify ASN1 object's types
before attempting to access them as a particular type in
crypto/ts/ts_rsp_verify.c.
- CVE-2025-69420
* SECURITY UPDATE: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex
- debian/patches/CVE-2025-69421.patch: add NULL check in
crypto/pkcs12/p12_decr.c.
- CVE-2025-69421
* SECURITY UPDATE: ASN1_TYPE missing validation and type confusion
- debian/patches/CVE-2026-2279x.patch: ensure ASN1 types are checked
before use in apps/s_client.c, crypto/pkcs12/p12_kiss.c,
crypto/pkcs7/pk7_doit.c.
- CVE-2026-22795
- CVE-2026-22796
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 26 Jan 2026 07:32:08 -0500
python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.5 to 1.26.5-1~exp1ubuntu0.6:
python-urllib3 (1.26.5-1~exp1ubuntu0.6) jammy-security; urgency=medium
* SECURITY REGRESSION: Missing _has_decoded_content from CVE-2026-21441
(LP: #2138420)
- debian/patches/CVE-2026-21441-fix1.patch: Implement _has_decoded_content
and decoded checks in src/urllib3/response.py. Add tests in
test/test_response.py.
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Fri, 16 Jan 2026 19:39:26 -0330
13/01/2026, commit https://github.com/canonical/core-base/tree/35ba5381ea78d6904d4e5d475e1aee78f7b61172
[ Changes in the core22 snap ]
Philip Meulengracht (1):
static: add snapd.conf to tmpfiles.d (#383)
[ Changes in primed packages ]
apparmor, libapparmor1:amd64 (built from apparmor) updated from 3.0.4-2ubuntu2.4 to 3.0.4-2ubuntu2.5:
apparmor (3.0.4-2ubuntu2.5) jammy; urgency=medium
* profiles: make /sys/devices PCI paths hex-aware (LP: #2115234)
-- Keifer Snedeker <keifer.snedeker@canonical.com> Fri, 15 Aug 2025 13:17:13 +0100
libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.6 to 2.72.4-0ubuntu2.7:
glib2.0 (2.72.4-0ubuntu2.7) jammy-security; urgency=medium
* SECURITY UPDATE: overflow via long invalid ISO 8601 timestamp
- debian/patches/CVE-2025-3360-1.patch: fix integer overflow when
parsing very long ISO8601 inputs in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-2.patch: fix potential integer overflow
in timezone offset handling in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-3.patch: track timezone length as an
unsigned size_t in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-4.patch: factor out some string pointer
arithmetic in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-5.patch: factor out an undersized
variable in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-6.patch: add some missing GDateTime
ISO8601 parsing tests in glib/tests/gdatetime.c.
- CVE-2025-3360
* SECURITY UPDATE: GString overflow
- debian/patches/CVE-2025-6052.patch: fix overflow check when expanding
the string in glib/gstring.c.
- CVE-2025-6052
* SECURITY UPDATE: integer overflow in temp file creation
- debian/patches/CVE-2025-7039.patch: fix computation of temporary file
name in glib/gfileutils.c.
- CVE-2025-7039
* SECURITY UPDATE: heap overflow in g_escape_uri_string()
- debian/patches/CVE-2025-13601.patch: add overflow check in
glib/gconvert.c.
- CVE-2025-13601
* SECURITY UPDATE: buffer underflow through glib/gvariant
- debian/patches/CVE-2025-14087-1.patch: fix potential integer overflow
parsing (byte)strings in glib/gvariant-parser.c.
- debian/patches/CVE-2025-14087-2.patch: use size_t to count numbers of
child elements in glib/gvariant-parser.c.
- debian/patches/CVE-2025-14087-3.patch: convert error handling code to
use size_t in glib/gvariant-parser.c.
- CVE-2025-14087
* SECURITY UPDATE: integer overflow in gfileattribute
- debian/patches/gfileattribute-overflow.patch: add overflow check in
gio/gfileattribute.c.
- No CVE number
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 10 Dec 2025 11:09:12 -0500
gpgv (built from gnupg2) updated from 2.2.27-3ubuntu2.4 to 2.2.27-3ubuntu2.5:
gnupg2 (2.2.27-3ubuntu2.5) jammy-security; urgency=medium
* SECURITY UPDATE: Remote Code Execution
- debian/patches/CVE-2025-68973.patch: gpg: Fix possible memory
corruption in the armor parser.
