/
snap
/
core18
/
3084
/
usr
/
share
/
doc
/
/snap/core18/3084/usr/share/doc
mkdir
upload
Name
Size
Mode
Actions
adduser/
-
0755
rm
apparmor/
-
0755
rm
base-files/
-
0755
rm
base-passwd/
-
0755
rm
bash/
-
0755
rm
bash-completion/
-
0755
rm
bsdutils/
-
0755
rm
bzip2/
-
0755
rm
ca-certificates/
-
0755
rm
cloud-guest-utils/
-
0755
rm
cloud-init/
-
0755
rm
console-conf/
-
0755
rm
coreutils/
-
0755
rm
dash/
-
0755
rm
dbus/
-
0755
rm
debianutils/
-
0755
rm
diffutils/
-
0755
rm
distro-info-data/
-
0755
rm
dmsetup/
-
0755
rm
dosfstools/
-
0755
rm
dpkg/
-
0755
rm
e2fsprogs/
-
0755
rm
fdisk/
-
0755
rm
finalrd/
-
0755
rm
findutils/
-
0755
rm
gcc-8-base/
-
0755
rm
gdbserver/
-
0755
rm
gpgv/
-
0755
rm
grep/
-
0755
rm
gzip/
-
0755
rm
hostname/
-
0755
rm
init-system-helpers/
-
0755
rm
iproute2/
-
0755
rm
iptables/
-
0755
rm
iputils-ping/
-
0755
rm
isc-dhcp-client/
-
0755
rm
kmod/
-
0755
rm
less/
-
0755
rm
libacl1/
-
0755
rm
libapparmor1/
-
0755
rm
libargon2-0/
-
0755
rm
libattr1/
-
0755
rm
libaudit-common/
-
0755
rm
libaudit1/
-
0755
rm
libblkid1/
-
0755
rm
libbsd0/
-
0755
rm
libbz2-1.0/
-
0755
rm
libc-bin/
-
0755
rm
libc6/
-
0755
rm
libcap-ng0/
-
0755
rm
libcap2/
-
0755
rm
libcom-err2/
-
0755
rm
libcryptsetup12/
-
0755
rm
libdb5.3/
-
0755
rm
libdbus-1-3/
-
0755
rm
libdebconfclient0/
-
0755
rm
libdevmapper1.02.1/
-
0755
rm
libdns-export1100/
-
0755
rm
libedit2/
-
0755
rm
libelf1/
-
0755
rm
libexpat1/
-
0755
rm
libext2fs/
-
0755
rm
libext2fs2/
-
0755
rm
libfdisk1/
-
0755
rm
libffi6/
-
0755
rm
libgcc1/
-
0755
rm
libgcrypt20/
-
0755
rm
libglib2.0-0/
-
0755
rm
libgmp10/
-
0755
rm
libgnutls30/
-
0755
rm
libgpg-error0/
-
0755
rm
libgssapi-krb5-2/
-
0755
rm
libhogweed4/
-
0755
rm
libidn2-0/
-
0755
rm
libidn11/
-
0755
rm
libip4tc0/
-
0755
rm
libip6tc0/
-
0755
rm
libiptc0/
-
0755
rm
libisc-export169/
-
0755
rm
libjson-c3/
-
0755
rm
libk5crypto3/
-
0755
rm
libkeyutils1/
-
0755
rm
libkmod2/
-
0755
rm
libkrb5-3/
-
0755
rm
libkrb5support0/
-
0755
rm
liblz4-1/
-
0755
rm
liblzma5/
-
0755
rm
liblzo2-2/
-
0755
rm
libmnl0/
-
0755
rm
libmount1/
-
0755
rm
libmpdec2/
-
0755
rm
libncurses5/
-
0755
rm
libncursesw5/
-
0755
rm
libnetfilter-conntrack3/
-
0755
rm
libnetplan0/
-
0755
rm
libnettle6/
-
0755
rm
libnfnetlink0/
-
0755
rm
libnl-3-200/
-
0755
rm
libnl-genl-3-200/
-
0755
rm
libnl-route-3-200/
-
0755
rm
libnss-extrausers/
-
0755
rm
libp11-kit0/
-
0755
rm
libpam-modules/
-
0755
rm
libpam-modules-bin/
-
0755
rm
libpam-runtime/
-
0755
rm
libpam-systemd/
-
0755
rm
libpam0g/
-
0755
rm
libpcre3/
-
0755
rm
libpcsclite1/
-
0755
rm
libprocps6/
-
0755
rm
libpython3-stdlib/
-
0755
rm
libpython3.6-minimal/
-
0755
rm
libpython3.6-stdlib/
-
0755
rm
libreadline7/
-
0755
rm
libseccomp2/
-
0755
rm
libselinux1/
-
0755
rm
libsemanage-common/
-
0755
rm
libsemanage1/
-
0755
rm
libsepol1/
-
0755
rm
libsmartcols1/
-
0755
rm
libsqlite3-0/
-
0755
rm
libss2/
-
0755
rm
libssl1.0.0/
-
0755
rm
libssl1.1/
-
0755
rm
libstdc++6/
-
0755
rm
libsystemd0/
-
0755
rm
libtasn1-6/
-
0755
rm
libtinfo5/
-
0755
rm
libudev1/
-
0755
rm
libunistring2/
-
0755
rm
libuuid1/
-
0755
rm
libwrap0/
-
0755
rm
libxtables12/
-
0755
rm
libyaml-0-2/
-
0755
rm
libzstd1/
-
0755
rm
login/
-
0755
rm
lsb-base/
-
0755
rm
mawk/
-
0755
rm
mime-support/
-
0755
rm
mount/
-
0755
rm
multiarch-support/
-
0755
rm
ncurses-base/
-
0755
rm
ncurses-bin/
-
0755
rm
netcat-openbsd/
-
0755
rm
netplan/
-
0755
rm
netplan.io/
-
0755
rm
openssh-client/
-
0755
rm
openssh-server/
-
0755
rm
openssh-sftp-server/
-
0755
rm
openssl/
-
0755
rm
passwd/
-
0755
rm
perl/
-
0755
rm
perl-base/
-
0755
rm
probert/
-
0755
rm
procps/
-
0755
rm
python3/
-
0755
rm
python3-all/
-
0755
rm
python3-asn1crypto/
-
0755
rm
python3-blinker/
-
0755
rm
python3-certifi/
-
0755
rm
python3-cffi-backend/
-
0755
rm
python3-chardet/
-
0755
rm
python3-configobj/
-
0755
rm
python3-cryptography/
-
0755
rm
python3-distutils/
-
0755
rm
python3-idna/
-
0755
rm
python3-jinja2/
-
0755
rm
python3-json-pointer/
-
0755
rm
python3-jsonpatch/
-
0755
rm
python3-jsonschema/
-
0755
rm
python3-jwt/
-
0755
rm
python3-lib2to3/
-
0755
rm
python3-markupsafe/
-
0755
rm
python3-minimal/
-
0755
rm
python3-netifaces/
-
0755
rm
python3-oauthlib/
-
0755
rm
python3-pkg-resources/
-
0755
rm
python3-pyudev/
-
0755
rm
python3-requests/
-
0755
rm
python3-requests-unixsocket/
-
0755
rm
python3-serial/
-
0755
rm
python3-six/
-
0755
rm
python3-urllib3/
-
0755
rm
python3-urwid/
-
0755
rm
python3-yaml/
-
0755
rm
python3.6/
-
0755
rm
python3.6-minimal/
-
0755
rm
readline-common/
-
0755
rm
rfkill/
-
0755
rm
sed/
-
0755
rm
sensible-utils/
-
0755
rm
squashfs-tools/
-
0755
rm
subiquitycore/
-
0755
rm
sudo/
-
0755
rm
systemd/
-
0755
rm
systemd-sysv/
-
0755
rm
sysvinit-utils/
-
0755
rm
tar/
-
0755
rm
tzdata/
-
0755
rm
ubuntu-keyring/
-
0755
rm
ucf/
-
0755
rm
udev/
-
0755
rm
util-linux/
-
0755
rm
vim-common/
-
0755
rm
vim-tiny/
-
0755
rm
wpasupplicant/
-
0755
rm
wpa_supplicant/
-
0755
rm
xxd/
-
0755
rm
zlib1g/
-
0755
rm
ChangeLog
67622
0644
edit
dl
rm
python3-debconf
-
0
edit
dl
rm
Edit:
/snap/core18/3084/usr/share/doc/ChangeLog
(67622B)
01/09/2026, commit https://git.launchpad.net/snap-core18/tree/ac77ccdf97b1bee988ee961e41efc2f5d06bd633 [ Changes in the core18 snap ] Mohit Chachada (1): README: document where to find changelog (#203) [ Changes in primed packages ] libattr1:amd64 (built from attr) updated from 1:2.4.47-2build1 to 1:2.4.47-2ubuntu0.18.04.1~esm1: attr (1:2.4.47-2ubuntu0.18.04.1~esm1) bionic-security; urgency=medium * SECURITY UPDATE: Symlink Traversal - d/p/CVE-2026-54371-01-add-visibility-attribute-header.patch: Add visibility attribute header in include/Makefile, include/visibility- hidden.h. - d/p/CVE-2026-54371-02-add-xattrat-syscall-wrappers.patch: Add xattrat syscall wrappers in configure.in, include/Makefile, include/xattrat.h, libmisc/Makefile, libmisc/xattrat.c, include/builddefs.in, include/config.h.in. - d/p/CVE-2026-54371-03-add-xattrat-syscall-backwards-compatibility- code.patch: Add xattrat syscall backwards compatibility code in include/Makefile, include/xattrat_compat.h, libmisc/Makefile, libmisc/getxattrat_compat.c, libmisc/listxattrat_compat.c, libmisc/proc- self-fd.c, libmisc/proc-self-fd.h, libmisc/removexattrat_compat.c, libmisc/setxattrat_compat.c, include/builddefs.in. - d/p/CVE-2026-54371-04-rename-walk_tree-to-old_walk_tree.patch: Rename walk_tree to old_walk_tree in include/Makefile, include/old_walk_tree.h, libmisc/Makefile, libmisc/old_walk_tree.c, getfattr/getfattr.c. - d/p/CVE-2026-54371-05-add-the-new-walk_tree-helper.patch: Add the new walk_tree helper in include/Makefile, include/walk_tree.h, libmisc/Makefile, libmisc/walk_tree.c. - debian/patches/CVE-2026-54371-06-harden-getfattr.patch: harden getfattr in man/man1/getfattr.1, getfattr/getfattr.c. - d/p/CVE-2026-54371-07-setfattr-multiple-restore-accesses-freed- buffer.patch: setfattr: multiple --restore accesses freed buffer in setfattr/setfattr.c. - d/p/CVE-2026-54371-08-setfattr-do-not-ignore-no-dereference-after- restore.patch: setfattr: Do not ignore --no-dereference after --restore in setfattr/setfattr.c. - d/p/CVE-2026-54371-09-add-openat2-syscall-wrapper.patch: Add openat2 syscall wrapper in configure.in, include/Makefile, include/openat2.h, libmisc/Makefile, libmisc/openat2.c, include/builddefs.in, include/config.h.in. - debian/patches/CVE-2026-54371-10-harden-setfattr-restore.patch: harden setfattr --restore in configure.in, man/man1/setfattr.1, test/Makefile, test/restore.test, setfattr/setfattr.c, include/builddefs.in, include/config.h.in. - CVE-2026-54371 -- John Breton <john.breton@canonical.com> Sun, 23 Aug 2026 21:48:18 -0400 libdns-export1100, libisc-export169:amd64 (built from bind9) updated from 1:9.11.3+dfsg-1ubuntu1.19+esm4 to 1:9.11.3+dfsg-1ubuntu1.19+esm5: bind9 (1:9.11.3+dfsg-1ubuntu1.19+esm5) bionic-security; urgency=medium * SECURITY UPDATE: BIND 9 server memory exhaustion during GSS-API TKEY negotiation - debian/patches/CVE-2026-3039-pre1.patch: Release gnamebuf also on the error path in lib/dns/gssapictx.c. - debian/patches/CVE-2026-3039-1.patch: