/snap/core18/3084/usr/share/doc
Edit: /snap/core18/3084/usr/share/doc/ChangeLog (67622B)
01/09/2026, commit https://git.launchpad.net/snap-core18/tree/ac77ccdf97b1bee988ee961e41efc2f5d06bd633
[ Changes in the core18 snap ]
Mohit Chachada (1):
README: document where to find changelog (#203)
[ Changes in primed packages ]
libattr1:amd64 (built from attr) updated from 1:2.4.47-2build1 to 1:2.4.47-2ubuntu0.18.04.1~esm1:
attr (1:2.4.47-2ubuntu0.18.04.1~esm1) bionic-security; urgency=medium
* SECURITY UPDATE: Symlink Traversal
- d/p/CVE-2026-54371-01-add-visibility-attribute-header.patch: Add
visibility attribute header in include/Makefile, include/visibility-
hidden.h.
- d/p/CVE-2026-54371-02-add-xattrat-syscall-wrappers.patch: Add xattrat
syscall wrappers in configure.in, include/Makefile, include/xattrat.h,
libmisc/Makefile, libmisc/xattrat.c, include/builddefs.in,
include/config.h.in.
- d/p/CVE-2026-54371-03-add-xattrat-syscall-backwards-compatibility-
code.patch: Add xattrat syscall backwards compatibility code in
include/Makefile, include/xattrat_compat.h, libmisc/Makefile,
libmisc/getxattrat_compat.c, libmisc/listxattrat_compat.c, libmisc/proc-
self-fd.c, libmisc/proc-self-fd.h, libmisc/removexattrat_compat.c,
libmisc/setxattrat_compat.c, include/builddefs.in.
- d/p/CVE-2026-54371-04-rename-walk_tree-to-old_walk_tree.patch: Rename
walk_tree to old_walk_tree in include/Makefile, include/old_walk_tree.h,
libmisc/Makefile, libmisc/old_walk_tree.c, getfattr/getfattr.c.
- d/p/CVE-2026-54371-05-add-the-new-walk_tree-helper.patch: Add the new
walk_tree helper in include/Makefile, include/walk_tree.h,
libmisc/Makefile, libmisc/walk_tree.c.
- debian/patches/CVE-2026-54371-06-harden-getfattr.patch: harden getfattr in
man/man1/getfattr.1, getfattr/getfattr.c.
- d/p/CVE-2026-54371-07-setfattr-multiple-restore-accesses-freed-
buffer.patch: setfattr: multiple --restore accesses freed buffer in
setfattr/setfattr.c.
- d/p/CVE-2026-54371-08-setfattr-do-not-ignore-no-dereference-after-
restore.patch: setfattr: Do not ignore --no-dereference after --restore in
setfattr/setfattr.c.
- d/p/CVE-2026-54371-09-add-openat2-syscall-wrapper.patch: Add openat2
syscall wrapper in configure.in, include/Makefile, include/openat2.h,
libmisc/Makefile, libmisc/openat2.c, include/builddefs.in,
include/config.h.in.
- debian/patches/CVE-2026-54371-10-harden-setfattr-restore.patch: harden
setfattr --restore in configure.in, man/man1/setfattr.1, test/Makefile,
test/restore.test, setfattr/setfattr.c, include/builddefs.in,
include/config.h.in.
- CVE-2026-54371
-- John Breton
Sun, 23 Aug 2026 21:48:18 -0400
libdns-export1100, libisc-export169:amd64 (built from bind9) updated from 1:9.11.3+dfsg-1ubuntu1.19+esm4 to 1:9.11.3+dfsg-1ubuntu1.19+esm5:
bind9 (1:9.11.3+dfsg-1ubuntu1.19+esm5) bionic-security; urgency=medium
* SECURITY UPDATE: BIND 9 server memory exhaustion during GSS-API TKEY
negotiation
- debian/patches/CVE-2026-3039-pre1.patch: Release gnamebuf also on the
error path in lib/dns/gssapictx.c.
- debian/patches/CVE-2026-3039-1.patch: Fix GSS-API context leak in TKEY
negotiation by rejecting multi-round GSS-API negotiation in
lib/dns/gssapictx.c, lib/dns/include/dst/gssapi.h, lib/dns/tkey.c.
- debian/patches/CVE-2026-3039-3.patch: Fix output token and GSS context
leaks in TKEY/GSS-API error paths in lib/dns/gssapictx.c,
lib/dns/tkey.c.
- CVE-2026-3039
* SECURITY UPDATE: Amplification vulnerabilities via self-pointed glue
records
- debian/patches/CVE-2026-3592-1.patch: Limit the number of addresses
returned per ADB find in bin/named/main.c, lib/dns/adb.c.
- debian/libdns1100.symbols: Add new exported symbol
dns_adb_addrslimit.
- debian/patches/CVE-2026-3592-2.patch: Remove duplicate addresses from
the resolver SLIST by replacing sort-based selection with linear scan
in nextaddress() in lib/dns/resolver.c.
- debian/patches/CVE-2026-3592-3.patch: Add system test for self-pointed
glue deduplication in bin/tests/system/selfpointedglue/.
- debian/patches/CVE-2026-3592-5.patch: Add SRTT-based server selection
system test in bin/tests/system/srtt/.
- CVE-2026-3592
* SECURITY UPDATE: Invalid handling of CLASS != IN
- debian/patches/CVE-2026-5946-1.patch: Disable recursion for non-IN
classes in bin/named/server.c, lib/bind9/check.c.
- debian/patches/CVE-2026-5946-2.patch: Disable UPDATE and NOTIFY for
non-IN classes in bin/named/client.c, bin/named/server.c,
bin/named/update.c, lib/dns/adb.c.
- debian/patches/CVE-2026-5946-3.patch: Validate DNS message CLASS early
in request processing in bin/named/client.c.
- debian/patches/CVE-2026-5946-4.patch: Reject meta-classes in UPDATE and
NOTIFY messages in lib/dns/message.c.
- debian/patches/CVE-2026-5946-5.patch: Skip "deny-answer-address" for
non-IN addresses in lib/dns/resolver.c.
- debian/patches/CVE-2026-5946-7.patch: Remove redundant recursion
setting for non-IN views in bin/named/server.c.
- CVE-2026-5946
-- Leonidas Da Silva Barbosa Thu, 30 Jul 2026 07:22:41 -0300
bzip2, libbz2-1.0:amd64 (built from bzip2) updated from 1.0.6-8.1ubuntu0.2 to 1.0.6-8.1ubuntu0.2+esm1:
bzip2 (1.0.6-8.1ubuntu0.2+esm1) bionic-security; urgency=medium
* SECURITY UPDATE: out-of-bounds write
- debian/patches/CVE-2026-42250.patch: bzip2recover: Make sure to not
process more than BZ_MAX_HANDLED_BLOCKS in bzip2recover.c.
- CVE-2026-42250
-- Shishir Subedi Thu, 27 Aug 2026 09:53:56 +0545
diffutils (built from diffutils) updated from 1:3.6-1 to 1:3.6-1ubuntu0.1~esm1:
diffutils (1:3.6-1ubuntu0.1~esm1) bionic-security; urgency=medium
* SECURITY UPDATE: Integer Overflow
- debian/patches/CVE-2026-53910-1.patch: diff3: check for integer overflows
when reading line numbers from diff in NEWS, THANKS, src/diff3.c.
- debian/patches/CVE-2026-53910-2.patch: diff3: prevent overflow in line
offsets in src/diff3.c.
- CVE-2026-53910
-- John Breton Wed, 26 Aug 2026 14:34:16 -0400
distro-info-data (built from distro-info-data) updated from 0.37ubuntu0.20 to 0.37ubuntu0.21:
distro-info-data (0.37ubuntu0.21) bionic; urgency=medium
* Add Ubuntu 26.10 "Stonking Stingray" (LP: #2150234)
-- Oliver Reiche Tue, 28 Apr 2026 16:36:47 +0200
libgnutls30:amd64 (built from gnutls28) updated from 3.5.18-1ubuntu1.6+esm2 to 3.5.18-1ubuntu1.6+esm4:
gnutls28 (3.5.18-1ubuntu1.6+esm4) bionic-security; urgency=medium
* SECURITY UPDATE: Name constraint bypass during certificate validation
- debian/patches/CVE-2026-42011.patch: Fix intersecting empty constraints
in lib/x509/name_constraints.c.
- CVE-2026-42011
* SECURITY UPDATE: Certificate validation bypass via URI/SRV SAN CN fallback
- debian/patches/CVE-2026-42012-pre1.patch: Refactor and simplify CN
fallback logic in lib/x509/hostname-verify.c.