- CVE-2025-68973
-- Allen Huang <allen.huang@canonical.com> Mon, 05 Jan 2026 22:14:39 +0000
libpng16-16:amd64 (built from libpng1.6) updated from 1.6.37-3build5 to 1.6.37-3ubuntu0.1:
libpng1.6 (1.6.37-3ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: buffer overflow issue
- debian/patches/CVE-2025-64505.patch: Fix a buffer overflow in
png_do_quantize
- debian/patches/CVE-2025-64506.patch: Fix a heap buffer overflow in
png_write_image_8bit
- debian/patches/CVE-2025-64720.patch: Fix a buffer overflow in
png_init_read_transformations
- debian/patches/CVE-2025-65018.patch: Fix a heap buffer overflow in
png_image_finish_read
- CVE-2025-64505
- CVE-2025-64506
- CVE-2025-64720
- CVE-2025-65018
-- Nishit Majithia <nishit.majithia@canonical.com> Tue, 09 Dec 2025 17:35:45 +0530
libtasn1-6:amd64 (built from libtasn1-6) updated from 4.18.0-4ubuntu0.1 to 4.18.0-4ubuntu0.2:
libtasn1-6 (4.18.0-4ubuntu0.2) jammy-security; urgency=medium
* SECURITY UPDATE: ETYPE_OK off-by-one array size check
- debian/patches/CVE-2021-46848.patch: fix size check in lib/int.h.
- CVE-2021-46848
* SECURITY UPDATE: Stack-based buffer overflow
- debian/patches/CVE-2025-13151.patch: fix asn1_expand_octet_string
buffer size in lib/decoding.c.
- CVE-2025-13151
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 08 Jan 2026 12:27:15 -0500
python3-attr (built from python-attrs) updated from 21.2.0-1 to 21.2.0-1ubuntu1:
python-attrs (21.2.0-1ubuntu1) jammy; urgency=medium
* d/p/0005-Rework-linecache-handling-828.patch: Cherry-pick upstream PR 826
- Fix memory leak when creating many identical classes (Fixes LP: #2121607)
-- Zachary Raines <zachary.raines@canonical.com> Mon, 06 Oct 2025 15:28:54 +0000
python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.3 to 1.26.5-1~exp1ubuntu0.5:
python-urllib3 (1.26.5-1~exp1ubuntu0.5) jammy-security; urgency=medium
* SECURITY UPDATE: Decompression bomb in HTTP redirect responses.
- debian/patches/CVE-2026-21441.patch: Add decode_content to self.read()
in src/urllib3/response.py. Add tests in
test/with_dummyserver/test_connectionpool.py.
- CVE-2026-21441
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Thu, 08 Jan 2026 16:06:10 -0330
python-urllib3 (1.26.5-1~exp1ubuntu0.4) jammy-security; urgency=medium
* SECURITY UPDATE: Denial of service due to unbounded decompression chain.
- debian/patches/CVE-2025-66418.patch: Add max_decode_links limit and
checks in src/urllib3/response.py. Add test in test/test_response.py.
- CVE-2025-66418
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 10 Dec 2025 17:29:42 -0330
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.12 to 3.10.12-1~22.04.13:
python3.10 (3.10.12-1~22.04.13) jammy-security; urgency=medium
* SECURITY UPDATE: HTTP Content-Length denial of service
- debian/patches/CVE-2025-13836.patch: Read large data in chunks with
geometric reads in Lib/http/client.py and add tests in
Lib/test/test_httplib.py
- CVE-2025-13836
-- Vyom Yadav <vyom.yadav@canonical.com> Thu, 08 Jan 2026 12:22:19 +0530
02/12/2025, commit https://github.com/canonical/core-base/tree/e66d98a0d2aa893b0907dd3bbe9db09c3d274c5d
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.11 to 3.10.12-1~22.04.12:
python3.10 (3.10.12-1~22.04.12) jammy-security; urgency=medium
* SECURITY UPDATE: Possible payload obfuscation
- debian/patches/CVE-2025-8291.patch: check consistency of
the zip64 end of central dir record in Lib/zipfile.py,
Lib/test/test_zipfile.py.
