Skip to content

1.323.0

Choose a tag to compare

@ari-wg-gitbot ari-wg-gitbot released this 17 Jul 14:03
· 1 commit to main since this release

Notably, this release addresses:

USN-8543-1 Wget vulnerabilities:

USN-8541-1 Vim vulnerabilities:

USN-8533-1 OpenSSH vulnerabilities:

USN-8531-1 libexif vulnerabilities:

USN-8512-1 Gzip vulnerabilities:

USN-8510-1 tar vulnerability:

USN-8495-1 nghttp2 vulnerability:

USN-8493-1 Linux kernel vulnerabilities:

USN-8487-1 curl vulnerabilities:

  • CVE-2026-8286: A vulnerability exists where a new transfer tha...
  • CVE-2026-9080: Calling curl_easy_pause() within the event-ba...
  • CVE-2026-8458: libcurl might in some circumstances reuse the w...
  • CVE-2026-9545: In this scenario, libcurl first uses a proper H...
  • CVE-2026-8927: When reusing a libcurl handle for sequential tr...
  • CVE-2026-8924: A flaw in curl’s cookie parsing logic allows a ...
  • CVE-2026-9079: libcurl had a flaw that when instructed to clea...
  • CVE-2026-9547: When a libcurl-based application performs trans...
  • CVE-2026-8926: When asking curl to use a .netrc file to find...
  • CVE-2026-8925: The curl logic that works with SASL authenticat...

USN-8480-1 SQLite vulnerabilities:

USN-8477-1 tar vulnerability:

  • CVE-2026-5704: A flaw was found in tar. A remote attacker coul...

USN-8468-1 ImageMagick vulnerabilities:

USN-8469-1 FFmpeg vulnerabilities:

USN-8454-1 libheif vulnerabilities:

USN-8451-1 Vim vulnerabilities:

USN-8415-1 Vim vulnerabilities:

USN-8414-1 OpenSSL vulnerabilities:

USN-8388-1 Linux kernel vulnerabilities:

USN-8362-1 XZ Utils vulnerability:

USN-8319-1 Libgcrypt vulnerabilities:

USN-8304-1 Vim vulnerabilities:

USN-8294-1 PostgreSQL vulnerabilities:

  • CVE-2026-6475: Symlink following in PostgreSQL pg_basebackup p...
  • CVE-2026-6637: Stack buffer overflow in PostgreSQL module "ref...
  • CVE-2026-6575: Buffer over-read in PostgreSQL function pg_rest...
  • CVE-2026-6478: Covert timing channel in comparison of MD5-hash...
  • CVE-2026-6473: Integer wraparound in multiple PostgreSQL serve...
  • CVE-2026-6477: Use of inherently dangerous function PQfn(..., ...
  • CVE-2026-6638: SQL injection in PostgreSQL logical replication...
  • CVE-2026-6472: Missing authorization in PostgreSQL CREATE TYPE...
  • CVE-2026-6476: SQL injection in PostgreSQL pg_createsubscriber...
  • CVE-2026-6474: Externally-controlled format string in PostgreS...
  • CVE-2026-6479: Uncontrolled recursion in PostgreSQL SSL and GS...

USN-8293-1 Bind vulnerabilities:

  • CVE-2026-5950: An unbounded resend loop vulnerability exists i...
  • CVE-2026-5947: Undefined behavior may result due to a race con...
  • CVE-2026-3593: A use-after-free vulnerability exists within th...
  • CVE-2026-5946: Multiple flaws have been identified in named ...
  • CVE-2026-3592: BIND resolvers are vulnerable to an amplified r...
  • CVE-2026-3039: BIND servers that are configured to use TKEY-ba...

USN-8292-1 libarchive vulnerabilities:

  • CVE-2026-4426: A flaw was found in libarchive. An Undefined Be...
  • CVE-2026-4424: A flaw was found in libarchive. This heap out-o...
  • CVE-2026-5121: A flaw was found in libarchive. On 32-bit syste...

USN-8284-1 GnuTLS vulnerabilities:

USN-8283-1 rsync vulnerabilities:

USN-8282-1 Unbound vulnerabilities:

USN-8279-1 Linux kernel vulnerabilities:

USN-8263-1 ImageMagick vulnerabilities:

USN-8259-1 OpenEXR vulnerabilities:

USN-8255-1 Linux kernel vulnerabilities:

USN-8246-1 Vim vulnerabilities:

USN-8233-1 nghttp2 vulnerability:

USN-8229-1 sed vulnerability:

  • CVE-2026-5958: When sed is invoked with both -i (in-place edit...

USN-8227-1 curl vulnerabilities:

  • CVE-2026-4873: A vulnerability exists where a connection requi...
  • CVE-2026-5773: libcurl might in some circumstances reuse the w...
  • CVE-2026-5545: libcurl might in some circumstances reuse the w...
  • CVE-2026-6429: When asked to both use a .netrc file for cred...
  • CVE-2026-6276: Using libcurl, when a custom Host: header is ...
  • CVE-2026-6253: curl might erroneously pass on credentials for ...
  • CVE-2026-7168: Successfully using libcurl to do a transfer ove...

USN-8226-1 kmod update:

USN-8222-1 OpenSSH vulnerabilities:

USN-8213-1 Vim vulnerabilities:

USN-8202-1 jq vulnerabilities:

USN-8171-1 Vim vulnerabilities:

USN-8119-1 systemd vulnerabilities:

-ii  linux-libc-dev:amd64 5.15.0-185.195               amd64 Linux Kernel Headers for development
+ii  linux-libc-dev:amd64 5.15.0-186.196               amd64 Linux Kernel Headers for development
-ii  tar                  1.34+dfsg-1ubuntu0.1.22.04.4 amd64 GNU version of the tar archiving utility
+ii  tar                  1.34+dfsg-1ubuntu0.1.22.04.5 amd64 GNU version of the tar archiving utility