Fix GSS-API context leak in TKEY negotiation by rejecting multi-round GSS-API negotiation in lib/dns/gssapictx.c, lib/dns/include/dst/gssapi.h, lib/dns/tkey.c. - debian/patches/CVE-2026-3039-3.patch: Fix output token and GSS context leaks in TKEY/GSS-API error paths in lib/dns/gssapictx.c, lib/dns/tkey.c. - CVE-2026-3039 * SECURITY UPDATE: Amplification vulnerabilities via self-pointed glue records - debian/patches/CVE-2026-3592-1.patch: Limit the number of addresses returned per ADB find in bin/named/main.c, lib/dns/adb.c. - debian/libdns1100.symbols: Add new exported symbol dns_adb_addrslimit. - debian/patches/CVE-2026-3592-2.patch: Remove duplicate addresses from the resolver SLIST by replacing sort-based selection with linear scan in nextaddress() in lib/dns/resolver.c. - debian/patches/CVE-2026-3592-3.patch: Add system test for self-pointed glue deduplication in bin/tests/system/selfpointedglue/. - debian/patches/CVE-2026-3592-5.patch: Add SRTT-based server selection system test in bin/tests/system/srtt/. - CVE-2026-3592 * SECURITY UPDATE: Invalid handling of CLASS != IN - debian/patches/CVE-2026-5946-1.patch: Disable recursion for non-IN classes in bin/named/server.c, lib/bind9/check.c. - debian/patches/CVE-2026-5946-2.patch: Disable UPDATE and NOTIFY for non-IN classes in bin/named/client.c, bin/named/server.c, bin/named/update.c, lib/dns/adb.c. - debian/patches/CVE-2026-5946-3.patch: Validate DNS message CLASS early in request processing in bin/named/client.c. - debian/patches/CVE-2026-5946-4.patch: Reject meta-classes in UPDATE and NOTIFY messages in lib/dns/message.c. - debian/patches/CVE-2026-5946-5.patch: Skip "deny-answer-address" for non-IN addresses in lib/dns/resolver.c. - debian/patches/CVE-2026-5946-7.patch: Remove redundant recursion setting for non-IN views in bin/named/server.c. - CVE-2026-5946 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Thu, 30 Jul 2026 07:22:41 -0300 bzip2, libbz2-1.0:amd64 (built from bzip2) updated from 1.0.6-8.1ubuntu0.2 to 1.0.6-8.1ubuntu0.2+esm1: bzip2 (1.0.6-8.1ubuntu0.2+esm1) bionic-security; urgency=medium * SECURITY UPDATE: out-of-bounds write - debian/patches/CVE-2026-42250.patch: bzip2recover: Make sure to not process more than BZ_MAX_HANDLED_BLOCKS in bzip2recover.c. - CVE-2026-42250 -- Shishir Subedi <shishir.subedi@canonical.com> Thu, 27 Aug 2026 09:53:56 +0545 diffutils (built from diffutils) updated from 1:3.6-1 to 1:3.6-1ubuntu0.1~esm1: diffutils (1:3.6-1ubuntu0.1~esm1) bionic-security; urgency=medium * SECURITY UPDATE: Integer Overflow - debian/patches/CVE-2026-53910-1.patch: diff3: check for integer overflows when reading line numbers from diff in NEWS, THANKS, src/diff3.c. - debian/patches/CVE-2026-53910-2.patch: diff3: prevent overflow in line offsets in src/diff3.c. - CVE-2026-53910 -- John Breton <john.breton@canonical.com> Wed, 26 Aug 2026 14:34:16 -0400 distro-info-data (built from distro-info-data) updated from 0.37ubuntu0.20 to 0.37ubuntu0.21: distro-info-data (0.37ubuntu0.21) bionic; urgency=medium * Add Ubuntu 26.10 "Stonking Stingray" (LP: #2150234) -- Oliver Reiche <oliver.reiche@canonical.com> Tue, 28 Apr 2026 16:36:47 +0200 libgnutls30:amd64 (built from gnutls28) updated from 3.5.18-1ubuntu1.6+esm2 to 3.5.18-1ubuntu1.6+esm4: gnutls28 (3.5.18-1ubuntu1.6+esm4) bionic-security; urgency=medium * SECURITY UPDATE: Name constraint bypass during certificate validation - debian/patches/CVE-2026-42011.patch: Fix intersecting empty constraints in lib/x509/name_constraints.c. - CVE-2026-42011 * SECURITY UPDATE: Certificate validation bypass via URI/SRV SAN CN fallback - debian/patches/CVE-2026-42012-pre1.patch: Refactor and simplify CN fallback logic in lib/x509/hostname-verify.c. - debian/patches/CVE-2026-42012-pre2.patch: Add bare-bones awareness of SRV virtual SAN in lib/includes/gnutls/gnutls.h.in, lib/x509/common.h, lib/x509/output.c, lib/x509/virt-san.c, lib/x509/x509.c. - debian/patches/CVE-2026-42012.patch: Make URI/SRV SAN preclude CN fallback in lib/x509/hostname-verify.c. - CVE-2026-42012 * SECURITY UPDATE: Certificate validation bypass via oversized SAN fallback - debian/patches/CVE-2026-42013-pre1.patch: Refactor DN fallback logic in lib/x509/email-verify.c. - debian/patches/CVE-2026-42013.patch: Prevent fallback on oversized SAN in lib/x509/email-verify.c, lib/x509/hostname-verify.c. - CVE-2026-42013 * SECURITY UPDATE: Memory corruption in PKCS#12 bag bounds check - debian/patches/CVE-2026-42015.patch: Fix off-by-one in bag element bounds check in lib/x509/pkcs12_bag.c. - CVE-2026-42015 -- Shafayat Hossain Majumder <shafayat.majumder@canonical.com> Fri, 10 Jul 2026 16:44:55 -0400 gnutls28 (3.5.18-1ubuntu1.6+esm3) bionic-security; urgency=medium * SECURITY UPDATE: Timing side channel during RSA-PSK decryption - debian/patches/CVE-2024-0553.patch: Eliminate post-decryption RSA-PSK branching in lib/auth/rsa_psk.c. - CVE-2024-0553 * SECURITY UPDATE: Resource exhaustion during name-constraint processing - debian/patches/CVE-2024-12243-pre1.patch: Add overflow-safe array reallocation in lib/mem.c and lib/mem.h. - debian/patches/CVE-2024-12243-pre2.patch: Add checked integer arithmetic in gl/intprops.h. - debian/patches/CVE-2024-12243.patch: Bound and optimize name-constraint processing in lib/datum.c, lib/x509/name_constraints.c, lib/x509/x509_ext.c, lib/x509/x509_ext_int.h, and lib/x509/x509_int.h. - CVE-2024-12243 * SECURITY UPDATE: Stack buffer overflow during PKCS#11 token initialization - debian/patches/CVE-2025-9820.patch: Bound PKCS#11 token labels in lib/pkcs11_write.c. - CVE-2025-9820 * SECURITY UPDATE: Resource exhaustion during name-constraint intersection - debian/patches/CVE-2025-14831-1.patch: Correct universal IP exclusions in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-2.patch: Propagate name-constraint test failures in tests/name-constraints-ip.c. - debian/patches/CVE-2025-14831-3.patch: Reject malformed domain constraints in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-4.patch: Add name-constraint node constructors in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-5.patch: Add rich name-constraint comparison in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-6.patch: Add sorted constraint views in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-7.patch: Implement name-constraint union in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-8.patch: Represent empty intersections as a bitmask in lib/x509/name_constraints.c. - debian/patches/CVE-2025-14831-9.patch: Intersect sorted name constraints in lib/x509/name_constraints.c. - CVE-2025-14831 * SECURITY UPDATE: Certificate bypass during name-constraint matching - debian/patches/CVE-2026-3833.patch: Compare constrained domain names case-insensitively in lib/x509/name_constraints.c. - CVE-2026-3833 * SECURITY UPDATE: Heap overread during PKCS#11-backed RSA decryption - debian/patches/CVE-2026-5260-1.patch: Validate RSA ciphertext modulus lengths in lib/auth/rsa_psk.c. - debian/patches/CVE-2026-5260-2.patch: Prevent short-ciphertext overreads in lib/pkcs11_privkey.c. - CVE-2026-5260 * SECURITY UPDATE: Heap buffer overflow during DTLS fragment reassembly - debian/patches/CVE-2026-33846-pre1.patch: Simplify DTLS receive-buffer access in lib/buffers.c. - debian/patches/CVE-2026-33846.patch: Validate DTLS fragment consistency and bounds in lib/buffers.c. - CVE-2026-33846 * SECURITY UPDATE: Denial of service during DTLS packet ordering - debian/patches/CVE-2026-42009-pre1.patch: Match DTLS fragments by sequence number in lib/buffers.c. - debian/patches/CVE-2026-42009-1.patch: Reject conflicting DTLS fragment sequence numbers in lib/buffers.c. - debian/patches/CVE-2026-42009-2.patch: Handle equal DTLS sequence numbers in lib/buffers.c. - CVE-2026-42009 -- Shafayat Hossain Majumder <shafayat.majumder@canonical.com> Tue, 30 Jun 2026 12:23:54 -0400 kmod, libkmod2:amd64 (built from kmod) updated from 24-1ubuntu3.5 to 24-1ubuntu3.5+esm1: kmod (24-1ubuntu3.5+esm1) bionic-security; urgency=medium * Disable loading of algif_aead module to mitigate CVE-2026-31431 (LP: #2150743) - debian/modprobe.d/disable-algif_aead.conf -- Eduardo Barretto <eduardo.barretto@canonical.com> Thu, 30 Apr 2026 14:55:55 +0200 libcap2:amd64 (built from libcap2) updated from 1:2.25-1.2ubuntu0.1~esm1 to 1:2.25-1.2ubuntu0.1~esm2: libcap2 (1:2.25-1.2ubuntu0.1~esm2) bionic-security; urgency=medium * SECURITY UPDATE: TOCTOU race condition in cap_set_file(). - debian/patches/CVE-2026-4878.patch: Locks onto the intended file in cap_set_file() in libcap/cap_file.c and progs/quicktest.sh - CVE-2026-4878 -- Kyle Kernick <kyle.kernick@canonical.com> Mon, 22 Jun 2026 11:40:03 -0600 libncurses5:amd64, libncursesw5:amd64, libtinfo5:amd64, ncurses-base, ncurses-bin (built from ncurses) updated from 6.1-1ubuntu1.18.04.1+esm2 to 6.1-1ubuntu1.18.04.1+esm3: ncurses (6.1-1ubuntu1.18.04.1+esm3) bionic-security; urgency=medium * SECURITY UPDATE: stack-based buffer overflow in infocmp - debian/patches/CVE-2025-69720.patch: clamp length to MAX_TERMINFO_LENGTH before copying into buf2 in analyze_string. - CVE-2025-69720 -- Paulo Flabiano Smorigo <pfsmorigo@canonical.com> Tue, 30 Jun 2026 21:25:34 +0000 libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm8 to 1.1.1-1ubuntu2.1~18.04.23+esm10: openssl (1.1.1-1ubuntu2.1~18.04.23+esm10) bionic-security; urgency=medium * SECURITY UPDATE: HollowByte Denial of Service issue (LP: #2161371) - debian/patches/lp2161371.patch: Grow the init_buf incrementally as we receive data in ssl/statem/statem.c, ssl/statem/statem_lib.c. - No CVE number * SECURITY UPDATE: crash or memory disclosure via SSL_select_next_proto - debian/patches/CVE-2024-5535.patch: validate provided client list in ssl/ssl_lib.c. - CVE-2024-5535 * SECURITY UPDATE: unbounded mem growth when processing TLSv1.3 sessions - debian/patches/CVE-2024-2511.patch: fix unconstrained session cache growth in TLSv1.3 in ssl/ssl_lib.c, ssl/ssl_sess.c, ssl/statem/statem_srvr.c. - CVE-2024-2511 * SECURITY UPDATE: Excessive Memory Use Buffering DTLS Records for a Future Epoch - debian/patches/CVE-2026-54874-1.patch: Avoid full read buffer allocation when buffering DTLS records in ssl/record/rec_layer_d1.c, ssl/record/record.h, ssl/record/ssl3_record.c. - debian/patches/CVE-2026-54874-2.patch: ssl/record: lower the DTLS unprocessed_rcds queue limit in ssl/record/rec_layer_d1.c, ssl/record/record_local.h, ssl/record/ssl3_record.c. - CVE-2026-54874 * SECURITY UPDATE: Heap Buffer Overflow in CMS Key Unwrapping - debian/patches/CVE-2026-63072-1.patch: Add test for CVE-2026-63072 in test/cmsapitest.c, test/recipes/80-test_cmsapi.t. - debian/patches/CVE-2026-63072-2.patch: Fix heap buffer overflow (8-byte OOB write) in AES-WRAP-PAD unwrap in crypto/cms/cms_kari.c. - CVE-2026-63072 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Mon, 17 Aug 2026 11:15:51 -0300 openssl (1.1.1-1ubuntu2.1~18.04.23+esm9) bionic-security; urgency=medium * SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing - debian/patches/CVE-2026-34180.patch: Avoid length truncation in ASN1_STRING_set in crypto/asn1/tasn_dec.c. - CVE-2026-34180 * SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages - debian/patches/CVE-2026-34182-pre1.patch: Ensure ossl_cms_EncryptedContent_init_bio() reports an error on no OID in crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt, include/openssl/cmserr.h. - CVE-2026-34182 * SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption - debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c. - CVE-2026-42766 * SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify() - debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c. - debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c. - debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty- digest-set.eml. - CVE-2026-45447 * SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion - debian/patches/CVE-2026-7383.patch: Reject oversized inputs in ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c. - CVE-2026-7383 * SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption - debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds read in check-byte validation in crypto/cms/cms_pwri.c. - CVE-2026-9076 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Fri, 05 Jun 2026 09:36:42 -0300 libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm4 to 1.0.2n-1ubuntu5.13+esm6: openssl1.0 (1.0.2n-1ubuntu5.13+esm6) bionic-security; urgency=medium * SECURITY UPDATE: HollowByte Denial of Service issue (LP: #2161371) - debian/patches/lp2161371.patch: Grow the init_buf incrementally as we receive data in ssl/s3_both.c. - No CVE number * SECURITY UPDATE: crash or memory disclosure via SSL_select_next_proto - debian/patches/CVE-2024-5535.patch: validate provided client list in ssl/ssl_lib.c. - CVE-2024-5535 * SECURITY UPDATE: Excessive Memory Use Buffering DTLS Records for a Future Epoch - debian/patches/CVE-2026-54874-1.patch: Avoid full read buffer allocation when buffering DTLS records in ssl/d1_pkt.c, ssl/d1_lib.c, ssl/dtls1.h. - debian/patches/CVE-2026-54874-2.patch: ssl/record: lower the DTLS unprocessed_rcds queue limit in ssl/d1_pkt.c. - CVE-2026-54874 * SECURITY UPDATE: Heap Buffer Overflow in CMS Key Unwrapping - debian/patches/CVE-2026-63072-2.patch: Fix heap buffer overflow (8-byte OOB write) in AES-WRAP-PAD unwrap in crypto/cms/cms_kari.c. - CVE-2026-63072 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Thu, 20 Aug 2026 12:47:48 -0300 openssl1.0 (1.0.2n-1ubuntu5.13+esm5) bionic-security; urgency=medium * SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing - debian/patches/CVE-2026-34180.patch: Avoid length truncation in ASN1_STRING_set in crypto/asn1/tasn_dec.c. - CVE-2026-34180 * SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages - debian/patches/CVE-2026-34182-pre1.patch: Ensure ossl_cms_EncryptedContent_init_bio() reports an error on no OID in crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt, include/openssl/cmserr.h. - CVE-2026-34182 * SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption - debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c. - CVE-2026-42766 * SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify() - debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c. - debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c. - debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty- digest-set.eml. - CVE-2026-45447 * SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion - debian/patches/CVE-2026-7383.patch: Reject oversized inputs in ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c. - CVE-2026-7383 * SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption - debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds read in check-byte validation in crypto/cms/cms_pwri.c. - CVE-2026-9076 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Fri, 05 Jun 2026 12:50:04 -0300 libp11-kit0:amd64 (built from p11-kit) updated from 0.23.9-2ubuntu0.1 to 0.23.9-2ubuntu0.1+esm1: p11-kit (0.23.9-2ubuntu0.1+esm1) bionic-security; urgency=medium * SECURITY UPDATE: integer overflow in nested attribute decoding - debian/patches/CVE-2026-18938.patch: guard against overflow when decoding nested attributes (32-bit only, heap OOB write, DoS). - CVE-2026-18938 * SECURITY UPDATE: unbounded recursion in RPC attribute parsing - debian/patches/CVE-2026-13757.patch: add recursion depth limit into RPC attribute parsing (stack exhaustion, DoS). - CVE-2026-13757 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Tue, 25 Aug 2026 07:28:42 -0300 libpam-modules-bin, libpam-modules:amd64, libpam-runtime, libpam0g:amd64 (built from pam) updated from 1.1.8-3.6ubuntu2.18.04.6+esm1 to 1.1.8-3.6ubuntu2.18.04.6+esm2: pam (1.1.8-3.6ubuntu2.18.04.6+esm2) bionic-security; urgency=medium * SECURITY UPDATE: account lockout bypass in pam_faillock account management phase (LP: #2164901) - debian/patches-applied/lp-2164901.patch: skip clearing user's failed attempt in modules/pam_faillock/pam_faillock.c. - No CVE number -- Shafayat Hossain Majumder <shafayat.majumder@canonical.com> Wed, 26 Aug 2026 15:37:28 -0400 perl-base (built from perl) updated from 5.26.1-6ubuntu0.7 to 5.26.1-6ubuntu0.7+esm3: perl (5.26.1-6ubuntu0.7+esm3) bionic-security; urgency=high * SECURITY UPDATE: Out-of-bounds heap read in Socket pack_ip_mreq_source - debian/patches/CVE-2026-12087.patch: Scope STRLEN len per argument in pack_ip_mreq_source in cpan/Socket/Socket.xs - CVE-2026-12087 * SECURITY UPDATE: Trie 16-bit overflow causing incorrect regex matches - debian/patches/CVE-2026-13221.patch: Skip trie creation when branch delta would overflow 16 bits in regcomp.c, t/re/pat_advanced.t - CVE-2026-13221 * SECURITY UPDATE: Integer overflow leading to heap OOB read in pack/unpack - debian/patches/CVE-2026-57432_1.patch: Reject pack/unpack template sizes that would overflow SSize_t in pp_pack.c - debian/patches/CVE-2026-57432_2.patch: Avoid bit-count overflows in B/H template size math in pp_pack.c - CVE-2026-57432 * SECURITY UPDATE: Signed int overflow in Storable SX_HOOK deserialization - debian/patches/CVE-2026-57433.patch: Reject I32_MAX hook data item counts before av_extend in dist/Storable/Storable.xs - CVE-2026-57433 -- Shafayat Hossain Majumder <shafayat.majumder@canonical.com> Tue, 18 Aug 2026 17:25:19 -0400 perl (5.26.1-6ubuntu0.7+esm2) bionic-security; urgency=high * SECURITY UPDATE: integer overflow in regular expression compiler - debian/patches/CVE-2026-8376_1.patch: accept quantifier limit error on 32-bit architectures where the quantifier limit catches the oversized pattern before the overflow guard - CVE-2026-8376 -- Chrisa Oikonomou <chrisa.oikonomou@canonical.com> Mon, 23 Jun 2026 11:11:00 +0300 perl (5.26.1-6ubuntu0.7+esm1) bionic-security; urgency=high * SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction - debian/patches/CVE-2026-42496.patch: validate symlink and hardlink targets against absolute paths and directory traversal in cpan/Archive-Tar/lib/Archive/Tar.pm - CVE-2026-42496 * SECURITY UPDATE: integer overflow in regular expression compiler - debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer overflow via quantified fixed-string regex in t/re/pat_psycho.t - debian/patches/CVE-2026-8376_2.patch: add overflow check before fixed-string buffer allocation in regcomp.c / regcomp_study.c - CVE-2026-8376 -- Chrisa Oikonomou <chrisa.oikonomou@canonical.com> Fri, 12 Jun 2026 16:42:32 +0300 python3-cryptography (built from python-cryptography) updated from 2.1.4-1ubuntu1.4+esm1 to 2.1.4-1ubuntu1.4+esm3: python-cryptography (2.1.4-1ubuntu1.4+esm3) bionic-security; urgency=medium * SECURITY UPDATE: Subgroup Attack due to Missing Subgroup Validation for SECT Curves - debian/patches/CVE-2026-26007.patch: EC check key on cofactor > 1 in src/cryptography/hazmat/primitives/asymmetric/ec.py, src/cryptography/utils.py, tests/hazmat/primitives/test_ec.py, src/_cffi_src/openssl/ec.py, src/cryptography/hazmat/backends/openssl/ec.py. - CVE-2026-26007 -- Sudhakar Verma <sudhakar.verma@canonical.com> Mon, 20 Apr 2026 21:38:35 +0530 sed (built from sed) updated from 4.4-2 to 4.4-2ubuntu0.1~esm1: sed (4.4-2ubuntu0.1~esm1) bionic-security; urgency=medium * SECURITY UPDATE: TOCTOU race in sed -i --follow-symlinks - debian/patches/CVE-2026-5958.patch: open the already-resolved path instead of re-traversing the symlink in sed/execute.c. - CVE-2026-5958 -- Kyle Kernick <kyle.kernick@canonical.com> Wed, 27 May 2026 09:38:00 -0600 tar (built from tar) updated from 1.29b-2ubuntu0.4+esm1 to 1.29b-2ubuntu0.4+esm4: tar (1.29b-2ubuntu0.4+esm4) bionic-security; urgency=medium * SECURITY REGRESSION: Old archives with nonzero directory sizes failing to be extracted - debian/patches/CVE-2026-5704-5.patch: fix this by forcing the size to zero for DIRTYPE in read_header() in src/list.c (LP: #2161311). -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Mon, 20 Jul 2026 13:21:24 -0300 tar (1.29b-2ubuntu0.4+esm3) bionic-security; urgency=medium * SECURITY REGRESSION: Extract files issue - debian/patches/CVE-2026-5704-*.patch: address a regression that makes valid files not extract in src/list.c, tests/Makefile.am, tests/extrac32.at, tests/extrac34.at, test/testsuite.at, src/extract.c, tests/extract23, tests/extrac30.at (LP: #2160650). -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Wed, 15 Jul 2026 14:47:55 -0300 tar (1.29b-2ubuntu0.4+esm2) bionic-security; urgency=medium * SECURITY UPDATE: file injection via crafted archive - debian/patches/CVE-2026-5704.patch: always call skip_member() after extraction in extract_archive(), remove conditional skip_member() from purge_directory(), skip directory data in skim_member(), and stop forcing LNKTYPE size to zero in read_header(). - CVE-2026-5704 -- Leonidas Da Silva Barbosa <leo.barbosa@canonical.com> Tue, 23 Jun 2026 11:48:07 -0300 tzdata (built from tzdata) updated from 2025b-0ubuntu0.18.04+esm1 to 2026c-0ubuntu0.18.04+esm1: tzdata (2026c-0ubuntu0.18.04+esm1) bionic-security; urgency=medium * New upstream release (LP: #2161092): - Alberta moved to permanent -06 on 2026-06-18, so it will not fall back from -06 to -07 on 2026-11-01. - Morocco moves to permanent +00 on 2026-09-20. * Add autopkgtest test case for 2026c release -- Benjamin Drung <bdrung@ubuntu.com> Fri, 17 Jul 2026 15:10:52 +0200 tzdata (2026b-0ubuntu0.18.04+esm1) bionic-security; urgency=medium * New upstream release (LP: #2157973): - British Columbia moved to permanent -07 on 2026-03-09, so it will not fall back from -07 to -08 on 2026-11-01. * Add autopkgtest test case for 2026b release -- Benjamin Drung <bdrung@ubuntu.com> Wed, 24 Jun 2026 13:46:50 +0200 tzdata (2026a-0ubuntu0.18.04+esm1) bionic-security; urgency=medium * New upstream release (LP: #2143355): - No leap second on 2026-06-30 - Moldova has used EU transition times since 2022 * Add autopkgtest test case for 2025c and 2026a release -- Nadzeya Hutsko <nadzeya.hutsko@canonical.com> Thu, 11 Jun 2026 17:36:34 +0200 vim-common, vim-tiny, xxd (built from vim) updated from 2:8.0.1453-1ubuntu1.13+esm14 to 2:8.0.1453-1ubuntu1.13+esm24: vim (2:8.0.1453-1ubuntu1.13+esm24) bionic-security; urgency=medium * SECURITY UPDATE: Arbitrary command execution during C omni-completion. - debian/patches/CVE-2026-73073.patch: Match tags typeref literally in runtime/autoload/ccomplete.vim. - CVE-2026-73073 -- Kyle Kernick <kyle.kernick@canonical.com> Mon, 24 Aug 2026 16:14:11 -0600 vim (2:8.0.1453-1ubuntu1.13+esm23) bionic-security; urgency=medium * SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785) - debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in runtime/autoload/netrw.vim - debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname in runtime/autoload/netrw.vim * SECURITY UPDATE: Heap buffer overflow in set_sofo(). - debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in src/spellfile.c. - CVE-2026-73072 * SECURITY UPDATE: Code execution via VimballRecord file. - debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix broken directory deletion code, and refactor code in runtime/autoload/vimball.vim - CVE-2026-73076 * SECURITY UPDATE: Code injection in netrw via bookmarks. - debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in runtime/autoload/netrw.vim. - CVE-2026-73078 -- Kyle Kernick <kyle.kernick@canonical.com> Tue, 18 Aug 2026 17:27:10 -0600 vim (2:8.0.1453-1ubuntu1.13+esm22) bionic-security; urgency=medium * SECURITY UPDATE: Stack out-of-bounds write in spell_soundfold_sal(). - debian/patches/CVE-2026-59857.patch: Bound the single-byte SAL result writes in src/spell.c - CVE-2026-59857 * SECURITY UPDATE: Arbitrary command execution during C omni-completion. - debian/patches/CVE-2026-59858.patch: Escape the type field before inserting it into pattern in runtime/autoload/ccomplete.vim - CVE-2026-59858 -- Kyle Kernick <kyle.kernick@canonical.com> Mon, 13 Jul 2026 13:11:05 -0600 vim (2:8.0.1453-1ubuntu1.13+esm21) bionic-security; urgency=medium * SECURITY UPDATE: Path Traversal in zip.vim - debian/patches/CVE-2026-35177.patch: Detect malicious zip files before writing in runtime/autoload/zip.vim - CVE-2026-35177 * SECURITY UPDATE: Out-of-bounds write. - debian/patches/CVE-2026-55693.patch: only descend while depth < MAXWLEN - 1 in src/spellfile.c. - debian/patches/CVE-2026-55892.patch: only descend while depth < MAXWLEN - 1 in src/spell.c. - CVE-2026-55693 - CVE-2026-55892 * SECURITY UPDATE: Code injection in local file deletion. - debian/patches/CVE-2026-55895.patch: Use fnameescape() to escape file name in runtime/autoload/netrw.vim. - CVE-2026-55895 * SECURITY UPDATE: Out-of-bounds write with soundfold(). - debian/patches/CVE-2026-57455.patch: Add an abort condition to validate buffer in src/spell.c. - CVE-2026-57455 * SECURITY UPDATE: Code execution with python complete. - debian/patches/CVE-2026-57456.patch: Use repr() to quote the doc strings in runtime/autoload/python3complete.vim and ../pythoncomplete.vim. - CVE-2026-57456 -- Kyle Kernick <kyle.kernick@canonical.com> Tue, 30 Jun 2026 13:53:59 -0600 vim (2:8.0.1453-1ubuntu1.13+esm20) bionic-security; urgency=medium * SECURITY UPDATE: Code injection via NetrwBookHistSave(). - debian/patches/CVE-2026-47162.patch: Properly quote the directory name in runtime/autoload/netrw.vim. - CVE-2026-47162 * SECURITY UPDATE: Code Injection in cucumber filetype plugin. - debian/patches/CVE-2026-47167.patch: Use rubys Regexp.new() in runtime/ftplugin/cucumber.vim. - CVE-2026-47167 * SECURITY UPDATE: Code execution with python3complete. - debian/patches/CVE-2026-52858.patch: Disable execution of import/from statements in runtime/autoload/python3complete.vim and ../pythoncomplete.vim - debian/patches/CVE-2026-52860.patch: Strip default expressions and annotations in runtime/autoload/python3complete.vim and ../pythoncomplete.vim - CVE-2026-52858 - CVE-2026-52860 * SECURITY UPDATE: Out-of-bounds read in update_snapshot(). - debian/patches/CVE-2026-52859.patch: Bound loop in update_snapshot() in src/terminal.c. - CVE-2026-52859 -- Kyle Kernick <kyle.kernick@canonical.com> Mon, 15 Jun 2026 16:22:28 -0600 vim (2:8.0.1453-1ubuntu1.13+esm19) bionic-security; urgency=medium * SECURITY UPDATE: Command injection in tar plugin. - debian/patches/CVE-2026-46483.patch: Use the correct shell-escape in runtime/autoload/tar.vim. - CVE-2026-46483 * SECURITY UPDATE: Code injection via mf command. - debian/patches/CVE-2026-43961.patch: Avoid string concatenation for filter commands in runtime/autoload/netrw.vim. - CVE-2026-43961 -- Kyle Kernick <kyle.kernick@canonical.com> Wed, 03 Jun 2026 13:20:01 -0600 vim (2:8.0.1453-1ubuntu1.13+esm18) bionic-security; urgency=medium * SECURITY UPDATE: Command injection via backtick expansion in tag files - debian/patches/CVE-2026-41411.patch: Disallow backticks before attempting to expand filenames - CVE-2026-41411 -- Kyle Kernick <kyle.kernick@canonical.com> Mon, 25 May 2026 16:48:55 -0600 vim (2:8.0.1453-1ubuntu1.13+esm17) bionic-security; urgency=medium * SECURITY UPDATE: Command injection in netrw plugin. - debian/patches/CVE-2026-42307.patch: Escape file names and harden regex patterns in runtime/autoload/netrw.vim - CVE-2026-42307 * SECURITY UPDATE: Shell execution in completion. - debian/patches/CVE-2026-44656.patch: Skip path entries containing backticks and add P_SECURE option in src/misc1.c and src/option.c - CVE-2026-44656 * SECURITY UPDATE: Heap overflow in spellfile. - debian/patches/CVE-2026-45130.patch: Enforce a maximum compound length in src/spellfile.c - CVE-2026-45130 -- Kyle Kernick <kyle.kernick@canonical.com> Wed, 20 May 2026 15:32:07 -0600 vim (2:8.0.1453-1ubuntu1.13+esm16) bionic-security; urgency=medium * SECURITY UPDATE: Command Injection in netbeans - debian/patches/CVE-2026-39881.patch: Validate typename, fg, and bg before passing to coloncmd in src/netbeans.c - CVE-2026-39881 -- Kyle Kernick <kyle.kernick@canonical.com> Wed, 22 Apr 2026 12:32:59 -0600 liblzma5:amd64 (built from xz-utils) updated from 5.2.2-1.3ubuntu0.1 to 5.2.2-1.3ubuntu0.1+esm1: xz-utils (5.2.2-1.3ubuntu0.1+esm1) bionic-security; urgency=medium * SECURITY UPDATE: heap buffer overflow - debian/patches/CVE-2026-34743.patch: adds a check to lzma_index_prealloc() to default to a safe size when decoding empty indexes in src/liblzma/common/index.c. - CVE-2026-34743 -- Ian Constantin <ian.constantin@canonical.com> Thu, 28 May 2026 19:06:23 +0300 10/04/2026, commit https://git.launchpad.net/snap-core18/tree/07351192087830057d9ad8554c6807f0a7690077 [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] libexpat1:amd64 (built from expat) updated from 2.2.5-3ubuntu0.9+esm2 to 2.2.5-3ubuntu0.9+esm3: expat (2.2.5-3ubuntu0.9+esm3) bionic-security; urgency=medium * SECURITY UPDATE: NULL pointer dereference - debian/patches/CVE-2026-24515.patch: updates XML_ExternalEntityParserCreate to copy unknown encoding handler user data in expat/lib/xmlparse.c. - CVE-2026-24515 * SECURITY UPDATE: integer overflow - debian/patches/CVE-2026-25210*.patch: adds an integer overflow check for tag buffer reallocation in the doContent function of expat/lib/xmlparse.c. - CVE-2026-25210 -- Ian Constantin <ian.constantin@canonical.com> Wed, 04 Feb 2026 17:24:02 +0200 libglib2.0-0:amd64 (built from glib2.0) updated from 2.56.4-0ubuntu0.18.04.9+esm4 to 2.56.4-0ubuntu0.18.04.9+esm5: glib2.0 (2.56.4-0ubuntu0.18.04.9+esm5) bionic-security; urgency=medium * SECURITY UPDATE: overflow via long invalid ISO 8601 timestamp - debian/patches/CVE-2025-3360-1.patch: fix integer overflow when parsing very long ISO8601 inputs in glib/gdatetime.c. - debian/patches/CVE-2025-3360-2.patch: fix potential integer overflow in timezone offset handling in glib/gdatetime.c. - debian/patches/CVE-2025-3360-3.patch: track timezone length as an unsigned size_t in glib/gdatetime.c. - debian/patches/CVE-2025-3360-4.patch: factor out some string pointer arithmetic in glib/gdatetime.c. - debian/patches/CVE-2025-3360-5.patch: factor out an undersized variable in glib/gdatetime.c. - debian/patches/CVE-2025-3360-6.patch: add some missing GDateTime ISO8601 parsing tests in glib/tests/gdatetime.c. - CVE-2025-3360 * SECURITY UPDATE: integer overflow in temp file creation - debian/patches/CVE-2025-7039.patch: fix computation of temporary file name in glib/gfileutils.c. - CVE-2025-7039 * SECURITY UPDATE: heap overflow in g_escape_uri_string() - debian/patches/CVE-2025-13601.patch: add overflow check in glib/gconvert.c. - CVE-2025-13601 * SECURITY UPDATE: buffer underflow through glib/gvariant - debian/patches/CVE-2025-14087-1.patch: fix potential integer overflow parsing (byte)strings in glib/gvariant-parser.c. - debian/patches/CVE-2025-14087-2.patch: use size_t to count numbers of child elements in glib/gvariant-parser.c. - debian/patches/CVE-2025-14087-3.patch: convert error handling code to use size_t in glib/gvariant-parser.c. - CVE-2025-14087 * SECURITY UPDATE: integer overflow in gfileattribute - debian/patches/gfileattribute-overflow.patch: add overflow check in gio/gfileattribute.c. - No CVE number -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Mon, 09 Feb 2026 13:07:47 -0330 libtasn1-6:amd64 (built from libtasn1-6) updated from 4.13-2 to 4.13-2ubuntu0.1~esm1: libtasn1-6 (4.13-2ubuntu0.1~esm1) bionic-security; urgency=medium * SECURITY UPDATE: Off-by-one error in asn1_encode_simple_der - debian/patches/CVE-2021-46848.patch: Fix equality bound in lib/int.h - CVE-2021-46848 * SECURITY UPDATE: Buffer overflow in asn1_expand_octet_string - debian/patches/CVE-2025-13151.patch: Correct buffer size in lib/decoding.c - CVE-2025-13151 -- Kyle Kernick <kyle.kernick@canonical.com> Thu, 05 Feb 2026 15:45:21 -0700 libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm7 to 1.1.1-1ubuntu2.1~18.04.23+esm8: openssl (1.1.1-1ubuntu2.1~18.04.23+esm8) bionic-security; urgency=medium * SECURITY UPDATE: NULL pointer dereference when processing an OCSP response - debian/patches/CVE-2026-28387.patch: dane_match_cert() should X509_free() on ->mcert instead of OPENSSL_free() in crypto/x509/x509_vfy.c. - CVE-2026-28387 * SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL - debian/patches/CVE-2026-28388-1.patch: fix NULL Dereference When Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c. - debian/patches/CVE-2026-28388-2.patch: Added test in test/*. - CVE-2026-28388 * SECURITY UPDATE: Possible NULL dereference when processing CMS KeyAgreeRecipientInfo - debian/patches/CVE-2026-28389.patch: fix inadvertent NULL deref in [ec]dh_cms_set_shared_info in crypto/dh/dh_ameth.c, crypto/ec/ec_ameth.c. - CVE-2026-28389 * SECURITY UPDATE: Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo - debian/patches/CVE-2026-28390.patch: Fix NULL deref in rsa_cms_decrypt in crypto/rsa/rsa_ameth.c. - CVE-2026-28390 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 01 Apr 2026 11:55:06 -0230 libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm3 to 1.0.2n-1ubuntu5.13+esm4: openssl1.0 (1.0.2n-1ubuntu5.13+esm4) bionic-security; urgency=medium * SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL - debian/patches/CVE-2026-28388.patch: fix NULL Dereference When Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c. - CVE-2026-28388 * SECURITY UPDATE: Possible NULL dereference when processing CMS KeyAgreeRecipientInfo - debian/patches/CVE-2026-28389.patch: fix inadvertent NULL deref in [ec]dh_cms_set_shared_info in crypto/dh/dh_ameth.c, crypto/ec/ec_ameth.c. - CVE-2026-28389 * SECURITY UPDATE: Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo - debian/patches/CVE-2026-28390.patch: Fix NULL deref in rsa_cms_decrypt in crypto/rsa/rsa_ameth.c. - CVE-2026-28390 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 08 Apr 2026 14:43:22 -0230 python3-jwt (built from pyjwt) updated from 1.5.3+ds1-1ubuntu0.1 to 1.5.3+ds1-1ubuntu0.1+esm1: pyjwt (1.5.3+ds1-1ubuntu0.1+esm1) bionic-security; urgency=medium * SECURITY UPDATE: Incorrect authorization of invalid JWS token. - debian/patches/CVE-2026-32597.patch: Add _supported_crit and checks for valid crit header in jwt/api_jws.py. Add tests in tests/test_api_jws.py and tests/test_api_jwt.py. - CVE-2026-32597 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Thu, 26 Mar 2026 15:55:01 -0230 libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm7 to 3.6.9-1~18.04ubuntu1.13+esm9: python3.6 (3.6.9-1~18.04ubuntu1.13+esm9) bionic-security; urgency=medium * SECURITY REGRESSION: Revert patch for CVE-2025-15366 - debian/patches/CVE-2025-15366.patch: Reverted. Patch breaks RFC 9051 IMAP conformance and introduces behavior regressions avoided by upstream. - CVE-2025-15366 * SECURITY REGRESSION: Revert patch for CVE-2025-15367 - debian/patches/CVE-2025-15367.patch: Reverted to prevent behavior regressions, aligning with upstream backporting decisions. - CVE-2025-15367 * SECURITY REGRESSION: Allow HTAB in wsgiref header values - debian/patches/CVE-2026-0865-2.patch: Permit HTAB in header values (excluding names) in Lib/wsgiref/headers.py, add test coverage. - CVE-2026-0865 -- Vyom Yadav <vyom.yadav@canonical.com> Tue, 03 Mar 2026 16:40:39 +0530 python3.6 (3.6.9-1~18.04ubuntu1.13+esm8) bionic-security; urgency=medium * SECURITY UPDATE: Header injection in email messages where addresses are not sanitized. - debian/patches/CVE-2025-11468.patch: Add escape parentheses and backslash in Lib/email/_header_value_parser.py. Add test in Lib/test/test_email/test__header_value_parser.py. - CVE-2025-11468 * SECURITY UPDATE: Quadratic algorithm when building excessively nested XML documents. - debian/patches/CVE-2025-12084-*.patch: Remove _in_document and replace with node.ownerDocument in Lib/xml/dom/minidom.py. Set self.ownerDocument to None in Lib/xml/dom/minidom.py. Add test in Lib/test/test_minidom.py. - CVE-2025-12084 * SECURITY UPDATE: OOM and denial of service when opening malicious plist file. - debian/patches/CVE-2025-13837.patch: Add _MIN_READ_BUF_SIZE and _read with checks in Lib/plistlib.py. Add test in Lib/test/test_plistlib.py. - CVE-2025-13837 * SECURITY UPDATE: Header injection in user controlled data URLs in urllib. - debian/patches/CVE-2025-15282.patch: Add control character checks in Lib/urllib/request.py. Add test in Lib/test/test_urllib.py. * SECURITY UPDATE: Command injection through user controlled commands in imaplib. - debian/patches/CVE-2025-15366.patch: Add _control_chars and checks in Lib/imaplib.py. Add test in Lib/test/test_imaplib.py. * SECURITY UPDATE: Command injection through user controlled commands in poplib. - debian/patches/CVE-2025-15367.patch: Add control character regex check in Lib/poplib.py. Add test in Lib/test/test_poplib.py. - CVE-2025-15367 * SECURITY UPDATE: HTTP header injection in user controlled cookie values. - debian/patches/CVE-2026-0672.patch: Add _control_characters_re and checks in Lib/http/cookies.py. Add test in Lib/test/test_http_cookies.py. - CVE-2026-0672 * SECURITY UPDATE: HTTP header injection in user controlled headers and values with newlines. - debian/patches/CVE-2026-0865.patch: Add _control_chars_re and check in Lib/wsgiref/headers.py. Add test in Lib/test/support/__init__.py and Lib/test/test_wsgiref.py. - CVE-2026-0865 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Fri, 30 Jan 2026 14:49:02 -0330 libpam-systemd:amd64, libsystemd0:amd64, libudev1:amd64, systemd, systemd-sysv, udev (built from systemd) updated from 237-3ubuntu10.57+esm2 to 237-3ubuntu10.57+esm3: systemd (237-3ubuntu10.57+esm3) bionic-security; urgency=medium * SECURITY UPDATE: Local root execution via malicious hardware devices - d/p/udev-check-for-invalid-chars-in-various-fields-received-f.patch - d/p/udev-fix-review-mixup.patch - No CVE number -- Nick Rosbrook <enr0n@ubuntu.com> Fri, 13 Mar 2026 15:06:23 -0400 vim-common, vim-tiny, xxd (built from vim) updated from 2:8.0.1453-1ubuntu1.13+esm13 to 2:8.0.1453-1ubuntu1.13+esm14: vim (2:8.0.1453-1ubuntu1.13+esm14) bionic-security; urgency=medium * SECURITY UPDATE: Buffer Overflow - debian/patches/CVE-2026-26269.patch: Limit writing to max KEYBUFLEN bytes to prevent writing out of bounds. - debian/patches/CVE-2026-28420.patch: Use VTERM_MAX_CHARS_PER_CELL * 4 for ga_grow() to ensure sufficient space. Add a boundary check to the character loop to prevent index out-of-bounds access. - debian/patches/CVE-2026-28422.patch: Update the size check to account for the byte length of the fill character (using MB_CHAR2LEN). - debian/patches/CVE-2026-25749.patch: Limit strncpy to the length of the buffer (MAXPATHL) - CVE-2026-26269 - CVE-2026-28420 - CVE-2026-28422 - CVE-2026-25749 * SECURITY UPDATE: Command Injection - debian/patches/CVE-2026-28417.patch: Implement stricter RFC1123 hostname and IP validation. Use shellescape() for the provided hostname and port. - CVE-2026-28417 * SECURITY UPDATE: Out of Bounds Read - debian/patches/CVE-2026-28418.patch: Check for end of buffer and return early. - CVE-2026-28418 * SECURITY UPDATE: Buffer Underflow - debian/patches/CVE-2026-28419.patch: Add a check to ensure the delimiter (p_7f) is not at the start of the buffer (lbuf) before attempting to isolate the tag name. - CVE-2026-28419 * SECURITY UPDATE: Denial of Service - debian/patches/CVE-2026-28421.patch: Add bounds checks on pe_page_count and pe_bnum against mf_blocknr_max before descending into the block tree, and validate pe_old_lnum >= 1 and pe_line_count > 0 before calling readfile(). - CVE-2026-28421 -- Bruce Cable <bruce.cable@canonical.com> Wed, 11 Mar 2026 13:21:33 +1100 04/02/2026, commit https://git.launchpad.net/snap-core18/tree/07351192087830057d9ad8554c6807f0a7690077 [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] libc-bin, libc6:amd64, libc6:i386, multiarch-support (built from glibc) updated from 2.27-3ubuntu1.6+esm5 to 2.27-3ubuntu1.6+esm6: glibc (2.27-3ubuntu1.6+esm6) bionic-security; urgency=medium * SECURITY UPDATE: use-after-free in wordexp_t fields - debian/patches/CVE-2025-15281.patch: posix: Reset wordexp_t fields with WRDE_REUSE - CVE-2025-15281 * SECURITY UPDATE: double free in regcomp - debian/patches/CVE-2025-8058.patch: posix: Fix double-free after allocation