- CVE-2025-8291
* SECURITY UPDATE: Performance degradation
- debian/patches/CVE-2025-6075.patch: fix quadratic complexity
in os.path.expandvars() in Lib/ntpatch.py, Lib/posixpath.py,
Lib/test/test_genericpatch.py, Lib/test/test_npath.py.
- CVE-2025-6075
-- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Tue, 04 Nov 2025 05:48:33 -0300
05/11/2025, commit https://github.com/canonical/core-base/tree/e66d98a0d2aa893b0907dd3bbe9db09c3d274c5d
[ Changes in the core22 snap ]
Philip Meulengracht (1):
github: add fips release builds (#378)
[ Changes in primed packages ]
distro-info-data (built from distro-info-data) updated from 0.52ubuntu0.9 to 0.52ubuntu0.11:
distro-info-data (0.52ubuntu0.11) jammy; urgency=medium
* ubuntu.csv: remove eol-legacy field from resolute
This version of distro-info does not know about eol-legacy.
-- Nick Rosbrook <enr0n@ubuntu.com> Fri, 10 Oct 2025 11:59:51 -0400
distro-info-data (0.52ubuntu0.10) jammy; urgency=medium
* Add Ubuntu 26.04 LTS "Resolute Raccoon" (LP: #2126961)
* Correct date for forky
* Correct estimation for trixie ELTS EoL to 10 years total support.
* Update the bookworm EoL
-- Florent 'Skia' Jacquet <florent.jacquet@canonical.com> Fri, 10 Oct 2025 11:33:51 +0100
libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.4 to 0.9.6-2ubuntu0.22.04.5:
libssh (0.9.6-2ubuntu0.22.04.5) jammy-security; urgency=medium
* SECURITY UPDATE: NULL pointer dereference
- debian/patches/CVE-2025-8114.patch: sets rc to SSH_ERROR prior to goto
error in ssh_make_sessionid() of src/kex.c.
- CVE-2025-8114
-- Ian Constantin <ian.constantin@canonical.com> Wed, 29 Oct 2025 14:58:26 +0200
09/10/2025, commit https://github.com/canonical/core-base/tree/6174ae97e09857c5e7e38f2a0599c7d2940acddf
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
cloud-init (built from cloud-init) updated from 25.1.4-0ubuntu0~22.04.1 to 25.2-0ubuntu1~22.04.1:
cloud-init (25.2-0ubuntu1~22.04.1) jammy; urgency=medium
* refresh patches
- d/p/cli-retain-file-argument-as-main-cmd-arg.patch
- d/p/deprecation-version-boundary.patch
- d/p/grub-dpkg-support.patch
- d/p/keep-dhclient-as-priority-client.patch
- d/p/no-nocloud-network.patch
- d/p/no-remove-networkd-online.patch
- d/p/no-single-process.patch
- d/p/retain-ec2-default-net-update-events.patch
- d/p/retain-old-groups.patch
- d/p/revert-551f560d-cloud-config-after-snap-seeding.patch
* add d/p/strip-invalid-mtu.patch
- Provides backwards compatibility for an other invalid
MTU in a netplan config. (GH-6239)
* Upstream snapshot based on 25.2. (LP: #2120495).
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/25.2/ChangeLog
-- James Falcon <james.falcon@canonical.com> Tue, 12 Aug 2025 14:48:04 -0500
dpkg (built from dpkg) updated from 1.21.1ubuntu2.3 to 1.21.1ubuntu2.6:
dpkg (1.21.1ubuntu2.6) jammy-security; urgency=medium
[ Joy Latten ]
* SECURITY UPDATE:
- Fix cleanup for control member with restricted directories. LP: #2122053
- Fixes CVE-2025-6297
-- Serge Hallyn <serge.hallyn@ubuntu.com> Tue, 09 Sep 2025 15:09:16 -0500
libssl3:amd64, openssl (built from openssl) updated from 3.0.2-0ubuntu1.19 to 3.0.2-0ubuntu1.20:
openssl (3.0.2-0ubuntu1.20) jammy-security; urgency=medium
* SECURITY UPDATE: Out-of-bounds read & write in RFC 3211 KEK Unwrap
- debian/patches/CVE-2025-9230.patch: fix incorrect check of unwrapped
key size in crypto/cms/cms_pwri.c.