- debian/patches/CVE-2026-42012-pre2.patch: Add bare-bones awareness of
SRV virtual SAN in lib/includes/gnutls/gnutls.h.in, lib/x509/common.h,
lib/x509/output.c, lib/x509/virt-san.c, lib/x509/x509.c.
- debian/patches/CVE-2026-42012.patch: Make URI/SRV SAN preclude CN
fallback in lib/x509/hostname-verify.c.
- CVE-2026-42012
* SECURITY UPDATE: Certificate validation bypass via oversized SAN fallback
- debian/patches/CVE-2026-42013-pre1.patch: Refactor DN fallback logic in
lib/x509/email-verify.c.
- debian/patches/CVE-2026-42013.patch: Prevent fallback on oversized SAN
in lib/x509/email-verify.c, lib/x509/hostname-verify.c.
- CVE-2026-42013
* SECURITY UPDATE: Memory corruption in PKCS#12 bag bounds check
- debian/patches/CVE-2026-42015.patch: Fix off-by-one in bag element
bounds check in lib/x509/pkcs12_bag.c.
- CVE-2026-42015
-- Shafayat Hossain Majumder Fri, 10 Jul 2026 16:44:55 -0400
gnutls28 (3.5.18-1ubuntu1.6+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: Timing side channel during RSA-PSK decryption
- debian/patches/CVE-2024-0553.patch: Eliminate post-decryption RSA-PSK
branching in lib/auth/rsa_psk.c.
- CVE-2024-0553
* SECURITY UPDATE: Resource exhaustion during name-constraint processing
- debian/patches/CVE-2024-12243-pre1.patch: Add overflow-safe array
reallocation in lib/mem.c and lib/mem.h.
- debian/patches/CVE-2024-12243-pre2.patch: Add checked integer arithmetic
in gl/intprops.h.
- debian/patches/CVE-2024-12243.patch: Bound and optimize name-constraint
processing in lib/datum.c, lib/x509/name_constraints.c,
lib/x509/x509_ext.c, lib/x509/x509_ext_int.h, and lib/x509/x509_int.h.
- CVE-2024-12243
* SECURITY UPDATE: Stack buffer overflow during PKCS#11 token initialization
- debian/patches/CVE-2025-9820.patch: Bound PKCS#11 token labels in
lib/pkcs11_write.c.
- CVE-2025-9820
* SECURITY UPDATE: Resource exhaustion during name-constraint intersection
- debian/patches/CVE-2025-14831-1.patch: Correct universal IP exclusions in
lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-2.patch: Propagate name-constraint test
failures in tests/name-constraints-ip.c.
- debian/patches/CVE-2025-14831-3.patch: Reject malformed domain
constraints in lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-4.patch: Add name-constraint node
constructors in lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-5.patch: Add rich name-constraint
comparison in lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-6.patch: Add sorted constraint views in
lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-7.patch: Implement name-constraint union in
lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-8.patch: Represent empty intersections as
a bitmask in lib/x509/name_constraints.c.
- debian/patches/CVE-2025-14831-9.patch: Intersect sorted name constraints
in lib/x509/name_constraints.c.
- CVE-2025-14831
* SECURITY UPDATE: Certificate bypass during name-constraint matching
- debian/patches/CVE-2026-3833.patch: Compare constrained domain names
case-insensitively in lib/x509/name_constraints.c.
- CVE-2026-3833
* SECURITY UPDATE: Heap overread during PKCS#11-backed RSA decryption
- debian/patches/CVE-2026-5260-1.patch: Validate RSA ciphertext modulus
lengths in lib/auth/rsa_psk.c.
- debian/patches/CVE-2026-5260-2.patch: Prevent short-ciphertext overreads
in lib/pkcs11_privkey.c.
- CVE-2026-5260
* SECURITY UPDATE: Heap buffer overflow during DTLS fragment reassembly
- debian/patches/CVE-2026-33846-pre1.patch: Simplify DTLS receive-buffer
access in lib/buffers.c.
- debian/patches/CVE-2026-33846.patch: Validate DTLS fragment consistency
and bounds in lib/buffers.c.
- CVE-2026-33846
* SECURITY UPDATE: Denial of service during DTLS packet ordering
- debian/patches/CVE-2026-42009-pre1.patch: Match DTLS fragments by
sequence number in lib/buffers.c.
- debian/patches/CVE-2026-42009-1.patch: Reject conflicting DTLS fragment
sequence numbers in lib/buffers.c.
- debian/patches/CVE-2026-42009-2.patch: Handle equal DTLS sequence numbers
in lib/buffers.c.
- CVE-2026-42009
-- Shafayat Hossain Majumder Tue, 30 Jun 2026 12:23:54 -0400
kmod, libkmod2:amd64 (built from kmod) updated from 24-1ubuntu3.5 to 24-1ubuntu3.5+esm1:
kmod (24-1ubuntu3.5+esm1) bionic-security; urgency=medium
* Disable loading of algif_aead module to mitigate CVE-2026-31431
(LP: #2150743)
- debian/modprobe.d/disable-algif_aead.conf
-- Eduardo Barretto Thu, 30 Apr 2026 14:55:55 +0200
libcap2:amd64 (built from libcap2) updated from 1:2.25-1.2ubuntu0.1~esm1 to 1:2.25-1.2ubuntu0.1~esm2:
libcap2 (1:2.25-1.2ubuntu0.1~esm2) bionic-security; urgency=medium
* SECURITY UPDATE: TOCTOU race condition in cap_set_file().
- debian/patches/CVE-2026-4878.patch: Locks onto the intended file in
cap_set_file() in libcap/cap_file.c and progs/quicktest.sh
- CVE-2026-4878
-- Kyle Kernick Mon, 22 Jun 2026 11:40:03 -0600
libncurses5:amd64, libncursesw5:amd64, libtinfo5:amd64, ncurses-base, ncurses-bin (built from ncurses) updated from 6.1-1ubuntu1.18.04.1+esm2 to 6.1-1ubuntu1.18.04.1+esm3:
ncurses (6.1-1ubuntu1.18.04.1+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: stack-based buffer overflow in infocmp
- debian/patches/CVE-2025-69720.patch: clamp length to
MAX_TERMINFO_LENGTH before copying into buf2 in analyze_string.
- CVE-2025-69720
-- Paulo Flabiano Smorigo Tue, 30 Jun 2026 21:25:34 +0000
libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm8 to 1.1.1-1ubuntu2.1~18.04.23+esm10:
openssl (1.1.1-1ubuntu2.1~18.04.23+esm10) bionic-security; urgency=medium
* SECURITY UPDATE: HollowByte Denial of Service issue (LP: #2161371)
- debian/patches/lp2161371.patch: Grow the init_buf incrementally as we
receive data in ssl/statem/statem.c, ssl/statem/statem_lib.c.
- No CVE number
* SECURITY UPDATE: crash or memory disclosure via SSL_select_next_proto
- debian/patches/CVE-2024-5535.patch: validate provided client list in
ssl/ssl_lib.c.
- CVE-2024-5535
* SECURITY UPDATE: unbounded mem growth when processing TLSv1.3 sessions
- debian/patches/CVE-2024-2511.patch: fix unconstrained session cache
growth in TLSv1.3 in ssl/ssl_lib.c, ssl/ssl_sess.c,
ssl/statem/statem_srvr.c.
- CVE-2024-2511
* SECURITY UPDATE: Excessive Memory Use Buffering DTLS Records for a Future
Epoch
- debian/patches/CVE-2026-54874-1.patch: Avoid full read buffer allocation
when buffering DTLS records in ssl/record/rec_layer_d1.c,
ssl/record/record.h, ssl/record/ssl3_record.c.
- debian/patches/CVE-2026-54874-2.patch: ssl/record: lower the DTLS
unprocessed_rcds queue limit in ssl/record/rec_layer_d1.c,
ssl/record/record_local.h, ssl/record/ssl3_record.c.
- CVE-2026-54874
* SECURITY UPDATE: Heap Buffer Overflow in CMS Key Unwrapping
- debian/patches/CVE-2026-63072-1.patch: Add test for CVE-2026-63072 in
test/cmsapitest.c, test/recipes/80-test_cmsapi.t.
- debian/patches/CVE-2026-63072-2.patch: Fix heap buffer overflow (8-byte
OOB write) in AES-WRAP-PAD unwrap in crypto/cms/cms_kari.c.
- CVE-2026-63072
-- Leonidas Da Silva Barbosa Mon, 17 Aug 2026 11:15:51 -0300
openssl (1.1.1-1ubuntu2.1~18.04.23+esm9) bionic-security; urgency=medium
* SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing
- debian/patches/CVE-2026-34180.patch: Avoid length truncation in
ASN1_STRING_set in crypto/asn1/tasn_dec.c.