failure in regcomp in posix/Makefile, posix/regcomp.c, posix/tst-regcomp-bracket-free.c - CVE-2025-8058 * SECURITY UPDATE: memory leak in NSS DNS - debian/patches/CVE-2026-0915.patch: resolv: Fix NSS DNS backend for getnetbyaddr - CVE-2026-0915 -- Nishit Majithia <nishit.majithia@canonical.com> Fri, 30 Jan 2026 13:33:29 +0530 gpgv (built from gnupg2) updated from 2.2.4-1ubuntu1.6+esm1 to 2.2.4-1ubuntu1.6+esm2: gnupg2 (2.2.4-1ubuntu1.6+esm2) bionic-security; urgency=medium * SECURITY UPDATE: Remote Code Execution - debian/patches/CVE-2025-68973.patch: gpg: Fix possible memory corruption in the armor parser. - CVE-2025-68973 -- Allen Huang <allen.huang@canonical.com> Tue, 06 Jan 2026 11:28:10 +0000 libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm6 to 1.1.1-1ubuntu2.1~18.04.23+esm7: openssl (1.1.1-1ubuntu2.1~18.04.23+esm7) bionic-security; urgency=medium * SECURITY UPDATE: Heap out-of-bounds write in BIO_f_linebuffer on short writes - debian/patches/CVE-2025-68160.patch: fix heap buffer overflow in BIO_f_linebuffer in crypto/bio/bf_lbuf.c. - CVE-2025-68160 * SECURITY UPDATE: Unauthenticated/unencrypted trailing bytes with low-level OCB function calls - debian/patches/CVE-2025-69418.patch: fix OCB AES-NI/HW stream path unauthenticated/unencrypted trailing bytes in crypto/modes/ocb128.c. - CVE-2025-69418 * SECURITY UPDATE: Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion - debian/patches/CVE-2025-69419.patch: check return code of UTF8_putc in crypto/asn1/a_strex.c, crypto/pkcs12/p12_utl.c. - CVE-2025-69419 * SECURITY UPDATE: Missing ASN1_TYPE validation in TS_RESP_verify_response() function - debian/patches/CVE-2025-69420.patch: verify ASN1 object's types before attempting to access them as a particular type in crypto/ts/ts_rsp_verify.c. - CVE-2025-69420 * SECURITY UPDATE: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex - debian/patches/CVE-2025-69421.patch: add NULL check in crypto/pkcs12/p12_decr.c. - CVE-2025-69421 * SECURITY UPDATE: ASN1_TYPE missing validation and type confusion - debian/patches/CVE-2026-2279x.patch: ensure ASN1 types are checked before use in apps/s_client.c, crypto/pkcs12/p12_kiss.c, crypto/pkcs7/pk7_doit.c. - CVE-2026-22795 - CVE-2026-22796 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 14 Jan 2026 16:15:12 -0330 libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm2 to 1.0.2n-1ubuntu5.13+esm3: openssl1.0 (1.0.2n-1ubuntu5.13+esm3) bionic-security; urgency=medium * SECURITY UPDATE: Heap out-of-bounds write in BIO_f_linebuffer on short writes - debian/patches/CVE-2025-68160.patch: fix heap buffer overflow in BIO_f_linebuffer in crypto/bio/bf_lbuf.c. - CVE-2025-68160 * SECURITY UPDATE: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex - debian/patches/CVE-2025-69421.patch: add NULL check in crypto/pkcs12/p12_decr.c. - CVE-2025-69421 * SECURITY UPDATE: ASN1_TYPE missing validation and type confusion - debian/patches/CVE-2026-2279x.patch: ensure ASN1 types are checked before use in apps/s_client.c, crypto/pkcs12/p12_kiss.c, crypto/pkcs7/pk7_doit.c. - CVE-2026-22796 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 14 Jan 2026 16:58:15 -0330 05/01/2026, commit https://git.launchpad.net/snap-core18/tree/07351192087830057d9ad8554c6807f0a7690077 [ Changes in the core18 snap ] Philip Meulengracht (2): static: add snapd.conf to tmpfiles.d from the snapd debian package github: add build action (#199) Valentin David (1): tools/generate-changelog.py: work-around esm re-upload of distro-info-data (#200) [ Changes in primed packages ] distro-info-data (built from distro-info-data) updated from 0.37ubuntu0.18 to 0.37ubuntu0.20: distro-info-data (0.37ubuntu0.20) bionic; urgency=medium * Add Ubuntu 26.04 LTS "Resolute Raccoon" (LP: #2126961) * Add release date for Debian 13 "Trixie" * Update the Debian 12 "bookworm" EoL -- Benjamin Drung <bdrung@ubuntu.com> Wed, 15 Oct 2025 20:50:31 +0200 distro-info-data (0.37ubuntu0.19) bionic; urgency=medium * Add Ubuntu 25.04 "Plucky Puffin" (LP: #2084572) * Add Ubuntu 25.10 "Questing Quokka" (LP: #2107391) * Add Debian 15 "Duke" -- Benjamin Drung <bdrung@ubuntu.com> Tue, 29 Apr 2025 11:54:42 +0200 gpgv (built from gnupg2) updated from 2.2.4-1ubuntu1.6 to 2.2.4-1ubuntu1.6+esm1: gnupg2 (2.2.4-1ubuntu1.6+esm1) bionic-security; urgency=medium * SECURITY UPDATE: verification DoS via crafted subkey data - debian/patches/CVE-2025-30258-1.patch: lookup key for merging/ inserting only by primary key in g10/getkey.c, g10/import.c, g10/keydb.h. - debian/patches/CVE-2025-30258-2.patch: remove a signature check function wrapper in g10/mainproc.c, g10/packet.h, g10/sig-check.c. - debian/patches/CVE-2025-30258-3.patch: fix a verification DoS due to a malicious subkey in the keyring in g10/getkey.c, g10/keydb.h, g10/mainproc.c, g10/packet.h, g10/sig-check.c, g10/pkclist.c. - debian/patches/CVE-2025-30258-4.patch: fix regression for the recent malicious subkey DoS fix in g10/getkey.c, g10/packet.h. - debian/patches/CVE-2025-30258-5.patch: fix double free of internal data in g10/sig-check.c. - CVE-2025-30258 * debian/patches/fix-key-validity-regression-due-to-CVE-2025- 30258.patch: - Fix a key validity regression following patches for CVE-2025-30258, causing trusted "certify-only" primary keys to be ignored when checking signature on user IDs and computing key validity. This regression makes imported keys signed by a trusted "certify-only" key have an unknown validity -- Nishit Majithia <nishit.majithia@canonical.com> Thu, 04 Dec 2025 18:43:02 +0530 libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm6 to 3.6.9-1~18.04ubuntu1.13+esm7: python3.6 (3.6.9-1~18.04ubuntu1.13+esm7) bionic-security; urgency=medium * SECURITY UPDATE: Possible payload obfuscation - debian/patches/CVE-2025-8291-pre1.patch: Add error raise in Lib/zipfile.py and add tests. - debian/patches/CVE-2025-8291.patch: check consistency of the zip64 end of central dir record in Lib/zipfile.py, Lib/test/test_zipfile.py. - CVE-2025-8291 * SECURITY UPDATE: Performance degradation - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in os.path.expandvars() in Lib/ntpatch.py, Lib/posixpath.py, Lib/test/test_genericpatch.py, Lib/test/test_npath.py. - CVE-2025-6075 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Tue, 18 Nov 2025 09:44:54 -0330 29/10/2025, commit https://git.launchpad.net/snap-core18/tree/45ab8ed14d51d8030d477bf7776855d5ce54eaf5 [ Changes in the core18 snap ] Alfonso Sánchez-Beato (1): snapcraft.yaml: add assumes for snapd 2.62 [ Changes in primed packages ] vim-common, vim-tiny, xxd (built from vim) updated from 2:8.0.1453-1ubuntu1.13+esm12 to 2:8.0.1453-1ubuntu1.13+esm13: vim (2:8.0.1453-1ubuntu1.13+esm13) bionic-security; urgency=medium * SECURITY UPDATE: Segmentation Fault - debian/patches/CVE-2025-24014.patch: Add check that ScreenLines is not NULL - CVE-2025-24014 -- Bruce Cable <bruce.cable@canonical.com> Fri, 03 Oct 2025 08:59:18 +1000 01/10/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] libssl1.1:amd64, openssl (built from openssl) updated from 1.1.1-1ubuntu2.1~18.04.23+esm5 to 1.1.1-1ubuntu2.1~18.04.23+esm6: openssl (1.1.1-1ubuntu2.1~18.04.23+esm6) bionic-security; urgency=medium * SECURITY UPDATE: Out of bounds read when decrypting password based CMS messages. - debian/patches/CVE-2025-9230.patch: Fix incorrect bound check for key size in crypto/cms/cms_pwri.c - CVE-2025-9230 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 17 Sep 2025 11:35:41 -0230 libssl1.0.0:amd64 (built from openssl1.0) updated from 1.0.2n-1ubuntu5.13+esm1 to 1.0.2n-1ubuntu5.13+esm2: openssl1.0 (1.0.2n-1ubuntu5.13+esm2) bionic-security; urgency=medium * SECURITY UPDATE: Out of bounds read when decrypting password based CMS messages. - debian/patches/CVE-2025-9230.patch: Fix incorrect bound check for key size in crypto/cms/cms_pwri.c - CVE-2025-9230 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 17 Sep 2025 14:20:14 -0230 10/09/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] libgnutls30:amd64 (built from gnutls28) updated