- CVE-2025-9230
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 18 Sep 2025 08:06:16 -0400
libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.16 to 249.11-0ubuntu3.17:
systemd (249.11-0ubuntu3.17) jammy; urgency=medium
[ Nick Rosbrook ]
* initramfs-tools: copy hwdb.bin to initramfs (LP: #2112237)
* d/t/tests-in-lxd: drop patching workaround (LP: #2115263)
- d/t/control: add Depends: dnsmasq-base
(Revealed by test progressing past previous failure)
[ Chengen Du ]
* core/device: fix devlink handling (LP: #2100252)
-- Nick Rosbrook <enr0n@ubuntu.com> Tue, 26 Aug 2025 11:23:06 -0400
wpasupplicant (built from wpa) updated from 2:2.10-6ubuntu2.2 to 2:2.10-6ubuntu2.3:
wpa (2:2.10-6ubuntu2.3) jammy; urgency=medium
* Bump DEFAULT_BSS_MAX_COUNT to 1000 (LP: #2117180)
-- Mitchell Augustin <mitchell.augustin@canonical.com> Mon, 21 Jul 2025 18:13:31 -0500
23/09/2025, commit https://github.com/canonical/core-base/tree/6174ae97e09857c5e7e38f2a0599c7d2940acddf
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
libc-bin, libc6:amd64, libc6:i386 (built from glibc) updated from 2.35-0ubuntu3.10 to 2.35-0ubuntu3.11:
glibc (2.35-0ubuntu3.11) jammy-security; urgency=medium
* SECURITY UPDATE: double-free in regcomp function
- debian/patches/any/CVE-2025-8058.patch: fix double-free after
allocation failure in regcomp in posix/Makefile, posix/regcomp.c,
posix/tst-regcomp-bracket-free.c.
- CVE-2025-8058
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 17 Sep 2025 11:26:08 -0400
22/08/2025, commit https://github.com/canonical/core-base/tree/6174ae97e09857c5e7e38f2a0599c7d2940acddf
[ Changes in the core22 snap ]
Alfonso Sánchez-Beato (3):
.github/workflows: add release-manual action
.github/workflows/tests.yaml: make sure to run on spread-enabled runners
many: ser snap version from date tag if present
[ Changes in primed packages ]
gcc-12-base:amd64, gcc-12-base:i386, libgcc-s1:amd64, libgcc-s1:i386, libstdc++6:amd64 (built from gcc-12) updated from 12.3.0-1ubuntu1~22.04 to 12.3.0-1ubuntu1~22.04.2:
gcc-12 (12.3.0-1ubuntu1~22.04.2) jammy-security; urgency=medium
* SECURITY UPDATE: A missed hardening option in -fstack-protector for AArch64
can lead to buffer overflows for dynamically allocated local variables
not being detected. (LP: #2054343)
- d/p/CVE-2023-4039.diff: Address stack protector and stack clash
protection weaknesses on AArch64. Taken from the gcc-12 branch.
- CVE-2023-4039
* Move allocator base to avoid conflict with high-entropy ASLR for x86-64
Linux. Patch taken from LLVM. Fixes ftbfs. (LP: #2107313)
- d/p/lp2107313-asan-allocator-base.diff
* aarch64: Fix loose ldpstp check. (LP: #2116909)
- d/p/lp2116909-aarch64-fix-loose-ldpstp-check.diff
-- Gerald Yang <gerald.yang@canonical.com> Tue, 15 Jul 2025 03:45:40 +0000
libglib2.0-0:amd64 (built from glib2.0) updated from 2.72.4-0ubuntu2.5 to 2.72.4-0ubuntu2.6:
glib2.0 (2.72.4-0ubuntu2.6) jammy; urgency=medium
* Fix crash due to infinite recursion in MIME subclassing (LP: #2097496)
-- Alessandro Astone <alessandro.astone@canonical.com> Fri, 20 Jun 2025 15:38:50 +0200
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.10 to 3.10.12-1~22.04.11:
python3.10 (3.10.12-1~22.04.11) jammy-security; urgency=medium
* SECURITY UPDATE: Regular expression denial of service.
- debian/patches/CVE-2025-6069.patch: Improve regex parsing in
Lib/html/parser.py.
- CVE-2025-6069
* SECURITY UPDATE: Infinite loop when parsing tar archives.
- debian/patches/CVE-2025-8194.patch: Raise exception when count < 0 in
Lib/tarfile.py.