- CVE-2026-34180
* SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages
- debian/patches/CVE-2026-34182-pre1.patch: Ensure
ossl_cms_EncryptedContent_init_bio() reports an error on no OID in
crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt,
include/openssl/cmserr.h.
- CVE-2026-34182
* SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption
- debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference
processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c.
- CVE-2026-42766
* SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify()
- debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary
PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in
OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in
PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty-
digest-set.eml.
- CVE-2026-45447
* SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String
Conversion
- debian/patches/CVE-2026-7383.patch: Reject oversized inputs in
ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c.
- CVE-2026-7383
* SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption
- debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds
read in check-byte validation in crypto/cms/cms_pwri.c.
- CVE-2026-9076
-- Leonidas Da Silva Barbosa Fri, 05 Jun 2026 09:36:42 -0300
libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm4 to 1.0.2n-1ubuntu5.13+esm6:
openssl1.0 (1.0.2n-1ubuntu5.13+esm6) bionic-security; urgency=medium
* SECURITY UPDATE: HollowByte Denial of Service issue (LP: #2161371)
- debian/patches/lp2161371.patch: Grow the init_buf incrementally as we
receive data in ssl/s3_both.c.
- No CVE number
* SECURITY UPDATE: crash or memory disclosure via SSL_select_next_proto
- debian/patches/CVE-2024-5535.patch: validate provided client list in
ssl/ssl_lib.c.
- CVE-2024-5535
* SECURITY UPDATE: Excessive Memory Use Buffering DTLS Records for a Future
Epoch
- debian/patches/CVE-2026-54874-1.patch: Avoid full read buffer allocation
when buffering DTLS records in ssl/d1_pkt.c, ssl/d1_lib.c, ssl/dtls1.h.
- debian/patches/CVE-2026-54874-2.patch: ssl/record: lower the DTLS
unprocessed_rcds queue limit in ssl/d1_pkt.c.
- CVE-2026-54874
* SECURITY UPDATE: Heap Buffer Overflow in CMS Key Unwrapping
- debian/patches/CVE-2026-63072-2.patch: Fix heap buffer overflow (8-byte
OOB write) in AES-WRAP-PAD unwrap in crypto/cms/cms_kari.c.
- CVE-2026-63072
-- Leonidas Da Silva Barbosa Thu, 20 Aug 2026 12:47:48 -0300
openssl1.0 (1.0.2n-1ubuntu5.13+esm5) bionic-security; urgency=medium
* SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing
- debian/patches/CVE-2026-34180.patch: Avoid length truncation in
ASN1_STRING_set in crypto/asn1/tasn_dec.c.
- CVE-2026-34180
* SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages
- debian/patches/CVE-2026-34182-pre1.patch: Ensure
ossl_cms_EncryptedContent_init_bio() reports an error on no OID in
crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt,
include/openssl/cmserr.h.
- CVE-2026-34182
* SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption
- debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference
processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c.
- CVE-2026-42766
* SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify()
- debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary
PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in
OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in
PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty-
digest-set.eml.
- CVE-2026-45447
* SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String
Conversion
- debian/patches/CVE-2026-7383.patch: Reject oversized inputs in
ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c.
- CVE-2026-7383
* SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption
- debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds
read in check-byte validation in crypto/cms/cms_pwri.c.
- CVE-2026-9076
-- Leonidas Da Silva Barbosa Fri, 05 Jun 2026 12:50:04 -0300
libp11-kit0:amd64 (built from p11-kit) updated from 0.23.9-2ubuntu0.1 to 0.23.9-2ubuntu0.1+esm1:
p11-kit (0.23.9-2ubuntu0.1+esm1) bionic-security; urgency=medium
* SECURITY UPDATE: integer overflow in nested attribute decoding
- debian/patches/CVE-2026-18938.patch: guard against overflow when
decoding nested attributes (32-bit only, heap OOB write, DoS).
- CVE-2026-18938
* SECURITY UPDATE: unbounded recursion in RPC attribute parsing
- debian/patches/CVE-2026-13757.patch: add recursion depth limit into
RPC attribute parsing (stack exhaustion, DoS).
- CVE-2026-13757
-- Leonidas Da Silva Barbosa Tue, 25 Aug 2026 07:28:42 -0300
libpam-modules-bin, libpam-modules:amd64, libpam-runtime, libpam0g:amd64 (built from pam) updated from 1.1.8-3.6ubuntu2.18.04.6+esm1 to 1.1.8-3.6ubuntu2.18.04.6+esm2:
pam (1.1.8-3.6ubuntu2.18.04.6+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: account lockout bypass in pam_faillock account
management phase (LP: #2164901)
- debian/patches-applied/lp-2164901.patch: skip clearing
user's failed attempt in modules/pam_faillock/pam_faillock.c.
- No CVE number
-- Shafayat Hossain Majumder Wed, 26 Aug 2026 15:37:28 -0400
perl-base (built from perl) updated from 5.26.1-6ubuntu0.7 to 5.26.1-6ubuntu0.7+esm3:
perl (5.26.1-6ubuntu0.7+esm3) bionic-security; urgency=high
* SECURITY UPDATE: Out-of-bounds heap read in Socket pack_ip_mreq_source
- debian/patches/CVE-2026-12087.patch: Scope STRLEN len per argument in
pack_ip_mreq_source in cpan/Socket/Socket.xs
- CVE-2026-12087
* SECURITY UPDATE: Trie 16-bit overflow causing incorrect regex matches
- debian/patches/CVE-2026-13221.patch: Skip trie creation when branch delta
would overflow 16 bits in regcomp.c, t/re/pat_advanced.t
- CVE-2026-13221
* SECURITY UPDATE: Integer overflow leading to heap OOB read in pack/unpack
- debian/patches/CVE-2026-57432_1.patch: Reject pack/unpack template sizes
that would overflow SSize_t in pp_pack.c
- debian/patches/CVE-2026-57432_2.patch: Avoid bit-count overflows in B/H
template size math in pp_pack.c
- CVE-2026-57432
* SECURITY UPDATE: Signed int overflow in Storable SX_HOOK deserialization
- debian/patches/CVE-2026-57433.patch: Reject I32_MAX hook data item counts
before av_extend in dist/Storable/Storable.xs
- CVE-2026-57433
-- Shafayat Hossain Majumder Tue, 18 Aug 2026 17:25:19 -0400
perl (5.26.1-6ubuntu0.7+esm2) bionic-security; urgency=high
* SECURITY UPDATE: integer overflow in regular expression compiler
- debian/patches/CVE-2026-8376_1.patch: accept quantifier limit error
on 32-bit architectures where the quantifier limit catches the
oversized pattern before the overflow guard
- CVE-2026-8376
-- Chrisa Oikonomou Mon, 23 Jun 2026 11:11:00 +0300
perl (5.26.1-6ubuntu0.7+esm1) bionic-security; urgency=high
* SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction
- debian/patches/CVE-2026-42496.patch: validate symlink and hardlink
targets against absolute paths and directory traversal in
cpan/Archive-Tar/lib/Archive/Tar.pm
- CVE-2026-42496
* SECURITY UPDATE: integer overflow in regular expression compiler
- debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer
overflow via quantified fixed-string regex in t/re/pat_psycho.t
- debian/patches/CVE-2026-8376_2.patch: add overflow check before
fixed-string buffer allocation in regcomp.c / regcomp_study.c
- CVE-2026-8376
-- Chrisa Oikonomou Fri, 12 Jun 2026 16:42:32 +0300
python3-cryptography (built from python-cryptography) updated from 2.1.4-1ubuntu1.4+esm1 to 2.1.4-1ubuntu1.4+esm3:
python-cryptography (2.1.4-1ubuntu1.4+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: Subgroup Attack due to Missing Subgroup Validation for
SECT Curves
- debian/patches/CVE-2026-26007.patch: EC check key on cofactor > 1 in
src/cryptography/hazmat/primitives/asymmetric/ec.py,
src/cryptography/utils.py, tests/hazmat/primitives/test_ec.py,
src/_cffi_src/openssl/ec.py,
src/cryptography/hazmat/backends/openssl/ec.py.
- CVE-2026-26007
-- Sudhakar Verma Mon, 20 Apr 2026 21:38:35 +0530
sed (built from sed) updated from 4.4-2 to 4.4-2ubuntu0.1~esm1:
sed (4.4-2ubuntu0.1~esm1) bionic-security; urgency=medium
* SECURITY UPDATE: TOCTOU race in sed -i --follow-symlinks
- debian/patches/CVE-2026-5958.patch: open the already-resolved path
instead of re-traversing the symlink in sed/execute.c.