from 3.5.18-1ubuntu1.6+esm1 to 3.5.18-1ubuntu1.6+esm2: gnutls28 (3.5.18-1ubuntu1.6+esm2) bionic-security; urgency=medium * SECURITY UPDATE: double-free via otherName in the SAN - debian/patches/CVE-2025-32988.patch: avoid double free when exporting othernames in SAN in lib/x509/extensions.c. - CVE-2025-32988 * SECURITY UPDATE: heap write overflow in certtool via invalid template - debian/patches/CVE-2025-32990.patch: avoid 1-byte write buffer overrun when parsing template in src/certtool-cfg.c, tests/cert-tests/Makefile.am, tests/cert-tests/template-test.sh, tests/cert-tests/templates/template-too-many-othernames.tmpl. - CVE-2025-32990 -- Ian Constantin <ian.constantin@canonical.com> Mon, 08 Sep 2025 19:05:25 +0300 22/08/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm5 to 3.6.9-1~18.04ubuntu1.13+esm6: python3.6 (3.6.9-1~18.04ubuntu1.13+esm6) bionic-security; urgency=medium * SECURITY UPDATE: Regular expression denial of service. - debian/patches/CVE-2025-6069.patch: Improve regex parsing in Lib/html/parser.py. - CVE-2025-6069 * SECURITY UPDATE: Infinite loop when parsing tar archives. - debian/patches/CVE-2025-8194.patch: Raise exception when count < 0 in Lib/tarfile.py. - CVE-2025-8194 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Tue, 19 Aug 2025 16:04:55 -0230 30/07/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] cloud-init (built from cloud-init) updated from 23.1.2-0ubuntu0~18.04.1 to 23.1.2-0ubuntu0~18.04.1+esm1: cloud-init (23.1.2-0ubuntu0~18.04.1+esm1) bionic-security; urgency=medium * d/cloud-init.postinst: move existing hotplug-cmd fifo to root-only share dir (LP: #2114229) (CVE-2024-11584) * cherry-pick 8c3ae1bb: fix: Don't attempt to identify non-x86 OpenStack instances (LP: #2069607) (CVE-2024-6174) * cherry-pick 8b45006c: fix: Make hotplug socket writable only by root (LP: #2114229) (CVE-2024-11584) * cherry-pick e3f42adc: fix: strict disable in ds-identify on no datasources found (LP: #2069607) (CVE-2024-6174) -- Chad Smith <chad.smith@canonical.com> Wed, 25 Jun 2025 15:46:01 -0600 libsqlite3-0:amd64 (built from sqlite3) updated from 3.22.0-1ubuntu0.7+esm1 to 3.22.0-1ubuntu0.7+esm2: sqlite3 (3.22.0-1ubuntu0.7+esm2) bionic-security; urgency=medium [ Marc Deslauriers ] * SECURITY UPDATE: Memory corruption via number of aggregate terms - debian/patches/CVE-2025-6965.patch: raise an error right away if the number of aggregate terms in a query exceeds the maximum number of columns in src/expr.c, src/sqliteInt.h. - CVE-2025-6965 * SECURITY UPDATE: DoS via sqlite3_db_config arguments - debian/patches/CVE-2025-29088.patch: harden SQLITE_DBCONFIG_LOOKASIDE interface against misuse in src/main.c, src/sqlite.h.in. - CVE-2025-29088 -- Ian Constantin <ian.constantin@canonical.com> Mon, 28 Jul 2025 23:25:48 +0300 01/07/2025, commit https://git.launchpad.net/snap-core18/tree/82a41a75ad121d5aa5a5340124ae20c559e7045b [ Changes in the core18 snap ] Philip Meulengracht (1): tools: aggregate old changelogs [ Changes in primed packages ] python3-urllib3 (built from python-urllib3) updated from 1.22-1ubuntu0.18.04.2+esm2 to 1.22-1ubuntu0.18.04.2+esm3: python-urllib3 (1.22-1ubuntu0.18.04.2+esm3) bionic-security; urgency=medium * SECURITY UPDATE: Information disclosure through improperly disabled redirects. - debian/patches/CVE-2025-50181.patch: Add "retries" check and set retries to Retry.from_int(retries, redirect=False) as well as set raise_on_redirect in ./src/urllib3/poolmanager.py. - CVE-2025-50181 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 25 Jun 2025 10:22:54 -0230 sudo (built from sudo) updated from 1.8.21p2-3ubuntu1.6 to 1.8.21p2-3ubuntu1.6+esm1: sudo (1.8.21p2-3ubuntu1.6+esm1) bionic-security; urgency=medium * SECURITY UPDATE: Local Privilege Escalation via host option - debian/patches/CVE-2025-32462.patch: only allow specifying a host when listing privileges. - CVE-2025-32462 -- Federico Quattrin <federico.quattrin@canonical.com> Wed, 25 Jun 2025 17:14:55 -0300 16/06/2025, commit https://git.launchpad.net/snap-core18/tree/74bb5585b7c696c20e4e7ca7faff13d2be218d8b [ Changes in the core18 snap ] No detected changes for the core18 snap [ Changes in primed packages ] libc-bin, libc6:amd64, libc6:i386, multiarch-support (built from glibc) updated from 2.27-3ubuntu1.6+esm4 to 2.27-3ubuntu1.6+esm5: glibc (2.27-3ubuntu1.6+esm5) bionic-security; urgency=medium * SECURITY UPDATE: privelege escalation issue - debian/patches/any/CVE-2025-4802.patch: elf: Ignore LD_LIBRARY_PATH and debug env var for setuid for static - CVE-2025-4802 -- Nishit Majithia <nishit.majithia@canonical.com> Mon, 26 May 2025 13:48:50 +0530 libgssapi-krb5-2:amd64, libk5crypto3:amd64, libkrb5-3:amd64, libkrb5support0:amd64 (built from krb5) updated from 1.16-2ubuntu0.4+esm3 to 1.16-2ubuntu0.4+esm5: krb5 (1.16-2ubuntu0.4+esm5) bionic-security; urgency=medium * SECURITY UPDATE: Use of weak cryptographic hash. - debian/patches/CVE-2025-3576*.patch: Add allow_des3 and allow_rc4 options. Disallow usage of des3 and rc4 unless allowed in the config. Replace warn_des3 with warn_deprecated in ./src/lib/krb5/krb/get_in_tkt.c. Add allow_des3 and allow_rc4 boolean in ./src/include/k5-int.h. Prevent usage of deprecated enctypes in ./src/kdc/kdc_util.c. - debian/patches/CVE-2025-3576-post1.patch: Add enctype comparison with ENCTYPE_AES256_CTS_HMAC_SHA1_96 in ./src/kdc/kdc_util.c. - debian/libk5crypto3.symbols: Add krb5int_c_deprecated_enctype symbol. - CVE-2025-3576 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Tue, 20 May 2025 11:16:32 -0230 python3-pkg-resources (built from python-setuptools) updated from 39.0.1-2ubuntu0.1+esm1 to 39.0.1-2ubuntu0.1+esm2: python-setuptools (39.0.1-2ubuntu0.1+esm2) bionic-security; urgency=medium * SECURITY UPDATE: path traversal vulnerability - debian/patches/CVE-2025-47273-pre1.patch: Extract _resolve_download_filename with test. - debian/patches/CVE-2025-47273.patch: Add a check to ensure the name resolves relative to the tmpdir. - CVE-2025-47273 -- Fabian Toepfer <fabian.toepfer@canonical.com> Wed, 28 May 2025 19:37:50 +0200 libpython3.6-minimal:amd64, libpython3.6-stdlib:amd64, python3.6, python3.6-minimal (built from python3.6) updated from 3.6.9-1~18.04ubuntu1.13+esm4 to 3.6.9-1~18.04ubuntu1.13+esm5: python3.6 (3.6.9-1~18.04ubuntu1.13+esm5) bionic-security; urgency=medium * SECURITY UPDATE: Improper encoding of comma during address list folding. - debian/patches/CVE-2025-1795-1.patch: Replace ValueTerminal with ListSeparator in ./Lib/email/_header_value_parser.py. - debian/patches/CVE-2025-1795-2.patch: Add checks for terminal non-encoding in ./Lib/email/_header_value_parser.py. - CVE-2025-1795 * SECURITY UPDATE: Use after free in unicode_escape decoding. - debian/patches/CVE-2025-4516-pre1.patch: Add DecodeUnicodeEscapeStateful and replace DecodeUnicodeEscape with DecodeUnicodeEscapeInternal in ./Include/cpython/unicodeobject.h. Change IncrementalDecoder and add decode to StreamReader in ./Lib/encodings/unicode_escape.py. Change instance to DecodeUnicodeEscapeStateful in ./Modules/_codecsmodule.c. Change checks in ./Modules/clinic/_codecsmodule.c.h and instances in ./Objects/unicodeobject.c and ./Parser/pegen/parse_string.c. - debian/patches/CVE-2025-4516.patch: Add _PyBytes_DecodeEscape2 in ./Include/cpython/bytesobject.h. Add _PyUnicode_DecodeUnicodeEscapeInternal2 in ./Include/cpython/unicodeobject.h. Add extra escape checks in ./Objects/bytesobject.c and ./Objects/unicodeobject.c. - debian/libpython.symbols.in: Update symbols with new functions. - CVE-2025-4516 -- Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> Wed, 11 Jun 2025 09:40:51 -0230 python3-requests (built from requests) updated from 2.18.4-2ubuntu0.1+esm1 to 2.18.4-2ubuntu0.1+esm2: requests (2.18.4-2ubuntu0.1+esm2) bionic-security; urgency=medium * SECURITY UPDATE: Information Leak - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc lookup instead of netloc - CVE-2024-47081 -- Bruce Cable <bruce.cable@canonical.com> Wed, 11 Jun 2025 13:27:28 +1000
Save
cmd:
run