- CVE-2025-8194
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Fri, 15 Aug 2025 12:02:43 -0230
30/07/2025, commit https://git.launchpad.net/snap-core22/tree/5915fa29307f6839820c681cf666367c164d1088
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
cloud-init (built from cloud-init) updated from 25.1.2-0ubuntu0~22.04.2 to 25.1.4-0ubuntu0~22.04.1:
cloud-init (25.1.4-0ubuntu0~22.04.1) jammy-security; urgency=medium
* refresh patches:
- d/p/revert-usr-lib-systemd-units.patch
* Upstream snapshot based on 25.1.4.
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/25.1.4/ChangeLog
- Bugs fixed in this snapshot:
+ fix: disable cloud-init when non-x86 environments have no DMI-data
and no strict datasources detected (LP: #2069607) (CVE-2024-6174)
-- Chad Smith <chad.smith@canonical.com> Tue, 24 Jun 2025 15:15:25 -0600
cloud-init (25.1.3-0ubuntu0~22.04.1) jammy-security; urgency=medium
* d/cloud-init-base.postinst: move existing hotplug-cmd fifo to root-only
share dir (CVE-2024-11584)
* Upstream security bugfix release based on 25.1.3.
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/25.1.3/ChangeLog
- Bugs fixed in this snapshot:
- security: make hotplug socket only writable by root (LP: #2114229)
(CVE-2024-11584)
- security: make ds-identify behavior strict datasource discovery on
non-x86 platforms without DMI data (LP: #2069607) (CVE-2024-6174)
-- Chad Smith <chad.smith@canonical.com> Thu, 12 Jun 2025 20:28:18 -0600
gnutls-bin, libgnutls30:amd64 (built from gnutls28) updated from 3.7.3-4ubuntu1.6 to 3.7.3-4ubuntu1.7:
gnutls28 (3.7.3-4ubuntu1.7) jammy-security; urgency=medium
* SECURITY UPDATE: double-free via otherName in the SAN
- debian/patches/CVE-2025-32988.patch: avoid double free when exporting
othernames in SAN in lib/x509/extensions.c.
- CVE-2025-32988
* SECURITY UPDATE: OOB read via malformed length field in SCT extension
- debian/patches/CVE-2025-32989.patch: fix read buffer overrun in SCT
timestamps in lib/x509/x509_ext.c.
- CVE-2025-32989
* SECURITY UPDATE: heap write overflow in certtool via invalid template
- debian/patches/CVE-2025-32990.patch: avoid 1-byte write buffer
overrun when parsing template in src/certtool-cfg.c,
tests/cert-tests/Makefile.am, tests/cert-tests/template-test.sh,
tests/cert-tests/templates/template-too-many-othernames.tmpl.
- CVE-2025-32990
* SECURITY UPDATE: NULL deref via missing PSK in TLS 1.3 handshake
- debian/patches/CVE-2025-6395.patch: clear HSK_PSK_SELECTED when
resetting binders in lib/handshake.c, lib/state.c, tests/Makefile.am,
tests/tls13/hello_retry_request_psk.c.
- CVE-2025-6395
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 11 Jul 2025 09:13:17 -0400
iputils-ping (built from iputils) updated from 3:20211215-1 to 3:20211215-1ubuntu0.1:
iputils (3:20211215-1ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: DoS via crafted ICMP Echo Reply packet
- debian/patches/CVE-2025-47268: fix signed 64-bit integer overflow in
RTT calculation in iputils_common.h, ping/ping_common.c.
- debian/patches/CVE-2025-48964.patch: fix moving average rtt
calculation in iputils_common.h, ping/ping.h, ping/ping_common.c.
- CVE-2025-47268
- CVE-2025-48964
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 24 Jul 2025 07:51:44 -0400
perl-base (built from perl) updated from 5.34.0-3ubuntu1.4 to 5.34.0-3ubuntu1.5:
perl (5.34.0-3ubuntu1.5) jammy-security; urgency=medium
* SECURITY UPDATE: threads race condition in file operations
- debian/patches/fixes/CVE-2025-40909-metaconfig.diff: check for
fdopendir in regen-configure/U/perl/d_fdopendir.U.