- CVE-2026-5958
-- Kyle Kernick Wed, 27 May 2026 09:38:00 -0600
tar (built from tar) updated from 1.29b-2ubuntu0.4+esm1 to 1.29b-2ubuntu0.4+esm4:
tar (1.29b-2ubuntu0.4+esm4) bionic-security; urgency=medium
* SECURITY REGRESSION: Old archives with nonzero directory sizes
failing to be extracted
- debian/patches/CVE-2026-5704-5.patch: fix this by forcing
the size to zero for DIRTYPE in read_header() in src/list.c
(LP: #2161311).
-- Leonidas Da Silva Barbosa Mon, 20 Jul 2026 13:21:24 -0300
tar (1.29b-2ubuntu0.4+esm3) bionic-security; urgency=medium
* SECURITY REGRESSION: Extract files issue
- debian/patches/CVE-2026-5704-*.patch: address a regression
that makes valid files not extract in src/list.c,
tests/Makefile.am, tests/extrac32.at, tests/extrac34.at,
test/testsuite.at, src/extract.c, tests/extract23,
tests/extrac30.at (LP: #2160650).
-- Leonidas Da Silva Barbosa Wed, 15 Jul 2026 14:47:55 -0300
tar (1.29b-2ubuntu0.4+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: file injection via crafted archive
- debian/patches/CVE-2026-5704.patch: always call skip_member() after
extraction in extract_archive(), remove conditional skip_member()
from purge_directory(), skip directory data in skim_member(), and
stop forcing LNKTYPE size to zero in read_header().
- CVE-2026-5704
-- Leonidas Da Silva Barbosa Tue, 23 Jun 2026 11:48:07 -0300
tzdata (built from tzdata) updated from 2025b-0ubuntu0.18.04+esm1 to 2026c-0ubuntu0.18.04+esm1:
tzdata (2026c-0ubuntu0.18.04+esm1) bionic-security; urgency=medium
* New upstream release (LP: #2161092):
- Alberta moved to permanent -06 on 2026-06-18, so it will not fall back
from -06 to -07 on 2026-11-01.
- Morocco moves to permanent +00 on 2026-09-20.
* Add autopkgtest test case for 2026c release
-- Benjamin Drung Fri, 17 Jul 2026 15:10:52 +0200
tzdata (2026b-0ubuntu0.18.04+esm1) bionic-security; urgency=medium
* New upstream release (LP: #2157973):
- British Columbia moved to permanent -07 on 2026-03-09, so it will not
fall back from -07 to -08 on 2026-11-01.
* Add autopkgtest test case for 2026b release
-- Benjamin Drung Wed, 24 Jun 2026 13:46:50 +0200
tzdata (2026a-0ubuntu0.18.04+esm1) bionic-security; urgency=medium
* New upstream release (LP: #2143355):
- No leap second on 2026-06-30
- Moldova has used EU transition times since 2022
* Add autopkgtest test case for 2025c and 2026a release
-- Nadzeya Hutsko Thu, 11 Jun 2026 17:36:34 +0200
vim-common, vim-tiny, xxd (built from vim) updated from 2:8.0.1453-1ubuntu1.13+esm14 to 2:8.0.1453-1ubuntu1.13+esm24:
vim (2:8.0.1453-1ubuntu1.13+esm24) bionic-security; urgency=medium
* SECURITY UPDATE: Arbitrary command execution during C omni-completion.
- debian/patches/CVE-2026-73073.patch: Match tags typeref literally in
runtime/autoload/ccomplete.vim.
- CVE-2026-73073
-- Kyle Kernick Mon, 24 Aug 2026 16:14:11 -0600
vim (2:8.0.1453-1ubuntu1.13+esm23) bionic-security; urgency=medium
* SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785)
- debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in
runtime/autoload/netrw.vim
- debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname
in runtime/autoload/netrw.vim
* SECURITY UPDATE: Heap buffer overflow in set_sofo().
- debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in
src/spellfile.c.
- CVE-2026-73072
* SECURITY UPDATE: Code execution via VimballRecord file.
- debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix
broken directory deletion code, and refactor code in
runtime/autoload/vimball.vim
- CVE-2026-73076
* SECURITY UPDATE: Code injection in netrw via bookmarks.
- debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in
runtime/autoload/netrw.vim.
- CVE-2026-73078
-- Kyle Kernick Tue, 18 Aug 2026 17:27:10 -0600
vim (2:8.0.1453-1ubuntu1.13+esm22) bionic-security; urgency=medium
* SECURITY UPDATE: Stack out-of-bounds write in spell_soundfold_sal().
- debian/patches/CVE-2026-59857.patch: Bound the single-byte SAL result
writes in src/spell.c
- CVE-2026-59857
* SECURITY UPDATE: Arbitrary command execution during C omni-completion.
- debian/patches/CVE-2026-59858.patch: Escape the type field before
inserting it into pattern in runtime/autoload/ccomplete.vim
- CVE-2026-59858
-- Kyle Kernick Mon, 13 Jul 2026 13:11:05 -0600
vim (2:8.0.1453-1ubuntu1.13+esm21) bionic-security; urgency=medium
* SECURITY UPDATE: Path Traversal in zip.vim
- debian/patches/CVE-2026-35177.patch: Detect malicious zip files before
writing in runtime/autoload/zip.vim
- CVE-2026-35177
* SECURITY UPDATE: Out-of-bounds write.
- debian/patches/CVE-2026-55693.patch: only descend while
depth < MAXWLEN - 1 in src/spellfile.c.
- debian/patches/CVE-2026-55892.patch: only descend while
depth < MAXWLEN - 1 in src/spell.c.
- CVE-2026-55693
- CVE-2026-55892
* SECURITY UPDATE: Code injection in local file deletion.
- debian/patches/CVE-2026-55895.patch: Use fnameescape() to escape
file name in runtime/autoload/netrw.vim.
- CVE-2026-55895
* SECURITY UPDATE: Out-of-bounds write with soundfold().
- debian/patches/CVE-2026-57455.patch: Add an abort condition to validate
buffer in src/spell.c.
- CVE-2026-57455
* SECURITY UPDATE: Code execution with python complete.
- debian/patches/CVE-2026-57456.patch: Use repr() to quote the doc strings
in runtime/autoload/python3complete.vim and ../pythoncomplete.vim.
- CVE-2026-57456
-- Kyle Kernick Tue, 30 Jun 2026 13:53:59 -0600
vim (2:8.0.1453-1ubuntu1.13+esm20) bionic-security; urgency=medium
* SECURITY UPDATE: Code injection via NetrwBookHistSave().
- debian/patches/CVE-2026-47162.patch: Properly quote the directory name
in runtime/autoload/netrw.vim.
- CVE-2026-47162
* SECURITY UPDATE: Code Injection in cucumber filetype plugin.
- debian/patches/CVE-2026-47167.patch: Use rubys Regexp.new() in
runtime/ftplugin/cucumber.vim.
- CVE-2026-47167
* SECURITY UPDATE: Code execution with python3complete.
- debian/patches/CVE-2026-52858.patch: Disable execution of import/from
statements in runtime/autoload/python3complete.vim and
../pythoncomplete.vim
- debian/patches/CVE-2026-52860.patch: Strip default expressions and
annotations in runtime/autoload/python3complete.vim and
../pythoncomplete.vim
- CVE-2026-52858
- CVE-2026-52860
* SECURITY UPDATE: Out-of-bounds read in update_snapshot().
- debian/patches/CVE-2026-52859.patch: Bound loop in update_snapshot() in
src/terminal.c.
- CVE-2026-52859
-- Kyle Kernick Mon, 15 Jun 2026 16:22:28 -0600
vim (2:8.0.1453-1ubuntu1.13+esm19) bionic-security; urgency=medium
* SECURITY UPDATE: Command injection in tar plugin.
- debian/patches/CVE-2026-46483.patch: Use the correct shell-escape in
runtime/autoload/tar.vim.
- CVE-2026-46483
* SECURITY UPDATE: Code injection via mf command.
- debian/patches/CVE-2026-43961.patch: Avoid string concatenation for
filter commands in runtime/autoload/netrw.vim.
- CVE-2026-43961
-- Kyle Kernick Wed, 03 Jun 2026 13:20:01 -0600
vim (2:8.0.1453-1ubuntu1.13+esm18) bionic-security; urgency=medium
* SECURITY UPDATE: Command injection via backtick expansion in tag files
- debian/patches/CVE-2026-41411.patch: Disallow backticks before attempting
to expand filenames
- CVE-2026-41411
-- Kyle Kernick Mon, 25 May 2026 16:48:55 -0600
vim (2:8.0.1453-1ubuntu1.13+esm17) bionic-security; urgency=medium
* SECURITY UPDATE: Command injection in netrw plugin.