- debian/patches/fixes/CVE-2025-40909-1.diff: clone dirhandles without
fchdir in Configure, Cross/config.sh-arm-linux,
Cross/config.sh-arm-linux-n770, Porting/Glossary, Porting/config.sh,
config_h.SH, configure.com, plan9/config_sh.sample, sv.c,
t/op/threads-dirh.t, win32/config.gc, win32/config.vc.
- debian/patches/fixes/CVE-2025-40909-2.diff: minor corrections in
Cross/config.sh-arm-linux, Cross/config.sh-arm-linux-n770,
config_h.SH,plan9/config_sh.sample.
- debian/patches/fixes/CVE-2025-40909-3.diff: use PerlLIO_dup_cloexec
in Perl_dirp_dup to set O_CLOEXEC in sv.c.
- debian/patches/fixes/CVE-2025-40909-metaconfig-reorder.diff: slightly
reorder Configure and config_h.SH to match metaconfig output in
Configure, config_h.SH.
- debian/patches/fixes/CVE-2025-40909-generated.diff: update generated
files and checksums in uconfig.sh, uconfig64.sh, uconfig.h,
NetWare/config.wc.
- CVE-2025-40909
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 25 Jul 2025 13:26:40 -0400
libsqlite3-0:amd64 (built from sqlite3) updated from 3.37.2-2ubuntu0.4 to 3.37.2-2ubuntu0.5:
sqlite3 (3.37.2-2ubuntu0.5) jammy-security; urgency=medium
* SECURITY UPDATE: Memory corruption via number of aggregate terms
- debian/patches/CVE-2025-6965.patch: raise an error right away if the
number of aggregate terms in a query exceeds the maximum number of
columns in src/expr.c, src/sqliteInt.h.
- CVE-2025-6965
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 18 Jul 2025 11:17:24 -0400
08/07/2025, commit https://git.launchpad.net/snap-core22/tree/5915fa29307f6839820c681cf666367c164d1088
[ Changes in the core22 snap ]
Philip Meulengracht (1):
tools: aggregate old changelogs
[ Changes in primed packages ]
gpgv (built from gnupg2) updated from 2.2.27-3ubuntu2.3 to 2.2.27-3ubuntu2.4:
gnupg2 (2.2.27-3ubuntu2.4) jammy-security; urgency=medium
* debian/patches/fix-key-validity-regression-due-to-CVE-2025-
30258.patch:
- Fix a key validity regression following patches for CVE-2025-30258,
causing trusted "certify-only" primary keys to be ignored when checking
signature on user IDs and computing key validity. This regression makes
imported keys signed by a trusted "certify-only" key have an unknown
validity (LP: #2114775).
-- dcpi <dcpi@u22vm> Wed, 25 Jun 2025 13:54:28 +0000
libssh-4:amd64 (built from libssh) updated from 0.9.6-2ubuntu0.22.04.3 to 0.9.6-2ubuntu0.22.04.4:
libssh (0.9.6-2ubuntu0.22.04.4) jammy-security; urgency=medium
* SECURITY UPDATE: Write beyond bounds in binary to base64 conversion
functions
- debian/patches/CVE-2025-4877.patch: prevent integer overflow and
potential OOB.
- CVE-2025-4877
* SECURITY UPDATE: Use of uninitialized variable in
privatekey_from_file()
- debian/patches/CVE-2025-4878-1.patch: initialize pointers where
possible.
- debian/patches/CVE-2025-4878-2.patch: properly check return value to
avoid NULL pointer dereference.
- CVE-2025-4878
* SECURITY UPDATE: OOB read in sftp_handle function
- debian/patches/CVE-2025-5318.patch: fix possible buffer overrun.
- CVE-2025-5318
* SECURITY UPDATE: ssh_kdf() returns a success code on certain failures
- debian/patches/CVE-2025-5372-pre1.patch: Reformat ssh_kdf().
- debian/patches/CVE-2025-5372.patch: simplify error checking and
handling of return codes in ssh_kdf().
- CVE-2025-5372
* SECURITY UPDATE: Missing packet filter may expose to variant of
Terrapin attack
- debian/patches/missing_packet_filter.patch: implement missing packet
filter for DH GEX.
- No CVE number
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 02 Jul 2025 14:48:47 -0400
libpam-modules-bin, libpam-modules:amd64, libpam-runtime, libpam0g:amd64 (built from pam) updated from 1.4.0-11ubuntu2.5 to 1.4.0-11ubuntu2.6:
pam (1.4.0-11ubuntu2.6) jammy-security; urgency=medium
* SECURITY UPDATE: privilege escalation via pam_namespace
- debian/patches-applied/pam_namespace_170.patch: sync pam_namespace
module to version 1.7.0.