- debian/patches/CVE-2026-42307.patch: Escape file names and harden regex
patterns in runtime/autoload/netrw.vim
- CVE-2026-42307
* SECURITY UPDATE: Shell execution in completion.
- debian/patches/CVE-2026-44656.patch: Skip path entries containing
backticks and add P_SECURE option in src/misc1.c and src/option.c
- CVE-2026-44656
* SECURITY UPDATE: Heap overflow in spellfile.
- debian/patches/CVE-2026-45130.patch: Enforce a maximum compound length
in src/spellfile.c
- CVE-2026-45130
-- Kyle Kernick Wed, 20 May 2026 15:32:07 -0600
vim (2:8.0.1453-1ubuntu1.13+esm16) bionic-security; urgency=medium
* SECURITY UPDATE: Command Injection in netbeans
- debian/patches/CVE-2026-39881.patch: Validate typename, fg, and bg
before passing to coloncmd in src/netbeans.c
- CVE-2026-39881
-- Kyle Kernick Wed, 22 Apr 2026 12:32:59 -0600
liblzma5:amd64 (built from xz-utils) updated from 5.2.2-1.3ubuntu0.1 to 5.2.2-1.3ubuntu0.1+esm1:
xz-utils (5.2.2-1.3ubuntu0.1+esm1) bionic-security; urgency=medium
* SECURITY UPDATE: heap buffer overflow
- debian/patches/CVE-2026-34743.patch: adds a check to
lzma_index_prealloc() to default to a safe size when decoding empty
indexes in src/liblzma/common/index.c.
- CVE-2026-34743
-- Ian Constantin Thu, 28 May 2026 19:06:23 +0300
10/04/2026, commit https://git.launchpad.net/snap-core18/tree/07351192087830057d9ad8554c6807f0a7690077
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
libexpat1:amd64 (built from expat) updated from 2.2.5-3ubuntu0.9+esm2 to 2.2.5-3ubuntu0.9+esm3:
expat (2.2.5-3ubuntu0.9+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: NULL pointer dereference
- debian/patches/CVE-2026-24515.patch: updates
XML_ExternalEntityParserCreate to copy unknown encoding handler user
data in expat/lib/xmlparse.c.
- CVE-2026-24515
* SECURITY UPDATE: integer overflow
- debian/patches/CVE-2026-25210*.patch: adds an integer overflow check for
tag buffer reallocation in the doContent function of
expat/lib/xmlparse.c.
- CVE-2026-25210
-- Ian Constantin Wed, 04 Feb 2026 17:24:02 +0200
libglib2.0-0:amd64 (built from glib2.0) updated from 2.56.4-0ubuntu0.18.04.9+esm4 to 2.56.4-0ubuntu0.18.04.9+esm5:
glib2.0 (2.56.4-0ubuntu0.18.04.9+esm5) bionic-security; urgency=medium
* SECURITY UPDATE: overflow via long invalid ISO 8601 timestamp
- debian/patches/CVE-2025-3360-1.patch: fix integer overflow when
parsing very long ISO8601 inputs in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-2.patch: fix potential integer overflow
in timezone offset handling in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-3.patch: track timezone length as an
unsigned size_t in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-4.patch: factor out some string pointer
arithmetic in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-5.patch: factor out an undersized
variable in glib/gdatetime.c.
- debian/patches/CVE-2025-3360-6.patch: add some missing GDateTime
ISO8601 parsing tests in glib/tests/gdatetime.c.
- CVE-2025-3360
* SECURITY UPDATE: integer overflow in temp file creation
- debian/patches/CVE-2025-7039.patch: fix computation of temporary file
name in glib/gfileutils.c.
- CVE-2025-7039
* SECURITY UPDATE: heap overflow in g_escape_uri_string()
- debian/patches/CVE-2025-13601.patch: add overflow check in
glib/gconvert.c.
- CVE-2025-13601
* SECURITY UPDATE: buffer underflow through glib/gvariant
- debian/patches/CVE-2025-14087-1.patch: fix potential integer overflow
parsing (byte)strings in glib/gvariant-parser.c.
- debian/patches/CVE-2025-14087-2.patch: use size_t to count numbers of
child elements in glib/gvariant-parser.c.
- debian/patches/CVE-2025-14087-3.patch: convert error handling code to
use size_t in glib/gvariant-parser.c.
- CVE-2025-14087
* SECURITY UPDATE: integer overflow in gfileattribute
- debian/patches/gfileattribute-overflow.patch: add overflow check in
gio/gfileattribute.c.
- No CVE number
-- Hlib Korzhynskyy Mon, 09 Feb 2026 13:07:47 -0330
libtasn1-6:amd64 (built from libtasn1-6) updated from 4.13-2 to 4.13-2ubuntu0.1~esm1:
libtasn1-6 (4.13-2ubuntu0.1~esm1) bionic-security; urgency=medium
* SECURITY UPDATE: Off-by-one error in asn1_encode_simple_der
- debian/patches/CVE-2021-46848.patch: Fix equality bound in lib/int.h
- CVE-2021-46848
* SECURITY UPDATE: Buffer overflow in asn1_expand_octet_string
- debian/patches/CVE-2025-13151.patch: Correct buffer size in
lib/decoding.c
- CVE-2025-13151
-- Kyle Kernick Thu, 05 Feb 2026 15:45:21 -0700
libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm7 to 1.1.1-1ubuntu2.1~18.04.23+esm8:
openssl (1.1.1-1ubuntu2.1~18.04.23+esm8) bionic-security; urgency=medium
* SECURITY UPDATE: NULL pointer dereference when processing an OCSP
response
- debian/patches/CVE-2026-28387.patch: dane_match_cert() should
X509_free() on ->mcert instead of OPENSSL_free() in
crypto/x509/x509_vfy.c.
- CVE-2026-28387
* SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL
- debian/patches/CVE-2026-28388-1.patch: fix NULL Dereference When
Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c.
- debian/patches/CVE-2026-28388-2.patch: Added test in test/*.
- CVE-2026-28388
* SECURITY UPDATE: Possible NULL dereference when processing CMS
KeyAgreeRecipientInfo
- debian/patches/CVE-2026-28389.patch: fix inadvertent NULL deref in
[ec]dh_cms_set_shared_info in crypto/dh/dh_ameth.c,
crypto/ec/ec_ameth.c.
- CVE-2026-28389
* SECURITY UPDATE: Possible NULL Dereference When Processing CMS
KeyTransportRecipientInfo
- debian/patches/CVE-2026-28390.patch: Fix NULL deref in
rsa_cms_decrypt in crypto/rsa/rsa_ameth.c.
- CVE-2026-28390
-- Hlib Korzhynskyy Wed, 01 Apr 2026 11:55:06 -0230
libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm3 to 1.0.2n-1ubuntu5.13+esm4:
openssl1.0 (1.0.2n-1ubuntu5.13+esm4) bionic-security; urgency=medium
* SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL
- debian/patches/CVE-2026-28388.patch: fix NULL Dereference When
Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c.
- CVE-2026-28388
* SECURITY UPDATE: Possible NULL dereference when processing CMS
KeyAgreeRecipientInfo
- debian/patches/CVE-2026-28389.patch: fix inadvertent NULL deref in
[ec]dh_cms_set_shared_info in crypto/dh/dh_ameth.c,
crypto/ec/ec_ameth.c.
- CVE-2026-28389
* SECURITY UPDATE: Possible NULL Dereference When Processing CMS
KeyTransportRecipientInfo
- debian/patches/CVE-2026-28390.patch: Fix NULL deref in
rsa_cms_decrypt in crypto/rsa/rsa_ameth.c.
- CVE-2026-28390
-- Hlib Korzhynskyy Wed, 08 Apr 2026 14:43:22 -0230
python3-jwt (built from pyjwt) updated from 1.5.3+ds1-1ubuntu0.1 to 1.5.3+ds1-1ubuntu0.1+esm1:
pyjwt (1.5.3+ds1-1ubuntu0.1+esm1) bionic-security; urgency=medium
* SECURITY UPDATE: Incorrect authorization of invalid JWS token.
- debian/patches/CVE-2026-32597.patch: Add _supported_crit and checks
for valid crit header in jwt/api_jws.py. Add tests in
tests/test_api_jws.py and tests/test_api_jwt.py.
- CVE-2026-32597
-- Hlib Korzhynskyy Thu, 26 Mar 2026 15:55:01 -0230
libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm7 to 3.6.9-1~18.04ubuntu1.13+esm9:
python3.6 (3.6.9-1~18.04ubuntu1.13+esm9) bionic-security; urgency=medium
* SECURITY REGRESSION: Revert patch for CVE-2025-15366
- debian/patches/CVE-2025-15366.patch: Reverted. Patch breaks RFC
9051 IMAP conformance and introduces behavior regressions avoided
by upstream.
- CVE-2025-15366
* SECURITY REGRESSION: Revert patch for CVE-2025-15367
- debian/patches/CVE-2025-15367.patch: Reverted to prevent behavior
regressions, aligning with upstream backporting decisions.
- CVE-2025-15367
* SECURITY REGRESSION: Allow HTAB in wsgiref header values
- debian/patches/CVE-2026-0865-2.patch: Permit HTAB in header values
(excluding names) in Lib/wsgiref/headers.py, add test coverage.
- CVE-2026-0865
-- Vyom Yadav Tue, 03 Mar 2026 16:40:39 +0530
python3.6 (3.6.9-1~18.04ubuntu1.13+esm8) bionic-security; urgency=medium
* SECURITY UPDATE: Header injection in email messages where addresses are not
sanitized.
- debian/patches/CVE-2025-11468.patch: Add escape parentheses and backslash
in Lib/email/_header_value_parser.py. Add test in
Lib/test/test_email/test__header_value_parser.py.
- CVE-2025-11468
* SECURITY UPDATE: Quadratic algorithm when building excessively nested XML
documents.
- debian/patches/CVE-2025-12084-*.patch: Remove _in_document and replace
with node.ownerDocument in Lib/xml/dom/minidom.py. Set self.ownerDocument
to None in Lib/xml/dom/minidom.py. Add test in Lib/test/test_minidom.py.
- CVE-2025-12084
* SECURITY UPDATE: OOM and denial of service when opening malicious plist
file.
- debian/patches/CVE-2025-13837.patch: Add _MIN_READ_BUF_SIZE and _read
with checks in Lib/plistlib.py. Add test in Lib/test/test_plistlib.py.
- CVE-2025-13837
* SECURITY UPDATE: Header injection in user controlled data URLs in urllib.
- debian/patches/CVE-2025-15282.patch: Add control character checks in
Lib/urllib/request.py. Add test in Lib/test/test_urllib.py.
* SECURITY UPDATE: Command injection through user controlled commands in
imaplib.
- debian/patches/CVE-2025-15366.patch: Add _control_chars and checks in
Lib/imaplib.py. Add test in Lib/test/test_imaplib.py.
* SECURITY UPDATE: Command injection through user controlled commands in
poplib.
- debian/patches/CVE-2025-15367.patch: Add control character regex check
in Lib/poplib.py. Add test in Lib/test/test_poplib.py.
- CVE-2025-15367
* SECURITY UPDATE: HTTP header injection in user controlled cookie values.
- debian/patches/CVE-2026-0672.patch: Add _control_characters_re and
checks in Lib/http/cookies.py. Add test in Lib/test/test_http_cookies.py.
- CVE-2026-0672
* SECURITY UPDATE: HTTP header injection in user controlled headers and
values with newlines.
- debian/patches/CVE-2026-0865.patch: Add _control_chars_re and check in
Lib/wsgiref/headers.py. Add test in Lib/test/support/__init__.py and
Lib/test/test_wsgiref.py.
- CVE-2026-0865
-- Hlib Korzhynskyy Fri, 30 Jan 2026 14:49:02 -0330
libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, udev (built from systemd) updated from 237-3ubuntu10.57+esm2 to 237-3ubuntu10.57+esm3:
systemd (237-3ubuntu10.57+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: Local root execution via malicious hardware devices
- d/p/udev-check-for-invalid-chars-in-various-fields-received-f.patch
- d/p/udev-fix-review-mixup.patch
- No CVE number
-- Nick Rosbrook Fri, 13 Mar 2026 15:06:23 -0400
vim-common, vim-tiny, xxd (built from vim) updated from 2:8.0.1453-1ubuntu1.13+esm13 to 2:8.0.1453-1ubuntu1.13+esm14:
vim (2:8.0.1453-1ubuntu1.13+esm14) bionic-security; urgency=medium
* SECURITY UPDATE: Buffer Overflow
- debian/patches/CVE-2026-26269.patch: Limit writing to max KEYBUFLEN
bytes to prevent writing out of bounds.
- debian/patches/CVE-2026-28420.patch: Use VTERM_MAX_CHARS_PER_CELL * 4
for ga_grow() to ensure sufficient space. Add a boundary check to the
character loop to prevent index out-of-bounds access.
- debian/patches/CVE-2026-28422.patch: Update the size check to account
for the byte length of the fill character (using MB_CHAR2LEN).
- debian/patches/CVE-2026-25749.patch: Limit strncpy to the length
of the buffer (MAXPATHL)
- CVE-2026-26269
- CVE-2026-28420
- CVE-2026-28422
- CVE-2026-25749
* SECURITY UPDATE: Command Injection
- debian/patches/CVE-2026-28417.patch: Implement stricter RFC1123
hostname and IP validation. Use shellescape() for the provided
hostname and port.
- CVE-2026-28417
* SECURITY UPDATE: Out of Bounds Read
- debian/patches/CVE-2026-28418.patch: Check for end of buffer
and return early.
- CVE-2026-28418
* SECURITY UPDATE: Buffer Underflow
- debian/patches/CVE-2026-28419.patch: Add a check to ensure the
delimiter (p_7f) is not at the start of the buffer (lbuf) before
attempting to isolate the tag name.
- CVE-2026-28419
* SECURITY UPDATE: Denial of Service
- debian/patches/CVE-2026-28421.patch: Add bounds checks on
pe_page_count and pe_bnum against mf_blocknr_max before descending
into the block tree, and validate pe_old_lnum >= 1 and
pe_line_count > 0 before calling readfile().
- CVE-2026-28421
-- Bruce Cable Wed, 11 Mar 2026 13:21:33 +1100
04/02/2026, commit https://git.launchpad.net/snap-core18/tree/07351192087830057d9ad8554c6807f0a7690077
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
libc-bin, libc6:amd64, libc6:i386, multiarch-support (built from glibc) updated from 2.27-3ubuntu1.6+esm5 to 2.27-3ubuntu1.6+esm6:
glibc (2.27-3ubuntu1.6+esm6) bionic-security; urgency=medium
* SECURITY UPDATE: use-after-free in wordexp_t fields
- debian/patches/CVE-2025-15281.patch: posix: Reset wordexp_t fields
with WRDE_REUSE
- CVE-2025-15281
* SECURITY UPDATE: double free in regcomp
- debian/patches/CVE-2025-8058.patch: posix: Fix double-free after
allocation failure in regcomp in posix/Makefile, posix/regcomp.c,
posix/tst-regcomp-bracket-free.c
- CVE-2025-8058
* SECURITY UPDATE: memory leak in NSS DNS
- debian/patches/CVE-2026-0915.patch: resolv: Fix NSS DNS backend for
getnetbyaddr
- CVE-2026-0915
-- Nishit Majithia Fri, 30 Jan 2026 13:33:29 +0530
gpgv (built from gnupg2) updated from 2.2.4-1ubuntu1.6+esm1 to 2.2.4-1ubuntu1.6+esm2:
gnupg2 (2.2.4-1ubuntu1.6+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: Remote Code Execution
- debian/patches/CVE-2025-68973.patch: gpg: Fix possible memory
corruption in the armor parser.
- CVE-2025-68973
-- Allen Huang Tue, 06 Jan 2026 11:28:10 +0000
libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm6 to 1.1.1-1ubuntu2.1~18.04.23+esm7:
openssl (1.1.1-1ubuntu2.1~18.04.23+esm7) bionic-security; urgency=medium
* SECURITY UPDATE: Heap out-of-bounds write in BIO_f_linebuffer on short
writes
- debian/patches/CVE-2025-68160.patch: fix heap buffer overflow in
BIO_f_linebuffer in crypto/bio/bf_lbuf.c.
- CVE-2025-68160
* SECURITY UPDATE: Unauthenticated/unencrypted trailing bytes with
low-level OCB function calls
- debian/patches/CVE-2025-69418.patch: fix OCB AES-NI/HW stream path
unauthenticated/unencrypted trailing bytes in crypto/modes/ocb128.c.
- CVE-2025-69418
* SECURITY UPDATE: Out of bounds write in PKCS12_get_friendlyname() UTF-8
conversion
- debian/patches/CVE-2025-69419.patch: check return code of UTF8_putc
in crypto/asn1/a_strex.c, crypto/pkcs12/p12_utl.c.