- debian/patches-applied/pam_namespace_post170-*.patch: add post-1.7.0
changes from upstream git tree.
- debian/patches-applied/pam_namespace_revert_abi.patch: revert ABI
change to prevent unintended issues in running daemons.
- debian/patches-applied/CVE-2025-6020-1.patch: fix potential privilege
escalation.
- debian/patches-applied/CVE-2025-6020-2.patch: add flags to indicate
path safety.
- debian/patches-applied/CVE-2025-6020-3.patch: secure_opendir: do not
look at the group ownership.
- debian/patches-applied/CVE-2024-22365.patch: removed, included in
patch cluster above.
- CVE-2025-6020
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 12 Jun 2025 10:45:28 -0400
python3-urllib3 (built from python-urllib3) updated from 1.26.5-1~exp1ubuntu0.2 to 1.26.5-1~exp1ubuntu0.3:
python-urllib3 (1.26.5-1~exp1ubuntu0.3) jammy-security; urgency=medium
* SECURITY UPDATE: Information disclosure through improperly disabled
redirects.
- debian/patches/CVE-2025-50181.patch: Add "retries" check and set retries
to Retry.from_int(retries, redirect=False) as well as set
raise_on_redirect in ./src/urllib3/poolmanager.py.
- CVE-2025-50181
-- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Mon, 23 Jun 2025 17:07:25 -0230
libpython3.10-minimal:amd64, libpython3.10-stdlib:amd64, python3.10, python3.10-minimal (built from python3.10) updated from 3.10.12-1~22.04.9 to 3.10.12-1~22.04.10:
python3.10 (3.10.12-1~22.04.10) jammy-security; urgency=medium
* SECURITY UPDATE: incorrect address list folding
- debian/patches/CVE-2025-1795-1.patch: don't encode list separators in
Lib/email/_header_value_parser.py,
Lib/test/test_email/test__header_value_parser.py.
- debian/patches/CVE-2025-1795-2.patch: fix AttributeError in the email
module in Lib/email/_header_value_parser.py,
Lib/test/test_email/test__header_value_parser.py.
- CVE-2025-1795
* SECURITY UPDATE: DoS via bytes.decode with unicode_escape
- debian/patches/CVE-2025-4516.patch: fix use-after-free in the
unicode-escape decoder with an error handler in
Include/cpython/bytesobject.h, Include/cpython/unicodeobject.h,
Lib/test/test_codeccallbacks.py, Lib/test/test_codecs.py,
Objects/bytesobject.c, Objects/unicodeobject.c,
Parser/string_parser.c.
- CVE-2025-4516
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 27 May 2025 13:12:29 -0400
python3-requests (built from requests) updated from 2.25.1+dfsg-2ubuntu0.1 to 2.25.1+dfsg-2ubuntu0.3:
requests (2.25.1+dfsg-2ubuntu0.3) jammy-security; urgency=medium
* SECURITY UPDATE: Information Leak
- debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
lookup instead of netloc
- CVE-2024-47081
-- Bruce Cable <bruce.cable@canonical.com> Wed, 11 Jun 2025 13:27:31 +1000
sudo (built from sudo) updated from 1.9.9-1ubuntu2.4 to 1.9.9-1ubuntu2.5:
sudo (1.9.9-1ubuntu2.5) jammy-security; urgency=medium
* SECURITY UPDATE: Local Privilege Escalation via host option
- debian/patches/CVE-2025-32462.patch: only allow specifying a host
when listing privileges.
- CVE-2025-32462
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 25 Jun 2025 08:48:23 -0400
12/06/2025, commit https://git.launchpad.net/snap-core22/tree/7c3b8a59559a1d01f35830501a6ef478213ae767
[ Changes in the core22 snap ]
No detected changes for the core22 snap
[ Changes in primed packages ]
libapt-pkg6.0:amd64 (built from apt) updated from 2.4.13 to 2.4.14:
apt (2.4.14) jammy; urgency=medium
* Fix buffer overflow, stack overflow, exponential complexity in
apt-ftparchive Contents generation (LP: #2083697)
- ftparchive: Mystrdup: Add safety check and bump buffer size
- ftparchive: contents: Avoid exponential complexity and overflows
- test framework: Improve valgrind support
- test: Check that apt-ftparchive handles deep paths
- increase valgrind cleanliness to make the tests pass
- pkgcachegen: Use placement new to construct header
- Workaround valgrind "invalid read" in ExtractTar::Go by moving large
buffer from stack to heap. The large buffer triggered some bugs in
valgrind stack clash protection handling.
-- Julian Andres Klode <juliank@ubuntu.com> Tue, 22 Oct 2024 15:09:58 +0200
cloud-init (built from cloud-init) updated from 24.4.1-0ubuntu0~22.04.2 to 25.1.2-0ubuntu0~22.04.2:
cloud-init (25.1.2-0ubuntu0~22.04.2) jammy; urgency=medium
* New bugfix release. (LP: #2113797)
- Revert relocation of systemd units and service files from /usr/lib
back to /lib so debhelper correctly enables cloud-init services in
postinst
-- Chad Smith <chad.smith@canonical.com> Mon, 09 Jun 2025 17:00:37 -0600
cloud-init (25.1.2-0ubuntu0~22.04.1) jammy; urgency=medium
* Upstream snapshot based on 25.1.2. (LP: #2104165).
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/25.1.2/ChangeLog
-- James Falcon <james.falcon@canonical.com> Fri, 02 May 2025 12:47:51 -0500
cloud-init (25.1.1-0ubuntu1~22.04.1) jammy; urgency=medium
* Drop cpicks which are now upstream:
- d/p/cpick-d75840be-fix-retry-AWS-hotplug-for-async-IMDS-5995
- d/p/cpick-84806336-chore-Add-feature-flag-for-manual-network-waiting
- d/p/cpick-c60771d8-test-pytestify-test_url_helper.py
- d/p/cpick-8810a2dc-test-Remove-CiTestCase-from-test_url_helper.py
- d/p/cpick-582f16c1-test-add-OauthUrlHelper-tests
- d/p/cpick-9311e066-fix-Update-OauthUrlHelper-to-use-readurl-exception_cb
* refresh patches
- d/p/deprecation-version-boundary.patch
- d/p/no-single-process.patch
- d/p/retain-ec2-default-net-update-events.patch
- d/p/revert-551f560d-cloud-config-after-snap-seeding.patch
* sort hunks within all patches (--sort on quilt refresh)
* d/cloud-init.templates:
- Move VMware before OVF. See GH-4030
- Enable CloudCIX by default
* Upstream snapshot based on 25.1.1.
List of changes from upstream can be found at
https://raw.githubusercontent.com/canonical/cloud-init/25.1.1/ChangeLog
-- Chad Smith <chad.smith@canonical.com> Tue, 25 Mar 2025 10:33:28 -0600
python3-pkg-resources, python3-setuptools (built from setuptools) updated from 59.6.0-1.2ubuntu0.22.04.2 to 59.6.0-1.2ubuntu0.22.04.3:
setuptools (59.6.0-1.2ubuntu0.22.04.3) jammy-security; urgency=medium
* SECURITY UPDATE: path traversal vulnerability
- debian/patches/CVE-2025-47273-pre1.patch: Extract
_resolve_download_filename with test.
- debian/patches/CVE-2025-47273.patch: Add a check to ensure the name
resolves relative to the tmpdir.
- CVE-2025-47273
-- Fabian Toepfer <fabian.toepfer@canonical.com> Wed, 28 May 2025 19:13:58 +0200
libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, systemd-timesyncd, udev (built from systemd) updated from 249.11-0ubuntu3.15 to 249.11-0ubuntu3.16:
systemd (249.11-0ubuntu3.16) jammy-security; urgency=medium
* SECURITY UPDATE: race condition in systemd-coredump
- debian/patches/CVE_2025_4598_1.patch: coredump: get rid of
_META_MANDATORY_MAX.
- debian/patches/CVE_2025_4598_2.patch: coredump: use %d in kernel core
pattern.
- debian/patches/CVE_2025_4598_3.patch: coredump: get rid of a bogus
assertion.
- CVE-2025-4598
-- Octavio Galland <octavio.galland@canonical.com> Wed, 04 Jun 2025 11:17:43 -0300