- CVE-2025-69419
* SECURITY UPDATE: Missing ASN1_TYPE validation in
TS_RESP_verify_response() function
- debian/patches/CVE-2025-69420.patch: verify ASN1 object's types
before attempting to access them as a particular type in
crypto/ts/ts_rsp_verify.c.
- CVE-2025-69420
* SECURITY UPDATE: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex
- debian/patches/CVE-2025-69421.patch: add NULL check in
crypto/pkcs12/p12_decr.c.
- CVE-2025-69421
* SECURITY UPDATE: ASN1_TYPE missing validation and type confusion
- debian/patches/CVE-2026-2279x.patch: ensure ASN1 types are checked
before use in apps/s_client.c, crypto/pkcs12/p12_kiss.c,
crypto/pkcs7/pk7_doit.c.
- CVE-2026-22795
- CVE-2026-22796
-- Hlib Korzhynskyy Wed, 14 Jan 2026 16:15:12 -0330
libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm2 to 1.0.2n-1ubuntu5.13+esm3:
openssl1.0 (1.0.2n-1ubuntu5.13+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: Heap out-of-bounds write in BIO_f_linebuffer on short
writes
- debian/patches/CVE-2025-68160.patch: fix heap buffer overflow in
BIO_f_linebuffer in crypto/bio/bf_lbuf.c.
- CVE-2025-68160
* SECURITY UPDATE: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex
- debian/patches/CVE-2025-69421.patch: add NULL check in
crypto/pkcs12/p12_decr.c.
- CVE-2025-69421
* SECURITY UPDATE: ASN1_TYPE missing validation and type confusion
- debian/patches/CVE-2026-2279x.patch: ensure ASN1 types are checked
before use in apps/s_client.c, crypto/pkcs12/p12_kiss.c,
crypto/pkcs7/pk7_doit.c.
- CVE-2026-22796
-- Hlib Korzhynskyy Wed, 14 Jan 2026 16:58:15 -0330
05/01/2026, commit https://git.launchpad.net/snap-core18/tree/07351192087830057d9ad8554c6807f0a7690077
[ Changes in the core18 snap ]
Philip Meulengracht (2):
static: add snapd.conf to tmpfiles.d from the snapd debian package
github: add build action (#199)
Valentin David (1):
tools/generate-changelog.py: work-around esm re-upload of distro-info-data (#200)
[ Changes in primed packages ]
distro-info-data (built from distro-info-data) updated from 0.37ubuntu0.18 to 0.37ubuntu0.20:
distro-info-data (0.37ubuntu0.20) bionic; urgency=medium
* Add Ubuntu 26.04 LTS "Resolute Raccoon" (LP: #2126961)
* Add release date for Debian 13 "Trixie"
* Update the Debian 12 "bookworm" EoL
-- Benjamin Drung Wed, 15 Oct 2025 20:50:31 +0200
distro-info-data (0.37ubuntu0.19) bionic; urgency=medium
* Add Ubuntu 25.04 "Plucky Puffin" (LP: #2084572)
* Add Ubuntu 25.10 "Questing Quokka" (LP: #2107391)
* Add Debian 15 "Duke"
-- Benjamin Drung Tue, 29 Apr 2025 11:54:42 +0200
gpgv (built from gnupg2) updated from 2.2.4-1ubuntu1.6 to 2.2.4-1ubuntu1.6+esm1:
gnupg2 (2.2.4-1ubuntu1.6+esm1) bionic-security; urgency=medium
* SECURITY UPDATE: verification DoS via crafted subkey data
- debian/patches/CVE-2025-30258-1.patch: lookup key for merging/
inserting only by primary key in g10/getkey.c, g10/import.c,
g10/keydb.h.
- debian/patches/CVE-2025-30258-2.patch: remove a signature check
function wrapper in g10/mainproc.c, g10/packet.h, g10/sig-check.c.
- debian/patches/CVE-2025-30258-3.patch: fix a verification DoS due to
a malicious subkey in the keyring in g10/getkey.c, g10/keydb.h,
g10/mainproc.c, g10/packet.h, g10/sig-check.c, g10/pkclist.c.
- debian/patches/CVE-2025-30258-4.patch: fix regression for the recent
malicious subkey DoS fix in g10/getkey.c, g10/packet.h.
- debian/patches/CVE-2025-30258-5.patch: fix double free of internal
data in g10/sig-check.c.
- CVE-2025-30258
* debian/patches/fix-key-validity-regression-due-to-CVE-2025-
30258.patch:
- Fix a key validity regression following patches for CVE-2025-30258,
causing trusted "certify-only" primary keys to be ignored when checking
signature on user IDs and computing key validity. This regression makes
imported keys signed by a trusted "certify-only" key have an unknown
validity
-- Nishit Majithia Thu, 04 Dec 2025 18:43:02 +0530
libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm6 to 3.6.9-1~18.04ubuntu1.13+esm7:
python3.6 (3.6.9-1~18.04ubuntu1.13+esm7) bionic-security; urgency=medium
* SECURITY UPDATE: Possible payload obfuscation
- debian/patches/CVE-2025-8291-pre1.patch: Add error raise in
Lib/zipfile.py and add tests.
- debian/patches/CVE-2025-8291.patch: check consistency of
the zip64 end of central dir record in Lib/zipfile.py,
Lib/test/test_zipfile.py.
- CVE-2025-8291
* SECURITY UPDATE: Performance degradation
- debian/patches/CVE-2025-6075.patch: fix quadratic complexity
in os.path.expandvars() in Lib/ntpatch.py, Lib/posixpath.py,
Lib/test/test_genericpatch.py, Lib/test/test_npath.py.
- CVE-2025-6075
-- Hlib Korzhynskyy Tue, 18 Nov 2025 09:44:54 -0330
29/10/2025, commit https://git.launchpad.net/snap-core18/tree/45ab8ed14d51d8030d477bf7776855d5ce54eaf5
[ Changes in the core18 snap ]
Alfonso Sánchez-Beato (1):
snapcraft.yaml: add assumes for snapd 2.62
[ Changes in primed packages ]
vim-common, vim-tiny, xxd (built from vim) updated from 2:8.0.1453-1ubuntu1.13+esm12 to 2:8.0.1453-1ubuntu1.13+esm13:
vim (2:8.0.1453-1ubuntu1.13+esm13) bionic-security; urgency=medium
* SECURITY UPDATE: Segmentation Fault
- debian/patches/CVE-2025-24014.patch: Add check that ScreenLines
is not NULL
- CVE-2025-24014
-- Bruce Cable Fri, 03 Oct 2025 08:59:18 +1000
01/10/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm5 to 1.1.1-1ubuntu2.1~18.04.23+esm6:
openssl (1.1.1-1ubuntu2.1~18.04.23+esm6) bionic-security; urgency=medium
* SECURITY UPDATE: Out of bounds read when decrypting password based CMS
messages.
- debian/patches/CVE-2025-9230.patch: Fix incorrect bound check for key
size in crypto/cms/cms_pwri.c
- CVE-2025-9230
-- Hlib Korzhynskyy Wed, 17 Sep 2025 11:35:41 -0230
libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm1 to 1.0.2n-1ubuntu5.13+esm2:
openssl1.0 (1.0.2n-1ubuntu5.13+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: Out of bounds read when decrypting password based CMS
messages.
- debian/patches/CVE-2025-9230.patch: Fix incorrect bound check for key
size in crypto/cms/cms_pwri.c
- CVE-2025-9230
-- Hlib Korzhynskyy Wed, 17 Sep 2025 14:20:14 -0230
10/09/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
libgnutls30:amd64 (built from gnutls28) updated from 3.5.18-1ubuntu1.6+esm1 to 3.5.18-1ubuntu1.6+esm2:
gnutls28 (3.5.18-1ubuntu1.6+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: double-free via otherName in the SAN
- debian/patches/CVE-2025-32988.patch: avoid double free when exporting
othernames in SAN in lib/x509/extensions.c.
- CVE-2025-32988
* SECURITY UPDATE: heap write overflow in certtool via invalid template
- debian/patches/CVE-2025-32990.patch: avoid 1-byte write buffer
overrun when parsing template in src/certtool-cfg.c,
tests/cert-tests/Makefile.am, tests/cert-tests/template-test.sh,
tests/cert-tests/templates/template-too-many-othernames.tmpl.
- CVE-2025-32990
-- Ian Constantin Mon, 08 Sep 2025 19:05:25 +0300
22/08/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm5 to 3.6.9-1~18.04ubuntu1.13+esm6:
python3.6 (3.6.9-1~18.04ubuntu1.13+esm6) bionic-security; urgency=medium
* SECURITY UPDATE: Regular expression denial of service.
- debian/patches/CVE-2025-6069.patch: Improve regex parsing in
Lib/html/parser.py.
- CVE-2025-6069
* SECURITY UPDATE: Infinite loop when parsing tar archives.
- debian/patches/CVE-2025-8194.patch: Raise exception when count < 0 in
Lib/tarfile.py.
- CVE-2025-8194
-- Hlib Korzhynskyy Tue, 19 Aug 2025 16:04:55 -0230
30/07/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
cloud-init (built from cloud-init) updated from 23.1.2-0ubuntu0~18.04.1 to 23.1.2-0ubuntu0~18.04.1+esm1:
cloud-init (23.1.2-0ubuntu0~18.04.1+esm1) bionic-security; urgency=medium
* d/cloud-init.postinst: move existing hotplug-cmd fifo to root-only
share dir (LP: #2114229) (CVE-2024-11584)
* cherry-pick 8c3ae1bb: fix: Don't attempt to identify non-x86 OpenStack
instances (LP: #2069607) (CVE-2024-6174)
* cherry-pick 8b45006c: fix: Make hotplug socket writable only by root
(LP: #2114229) (CVE-2024-11584)
* cherry-pick e3f42adc: fix: strict disable in ds-identify on no
datasources found (LP: #2069607) (CVE-2024-6174)
-- Chad Smith Wed, 25 Jun 2025 15:46:01 -0600
libsqlite3-0:amd64 (built from sqlite3) updated from 3.22.0-1ubuntu0.7+esm1 to 3.22.0-1ubuntu0.7+esm2:
sqlite3 (3.22.0-1ubuntu0.7+esm2) bionic-security; urgency=medium
[ Marc Deslauriers ]
* SECURITY UPDATE: Memory corruption via number of aggregate terms
- debian/patches/CVE-2025-6965.patch: raise an error right away if the
number of aggregate terms in a query exceeds the maximum number of
columns in src/expr.c, src/sqliteInt.h.
- CVE-2025-6965
* SECURITY UPDATE: DoS via sqlite3_db_config arguments
- debian/patches/CVE-2025-29088.patch: harden SQLITE_DBCONFIG_LOOKASIDE
interface against misuse in src/main.c, src/sqlite.h.in.
- CVE-2025-29088
-- Ian Constantin Mon, 28 Jul 2025 23:25:48 +0300
01/07/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b
[ Changes in the core18 snap ]
Philip Meulengracht (1):
tools: aggregate old changelogs
[ Changes in primed packages ]
python3-urllib3 (built from python-urllib3) updated from 1.22-1ubuntu0.18.04.2+esm2 to 1.22-1ubuntu0.18.04.2+esm3:
python-urllib3 (1.22-1ubuntu0.18.04.2+esm3) bionic-security; urgency=medium
* SECURITY UPDATE: Information disclosure through improperly disabled
redirects.
- debian/patches/CVE-2025-50181.patch: Add "retries" check and set retries
to Retry.from_int(retries, redirect=False) as well as set
raise_on_redirect in ./src/urllib3/poolmanager.py.
- CVE-2025-50181
-- Hlib Korzhynskyy Wed, 25 Jun 2025 10:22:54 -0230
sudo (built from sudo) updated from 1.8.21p2-3ubuntu1.6 to 1.8.21p2-3ubuntu1.6+esm1:
sudo (1.8.21p2-3ubuntu1.6+esm1) bionic-security; urgency=medium
* SECURITY UPDATE: Local Privilege Escalation via host option
- debian/patches/CVE-2025-32462.patch: only allow specifying a host
when listing privileges.
- CVE-2025-32462
-- Federico Quattrin Wed, 25 Jun 2025 17:14:55 -0300
16/06/2025, commit https://git.launchpad.net/snap-core18/tree/74bb5585b7c696c20e4e7ca7faff13d2be218d8b
[ Changes in the core18 snap ]
No detected changes for the core18 snap
[ Changes in primed packages ]
libc-bin, libc6:amd64, libc6:i386, multiarch-support (built from glibc) updated from 2.27-3ubuntu1.6+esm4 to 2.27-3ubuntu1.6+esm5:
glibc (2.27-3ubuntu1.6+esm5) bionic-security; urgency=medium
* SECURITY UPDATE: privelege escalation issue
- debian/patches/any/CVE-2025-4802.patch: elf: Ignore LD_LIBRARY_PATH
and debug env var for setuid for static
- CVE-2025-4802
-- Nishit Majithia Mon, 26 May 2025 13:48:50 +0530
libgssapi-krb5-2:amd64, libk5crypto3:amd64, libkrb5-3:amd64, libkrb5support0:amd64 (built from krb5) updated from 1.16-2ubuntu0.4+esm3 to 1.16-2ubuntu0.4+esm5:
krb5 (1.16-2ubuntu0.4+esm5) bionic-security; urgency=medium
* SECURITY UPDATE: Use of weak cryptographic hash.
- debian/patches/CVE-2025-3576*.patch: Add allow_des3 and allow_rc4 options.
Disallow usage of des3 and rc4 unless allowed in the config. Replace
warn_des3 with warn_deprecated in ./src/lib/krb5/krb/get_in_tkt.c. Add
allow_des3 and allow_rc4 boolean in ./src/include/k5-int.h. Prevent usage
of deprecated enctypes in ./src/kdc/kdc_util.c.
- debian/patches/CVE-2025-3576-post1.patch: Add enctype comparison with
ENCTYPE_AES256_CTS_HMAC_SHA1_96 in ./src/kdc/kdc_util.c.
- debian/libk5crypto3.symbols: Add krb5int_c_deprecated_enctype symbol.
- CVE-2025-3576
-- Hlib Korzhynskyy Tue, 20 May 2025 11:16:32 -0230
python3-pkg-resources (built from python-setuptools) updated from 39.0.1-2ubuntu0.1+esm1 to 39.0.1-2ubuntu0.1+esm2:
python-setuptools (39.0.1-2ubuntu0.1+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: path traversal vulnerability
- debian/patches/CVE-2025-47273-pre1.patch: Extract
_resolve_download_filename with test.
- debian/patches/CVE-2025-47273.patch: Add a check to ensure the name
resolves relative to the tmpdir.
- CVE-2025-47273
-- Fabian Toepfer Wed, 28 May 2025 19:37:50 +0200
libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm4 to 3.6.9-1~18.04ubuntu1.13+esm5:
python3.6 (3.6.9-1~18.04ubuntu1.13+esm5) bionic-security; urgency=medium
* SECURITY UPDATE: Improper encoding of comma during address list folding.
- debian/patches/CVE-2025-1795-1.patch: Replace ValueTerminal with
ListSeparator in ./Lib/email/_header_value_parser.py.
- debian/patches/CVE-2025-1795-2.patch: Add checks for terminal
non-encoding in ./Lib/email/_header_value_parser.py.
- CVE-2025-1795
* SECURITY UPDATE: Use after free in unicode_escape decoding.
- debian/patches/CVE-2025-4516-pre1.patch: Add DecodeUnicodeEscapeStateful
and replace DecodeUnicodeEscape with DecodeUnicodeEscapeInternal in
./Include/cpython/unicodeobject.h. Change IncrementalDecoder and add
decode to StreamReader in ./Lib/encodings/unicode_escape.py. Change
instance to DecodeUnicodeEscapeStateful in ./Modules/_codecsmodule.c.
Change checks in ./Modules/clinic/_codecsmodule.c.h and instances in
./Objects/unicodeobject.c and ./Parser/pegen/parse_string.c.
- debian/patches/CVE-2025-4516.patch: Add _PyBytes_DecodeEscape2 in
./Include/cpython/bytesobject.h. Add
_PyUnicode_DecodeUnicodeEscapeInternal2 in
./Include/cpython/unicodeobject.h. Add extra escape checks in
./Objects/bytesobject.c and ./Objects/unicodeobject.c.
- debian/libpython.symbols.in: Update symbols with new functions.
- CVE-2025-4516
-- Hlib Korzhynskyy Wed, 11 Jun 2025 09:40:51 -0230
python3-requests (built from requests) updated from 2.18.4-2ubuntu0.1+esm1 to 2.18.4-2ubuntu0.1+esm2:
requests (2.18.4-2ubuntu0.1+esm2) bionic-security; urgency=medium
* SECURITY UPDATE: Information Leak
- debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
lookup instead of netloc
- CVE-2024-47081
-- Bruce Cable Wed, 11 Jun 2025 13:27:28 +1000